Job Summary: Reporting to the Assistant Director, Information Governance you will lead on responding to information rights requests and fulfil the role of the Data Protection Officer - a key role within SFC. You will work in close partnership with senior leaders, including the Senior Information Risk Officer and Chief Information Officer, supporting the Assistant Director to deliver the Information Governance Framework and leading on associated activities. As an experienced Information Rights and Data Protection practitioner, you will be skilled in dealing with sensitive, complex information at pace, building trusted relationships with colleagues across SFC, and you will exercise good judgement in responding to information rights requests. You will be expected to work flexibly across the responsibilities of the information governance team, stepping in to provide cover and support when required to ensure deadlines are met. A keen understanding of the strategic context within which the SFC is working will be key to success in this role.
Key Responsibilities:
1. Leading the response to information rights requests, providing advice to colleagues across SFC, ensuring legal compliance with relevant legislation.
2. Provide an efficient and effective senior contact point for queries in relation to information rights and data protection including complex ones.
3. Ensure staff fully understand their responsibilities within data protection legislation and information rights and follow relevant processes, evidenced through reporting and auditing.
4. Promote an information governance culture and an understanding of data protection compliance throughout the organisation.
5. Inform and advise SFC staff, including senior leaders, about their obligations to comply with the UK GDPR and other relevant data protection laws taking into account the nature, scope, context and purposes of the processing.
6. Develop and maintain effective coordination and liaison with our stakeholders and external partners.
7. Identify opportunities to improve ways of working within Information Governance and implement positive change.
8. Manage and advise on internal data protection activities, for example supporting colleagues to deliver Data Protection Impact Assessments and Data Sharing Agreements.
9. Develop and maintain SFC’s Records of Processing Activities (RoPA) to ensure that it is accurate and regularly reviewed and information asset owners understand their responsibilities.
10. Co-ordinating with Information Governance colleagues, assess and respond to personal data breaches, including reporting to senior management and the ICO as required.
11. Identify and implement improvements to data protection and information rights compliance based on user requirements and best practice.
12. Contribute, make recommendations and report to the Information Governance Oversight Group on data protection and information rights development and compliance, including risks, trends, good practice, mitigation, and training.
13. Monitoring SFC’s compliance with the UK GDPR and other data protection laws and with our data protection policies, raising awareness of data protection issues, training staff and conducting audits.
14. Being the first point of contact for the ICO and for internal and external stakeholders, including data subjects.
15. Support the formulation, implementation and regular review of policy and guidance to ensure that data protection and information rights policies meet all relevant legislation and best practice.
Person specification:
Essential Requirements:
1. Experience administering Azure Services: M365, App Service, Azure SQL, Blob Storage, Key Vault, ExpressRoute, Virtual machines, Virtual Networks.
2. Experience of Azure Migration, migrating on-premises solutions to the cloud using Azure Migrate (or other) tools.
3. Experience with Continuity of Operations/Disaster Recovery architecture and planning.
4. Extensive and applied experience administering Windows Server OS 2016 and above (Standalone & Cluster) patching, domain admin, network configuration, security monitoring.
5. In-depth technical knowledge of Microsoft Azure and On-Prem infrastructure components and how they integrate with one another.
6. In-depth knowledge of Azure Security Centre and Azure Monitor: Network, Application, Infrastructure.
7. In-depth knowledge of multi factor authentication (Azure MFA preferred), Microsoft AD Integration with Cloud Applications/Microsoft Azure Active Directory.
8. Good working knowledge of Network administration and VPN administration.
9. Good working knowledge of Active Directory Services including DNS, DHCP, and DFS.
10. Qualifications: Microsoft Cloud Certification, at least one of the following (AZ-400, AZ-303, AZ-104).
11. Good interpersonal and communication skills.
12. Proven track record of delivering high quality and effective outputs within time and resource constraints.
13. Ability to work collectively and with impact as part of a team.
Desirable Criteria:
1. Experience of performing the Data Protection Officer role, preferably in a public sector context.
2. Experience of enhancing the information governance culture in an organisation, preferably within a public sector context.
Additional information:
Location: SFC offers hybrid working for its employees. This means that whilst the role is based at our Edinburgh office, there is substantial opportunity to work from home most of the time. As a rule of thumb SFC expects that a minimum of one day a month in the office will achieve the benefits of its hybrid approach, however it is for the employee and their line manager to agree the balance between home and workplace working - determined primarily by business need. Please be aware that this role can only be worked from within the UK and not overseas. Relocation...
#J-18808-Ljbffr