Job summary

The Grants, Risk, Assurance and Fraud team - or GRAFT - is a diverse and friendly team of c. 20 experts that sits within the Finance Directorate in DCMS. We were created to provide advice and guidance to ensure the Department and its public bodies spend money and manage their risks wisely and to maximise public outcomes.

We work across the organisation and our public bodies, supporting a variety of policy and project areas from sporting events to heritage projects through to our charities sector.

This is a new role and team, to provide a stronger and cohesive offer to the department on data, information and cyber policies and assurance. You will work very closely with the operational teams in our Data and Technology division.

We love innovation and new ideas. It is team that welcomes challenge and growth, so if that sounds like somewhere you like to be please do apply.

Come and make a difference to the things you love.

Job description

This role is the department’s senior lead for information and data protection compliance and for the escalation and management of data, information and cyber-related risk. The post holder sets the strategic direction for how information and data risks are governed and managed, and provides trusted advice to senior leaders and operational staff on risk appetite, compliance and proportionate control.

Change leadership

  • Maximise the value of the guidance and assurance you and your team provide to support the risk profile of the department and effective management of data protection and cyber-related risks
  • Engage the department to ensure policies are proportionate, providing choices between ‘minimum viable’ and more gold-standard assurance depending on levels of risk, spend, and complexity

Functional assurance

  • Act as the Department's DPO, providing independent advice to the Permanent Secretary and provide functional assurance on data protection across the department
  • Provide advice and guidance to the operational Data protection and cyber teams on how to effectively manage risk in the department, including supporting escalation and triage of more significant issues as working with first line teams on more significant risks through the development of an effective triage system
  • Maintain strong awareness of Government’s strategic direction for information rights, management and data protection legislation, guidance and relevant case law.

Corporate and people leadership

  • Lead, support and develop three members of staff (across cyber and data) in their own professional development and in their ability to influence effectively across the department:
  • Own specific work streams for our directorate (c.100 members of staff), for example designing and delivering work programmes to improve wellbeing or our COO vision and strategy

Person specification

The ideal candidate would have the following key skills and experience, please note that desirable skills will only be used in the event of tied candidates:

Essential requirements:

  • Demonstrable knowledge of relevant privacy laws and practices, or a professional privacy qualification/accreditation (such as CIPP/E or equivalent)
  • Ability to lead and develop a team to recommend proportionate and confident data protection and information security practices and policies to provide robust, risk-based solutions.
  • Strong communication skills, with the ability to explain complex issues in a way that is easy to understand, and the ability to rapidly grasp the nuances of an organisation's strategic priorities
  • Ability to drive culture change and support operational teams to engage proactively with data protection, cyber, and information security
  • Strong people leadership and change management skills, with a demonstrable ability to collaborate, influence, and persuade diverse stakeholders to optimise compliance

Desirable Skills:

  • Relevant audit/assurance experience in assessing compliance with cyber /data protection policies.
  • Awareness of the technological landscape, and the tools and platforms used to store and share corporate information.

Application:

Please click the link to apply - Head of Information and Data Security and Data Protection Officer - Civil Service Jobs - GOV.UK

We are running an information session where prospective applicants can find out more about the role. This will be hosted by the vacancy holder, and will take place on:

  • Tuesday 28th July at 10:30am

The session will be an opportunity to hear more about the role, the team and wider directorate and the department. It will also be an opportunity for you to ask any questions.

Please register your interest by filling out this Registration form by 4pm on 27th July and you will be sent an invitation. Invites will only be sent after this deadline has passed.

Please note that the session will not be recorded and will not focus on the DCMS recruitment process - please direct any queries that you have on this topic (timelines, reasonable adjustments, onboarding etc) to resourcing.team@dcms.gov.uk

Behaviours

We'll assess you against these behaviours during the selection process:

  • Managing a Quality Service
  • Working Together
  • Leadership
  • Communicating and Influencing

Location

17, Marble Street, Manchester, M2 3AW, United Kingdom

Job ID

15697