National Audit Office
National Audit Office


Position details

Login and apply
Hide Section - Vacancy

Vacancy

Job titleCloud Senior Information Security Officer
Minimum salary 
Maximum salary 
LocationLondon
Close date11/04/2021
Hide Section - Job description

Job description

Job descriptionCloud Senior Information Security Officer
Band 2
Type of contract: Full Time, permanent
Salary: £60,188 to £70,217 per annum

Nationality Requirements:

UK nationals
nationals of Commonwealth countries who have the right to work in the UK
nationals from the EU, EEA or Switzerland with (or eligible for) status under the European Union Settlement Scheme (EUSS)

Please note, we are not able to sponsor work visas. Please contact us at hrservicedesk@nao.org.uk should you have any questions on your nationality eligibility.

Why are we recruiting for this role?
The NAO is expanding its Information Security team to support the evolving needs of the business and enable continuous improvement in response to an ever-changing threat landscape. The continued adoption of cloud services changes how organisations identify, protect, detect, respond and recover from threats and risks; whilst maintaining continuous assurance and delivering continuous improvement of our security posture and risk profile in support of our ambition of being an exemplar organisation.

Who are the team?
The Senior Information Security Officer is an integral role in the ongoing development and continuous improvement of the NAO’s “Cloud First” strategy. You’ll play a key role in identifying, evaluating, measuring and managing cyber risks; and be responsible for supporting the continuous assurance and continuous improvement of our security posture and risk profile.

The Senior Information Security Officer role sits within a diverse, inclusive, respectful and agile team of information security professionals; responsible for enabling the business to better understand, identify and manage the threats and risks that impact the NAO’s ability to deliver on its vision and strategy.

What are the main responsibilities of this role?
The Senior Information Security Officer role primarily focuses on the following key areas of responsibility:

• Information Assurance – Evaluate and asses existing cloud security controls in accordance with the NAO’s ISO27001 certified Information Security Management System; providing assurance to key stakeholders around our security posture and risk profile, supported by appropriate and proportion recommendations around how the NAO can drive continuous improvement.

• Risk Management - Proactively identifying, evaluating, assessing and reporting on risks that impact the NAO’s ability to deliver on its vision and strategy; working with key stakeholder groups in the delivery of appropriate and proportionate mitigations that continuously improve the NAO’s risk profile.

• Continuous Improvement - Support the NAO’s commitment to information security by supporting the continuous improvement of our cloud security controls in response to the ever-changing threat, business and regulatory landscape.

The successful Senior Information Security Officer will have the opportunity to develop and grow in field such as security testing, audit, assurance and ISO27001. Furthermore, you will have the opportunity to influence the direction of our Information Security Strategy; as we support the business in delivering on its strategic objective(s) of being an exemplar organisation.

About the National Audit Office
The National Audit Office (NAO) supports parliament to hold government to account and to improve public services. We focus on driving long-term sustainable improvement in public service delivery and work with government and our stakeholders to deliver better performance. In a nutshell, we help the nation spend wisely.
The NAO welcomes applications from everyone. We value diversity in all its forms and the difference it makes to our organisation. By removing barriers and creating an inclusive culture all our people have the opportunity to develop and maximise their full potential. As members of the Business Disability Forum and the Disability Confident Scheme we guarantee to interview all disabled applicants who meet the minimum criteria. The NAO supports flexible working and is happy to discuss this with you at application stage.

Relationships:
• Reporting to: Head of Information Security
• Internal relationships: Critical relationships with Information Security peers, Digital Services, IT Operations and
project teams.
• External: Suppliers, vendors, and peers in similar organisations.
• Resources Managed: None
ResponsibilitiesInformation Assurance
• Discover, validate and drive remediation of security threats, risks, vulnerabilities and configuration gaps that
may exist across NAO cloud services.
• Evaluate and assess existing security controls in accordance with the NAO’s ISO27001 certified Information
Security Management System
• Develop and maintain a schedule for the ongoing assessment of security controls, seeking opportunities to
leverage automation to enable a continuous assurance culture.
• Support the ongoing assurance of suppliers and cloud service provider (CSPs), advising on cloud specific
regulatory risks or regulatory requirements relating to cloud assurance
• Proactively identify, evaluate, document and report on areas of non-compliance and non-conformity to key
stakeholders

Risk Management
• Proactively identify, evaluate and assess threats and risks that may impact the NAO’s ability to deliver on its
vision and strategy
• Clearly communicate risks to key stakeholders with recommendations on appropriate and proportionate
mitigations
• Contribute to the management and maintenance of the Information Security Risk Register
• Manage and coordinate the delivery of appropriate and proportionate mitigations in accordance with the
Information Security Continuous Improvement Plan

