As the Cyber Risk & Compliance Lead at the Scottish Funding Council, you will champion our cybersecurity initiatives, ensuring the protection of our operations, data and technologies in alignment with UK-specific cybersecurity standards and frameworks. This role is critical in maintaining the SFC’s reputation for excellence and integrity in the funding of education and research across Scotland.
As well as a competitive salary of £62172 - £73326 per annum, the role also has an M1 Grade, 28.97% employer contribution civil service pension, flexible working hours, hybrid working + up to £10k annual retention allowance.
Key Responsibilities
Develop and implement a cyber risk management framework tailored to the specific needs and challenges of the SFC, focusing on the protection of financial data, personal information of students and staff, and sensitive research data.
Ensure full compliance with Scottish and UK data protection laws, as well as adherence to specific regulations relevant to our organisation and our internal and external audit obligations.
Collaborate closely with academic institutions, research bodies, and government agencies to align cyber security practices and foster a culture of shared responsibility and leading practices in data protection and risk management.
Lead the review and enhancement of policies, procedures, and controls governing data security, risk assessment, and compliance within the funding council’s operations.
Conduct targeted cyber risk assessments and compliance audits, providing strategic insights and recommendations to the SFC’s senior management and governing board.
Act as a principal advisor on cyber security matters, offering expert guidance to support the council’s strategic initiatives in funding education and research.
Stay abreast of emerging cyber threats and advancements in cyber security technologies and practices, ensuring the SFC remains proactive and responsive in its cyber risk and compliance strategies.
Skills, Knowledge and Expertise
It is important through your CV / Cover Letter that you give evidence of proven experience of each of the following essential criteria:
Proven track record in cybersecurity risk management, with a strong understanding of the UK cybersecurity landscape, including Cyber Essentials, ISO 27001 frameworks.
Familiarity with the NCSC’s guidelines and recommendations for public sector organisations.
Experience in managing cybersecurity compliance projects within the UK, including the attainment of Cyber Essentials certification.
Leadership experience with the ability to mentor a team and drive cybersecurity awareness across an organisation.
Excellent communication and influencing skills, capable of engaging effectively with a range of stakeholders on complex cybersecurity issues to ensure change is adopted and sustained.
Professional Certifications:
Holding or working towards UK-recognized cybersecurity certifications, such as those offered by CREST or Cyber Essentials Plus, is highly desirable.
Additional certifications such as CISSP, CISM, or ISO 27001 Lead Auditor/Implementer would be beneficial.
Proud member of the Disability Confident employer scheme
Disability Confident
About Disability Confident
A Disability Confident employer will generally offer an interview to any applicant that declares they have a disability and meets the minimum criteria for the job as defined by the employer. It is important to note that in certain recruitment situations such as high-volume, seasonal and high-peak times, the employer may wish to limit the overall numbers of interviews offered to both disabled people and non-disabled people. For more details please go to Disability Confident .