Everything we do at the Scottish Funding Council (SFC) aims to create the right environment for colleges and universities to thrive. The Scottish Funding Council is Scotland’s tertiary education and research authority. Our ambition is to make Scotland an outstanding place to learn, educate, research, and innovate – now and for the future. So, naturally, we have a clear focus on recruiting the best people and developing them throughout their career. We invest around £2 billion every year, and our funding enables colleges and universities to provide life-changing opportunities for over half a million people. We’re not only looking for the best people to come and work for us, but also people who will connect with our guiding principles which include working in partnership, championing diversity, and supporting sustainability for future generations. By fostering our guiding principles, we are very proud of the inclusive working environment that we have created. We are committed to attracting people of all backgrounds: we want our colleague base to reflect the people and communities that we serve. Job Summary Reporting to the Assistant Director, Information Governance you will lead on responding to information rights requests and fulfil the role of the Data Protection Officer - a key role within SFC. You will work in close partnership with senior leaders, including the Senior Information Risk Officer and Chief Information Officer, supporting the Assistant Director to deliver the Information Governance Framework and leading on associated activities. As an experienced Information Rights and Data Protection practitioner, you will be skilled in dealing with sensitive, complex information at pace, building trusted relationships with colleagues across SFC, and you will exercise good judgement in responding to information rights requests. You will be expected to work flexibly across the responsibilities of the information governance team, stepping in to provide cover and support when required to ensure deadlines are met. A keen understanding of the strategic context within which the SFC is working will be key to success in this role. Key Responsibilities Leading the response to information rights requests, providing advice to colleagues across SFC, ensuring legal compliance with relevant legislation. Provide an efficient and effective senior contact point for queries in relation to information rights and data protection including complex ones. Ensure staff fully understand their responsibilities within data protection legislation and information rights and follow relevant processes, evidenced through reporting and auditing. Promote an information governance culture and an understanding of data protection compliance throughout the organisation. Inform and advise SFC staff, including senior leaders, about their obligations to comply with the UK GDPR and other relevant data protection laws taking into account the nature, scope, context and purposes of the processing. Develop and maintain effective coordination and liaison with our stakeholders and external partners. Identify opportunities to improve ways of working within Information Governance and implement positive change. Manage and advise on internal data protection activities, for example supporting colleagues to deliver Data Protection Impact Assessments and Data Sharing Agreements. Develop and maintain SFC’s Records of Processing Activities (RoPA) to ensure that it is accurate and regularly reviewed and information asset owners understand their responsibilities. Co-ordinating with Information Governance colleagues, assess and respond to personal data breaches, including reporting to senior management and the ICO as required. Identify and implement improvements to data protection and information rights compliance based on user requirements and best practice. Contribute, make recommendations and report to the Information Governance Oversight Group on data protection and information rights development and compliance, including risks, trends, good practice, mitigation, and training. Monitoring SFC’s compliance with the UK GDPR and other data protection laws and with our data protection policies, raising awareness of data protection issues, training staff and conducting audits. Being the first point of contact for the ICO and for internal and external stakeholders, including data subjects. Support the formulation, implementation and regular review of policy and guidance to ensure that data protection and information rights policies meet all relevant legislation and best practice. Person Specification Essential Requirements: Experience administering Azure Services: M365, App Service, Azure SQL, Blob Storage, Key Vault, ExpressRoute, Virtual machines, Virtual Networks. Experience of Azure Migration, migrating on-premises solutions to the cloud using Azure Migrate (or other) tools. Experience with Continuity of Operations/Disaster Recovery architecture and planning. Extensive and applied experience administering Windows Server OS 2016 and above (Standalone & Cluster) patching, domain admin, network configuration, security monitoring. In-depth technical knowledge of Microsoft Azure and On-Prem infrastructure components and how they integrate with one another. In-depth knowledge of with Azure Security Centre and Azure Monitor: Network, Application, Infrastructure. In-depth knowledge of multi factor authentication (Azure MFA preferred), Microsoft AD Integration with Cloud Applications/Microsoft Azure Active Directory. Good working knowledge of Network administration and VPN administration. Good working knowledge of Active Directory Services including DNS, DHCP, and DFS. Qualifications: Microsoft Cloud Certification, at least one of the following (AZ-400, AZ-303, AZ-104). Good interpersonal and communication skills. Proven track record of delivering high quality and effective outputs within time and resource constraints. Ability to work collectively and with impact as part of a team. Desirable Criteria: Experience of performing the Data Protection Officer role, preferably in a public sector context. Experience of enhancing the information governance culture in an organisation, preferably within a public sector context. Additional Information Key Rewards and Benefits Normal full-time hours of work are 35 per week. We will consider flexible working arrangements. A flexi-time system is in operation. Annual leave entitlement of 26.5 days pro-rata, rising to 30 days pro-rata after 4 years’ continuous service. Public and privilege holiday entitlement of 11.5 days pro-rata. A flexible approach to hybrid working, giving you flexibility to work from home for some of the time while also maintaining regular in-person contact with colleagues. Annual pay review: approved within the framework of the Scottish Government’s Public Sector Pay Policy and negotiated with our recognised trade union, Unite. Salaries are reviewed annually in April for employees who commence employment prior to 1 October in the preceding year. Eligibility to join the Civil Service Pension Scheme. Support for continuous professional development. Support for health and wellbeing, including generous occupational sick pay, free access to confidential advice and support through our 24/7 Employee Assistance Programme. Support for travel to and from work, including a salary sacrifice cycle loan scheme, cycle storage and shower facilities, an interest-free loan for bus or rail season tickets. The Selection Process How to Apply: To apply, please send your CV and cover letter. The selection panel will use this evidence to assess your application against the selection criteria in the Person Specification. Expected Timeline: Your application will be reviewed by a Reed Recruitment Specialist who may invite you to an initial telephone screening call. Pre-Employment Checks: As part of our pre-employment process, we will ask you to provide relevant documentation to show that you are eligible to work in the UK and a Basic Disclosure Scotland certificate.