Continuous Improvement
• Identify, develop, implement and continuously improve appropriate and proportionate cloud security controls
in response to an evolving threat landscape
• Work in collaboration with the wider Information Security and Digital Services teams in the continuous
improvement of cloud controls, policies and standards; as part of our ISO27001 certified Information Security

Management System
• Promote, evangelise and support the continuous improvement of cloud security controls; empowering the
business in the continued application of “security and privacy by default” principles
• Support the delivery of the proactive communications and security awareness campaigns to key stakeholder
groups across the business.
• Support the delivery and continuous improvement of the NAO Information Security Strategy
• Support the wider business in the delivery of strategic business changes and technical projects
• Deliver and maintain documentation and procedures to ensure effective, ongoing management of our

Information Security Management System.
• Most importantly of all being curious, seeking to learn and striving for excellence
Skills requiredExperience
• Demonstrable, technical background working in an information security, cyber security or security leadership
role within a fast paced and dynamic environment
• Demonstrable experience contributing to the delivery of and continuous improvement of cloud security
controls
• Demonstrable experience working with cloud technology – including IaaS, PaaS, SaaS and hybrid cloud
environments
• Must hold relevant industry accreditations such as CISSP, CCSP, CISM or CISA.

Key Behaviours
• Customer First: Apply a customer first mindset in the engagement, enablement and support of internal
stakeholders.
• Develop and Apply Knowledge: Build on your existing technical and security expertise by being curious,
continuously developing and seeking to learn new skills.
• Deliver High Performance: Be bold in delivering and driving through improvements and innovative solutions
• Collaborative: Be an effective and flexible contributor to the success of the team.
• Communication: Apply your strong verbal and written communication skills to clearly articulate the threats and
risks that impact the business to different audiences (both technical and non-technical.)

Practical Experience
• Strong background in the identification, evaluation and assessment of cloud security threats and risks; and
providing recommendations on appropriate and proportionate mitigations.
• Experience in the analysis of existing cloud security controls and making recommendations on how to drive
continuous improvement
• Experience working to industry standards such as ISO/IEC 27001, NCSC, NIST, CSA CCM, CREST and/or the
HMG Security Policy Framework (HMG SPF)
• Experience with risk assessment and threat modelling techniques such as ISO31000, ISO27005, the Diamond
Model and/or MITRE ATT&CK
• Experience with data protection and privacy regulations such as GDPR and Data Protection Act
• Able to work under pressure, as part of a multi-disciplinary team to deliver key outcomes to challenging
timescales
• Able to provide expertise from both a cyber security and technical perspective on projects
• Ability to be self-sufficient and make independent decisions on problem resolution that align to departmental
and functional strategy

Technical Knowledge
• Must have a strong background with a broad set of Microsoft Azure and Microsoft 365 cloud services, products
and concepts
• Strong experience in the testing, assessment, evaluation and/or audit of cloud security controls, including the
ability to articulate the current state of controls to both technical and non-technical audiences.
• Strong experience in three or more of the following security domains:
• Cloud Security
• Identity & Access Management
• Network Security (e.g. Firewalls, IDS/IPS, Proxy, Internet Filtering etc)
• Email Security
• Endpoint Security
• Encryption & Cryptography
• Vulnerability Management
• Strong experience with two or more of the following toolsets:
• Identity & Access Management platforms (such as Azure Active Directory)
• Threat Protection tools (such as Defender ATP, Office 365 ATP and Cloud App Security)
• Enterprise firewall technologies (such as Fortinet, Cisco, Checkpoint)
• Vulnerability Management tools (such as Tenable, Qualys or Rapid7)
• Security Incident & Event Management (SIEM) platforms (such as Azure Sentinel)

Desirable
Whilst not essential for being successful in this role, the following key skills/competencies would be desirable:
• Understanding of agile, DevOps or DevSecOps principles and practices
• Hold one or more of the following accreditations:
• CSA CCSK
• ISC(2) CCSP
• ISC(2) CISSP
• ISACA CISA
• IAPP CIPT
• IAPP CIPP/E
• Microsoft 365 Certified: Fundamentals
• Microsoft 365 Certified: Security Administrator
• Microsoft Azure Certified: Fundamentals
• Microsoft Azure Certified: Administration Associate
• Microsoft Azure Certified: Security Administrator
Educational requirements

Powered by