Public Sector Resourcing CWS

Public Sector Resourcing CWS

Aberdeen, Scotland

Chief Information Security Officer

Full-Time£100,000 - 100,000 per yearanteayerUnited Kingdom
IT

Job Description

Salary: £100,000 - 100,000 per year

Requirements:
  • Senior security leader (CISO, deputy CISO or head of security) with a track record in complex, fast-moving organisations, including standing up or substantially rebuilding a security function.
  • Executive-level ownership of security strategy, risk and assurance, including presenting risk clearly to boards and audit committees.
  • Operational accountability for detection, response and incident management, including selecting and directing an in-house, managed service or hybrid delivery model.
  • Strong knowledge of security standards and compliance, including the NCSC Cyber Assessment Framework, government security standards or comparable regulated regimes, and experience translating them into practical, proportionate controls.
  • Demonstrable expertise in strategic cyber security planning, governance, risk management, security architecture and incident management.
  • Experience securing major technology transitions, including cloud adoption, separation from shared or outsourced services, and programmes delivered through multiple partners.
  • Accountability for personal data security under UK GDPR, including breach response.
  • Ability to communicate security clearly and credibly to executives, boards and non-specialists.
  • Comfort working where structures and processes are still being established, making sound decisions at pace with imperfect information.
  • Willingness to govern and personally deliver key parts of our security capability.
  • Commitment to keeping abreast of changes in the security and regulatory landscape and our business.
  • Desirable: experience in energy, utilities or critical national infrastructure, including understanding operational technology and energy-system resilience.
  • Desirable: experience in government, arms-length bodies or other high-assurance settings, including working with the NCSC.
  • Desirable: experience exiting shared or outsourced services and establishing independently owned security operations.
  • Desirable: recognised security qualifications such as CISSP or CISM, or an equivalent demonstrable record.
  • Personal qualities: ownership, confidence in decision-making, constructive challenge, outcome focus, collaboration, inclusive relationship-building, adaptability, curiosity, resilience and resourcefulness.
Responsibilities:
  • Review the recorded security decision log from our establishment phase, confirm or adjust recommendations against the evidence, and carry decisions through to delivery.
  • Establish our security operating model and minimum security requirements, applying best practice and selecting which established ICS security foundations within DESNZ we carry forward.
  • Decide and implement our model for detecting and responding to attacks, with accountability documented at every stage of separation from shared services.
  • Confirm the standards we must meet, close priority gaps and establish an assurance regime reporting through the Digital Investment Governance Committee to the Audit, Assurance and Enterprise Risk Committee.
  • Secure our cloud, collaboration, staff identity and access environments as they are established, ensuring new services launch on secure foundations.
  • Establish practical incident-response plans, roles, on-call arrangements and exercises.
  • Baseline our security maturity, agree a target state and publish a prioritised improvement roadmap with clear ownership and progress measures.
  • Embed security requirements in our procurements and strategic partner framework, and assure our first major deliveries against them.
  • Develop the case and plan for our permanent security function, growing capability alongside the estate it protects.
Technologies:
  • Cloud
  • Incident Management
  • Support
  • Security
  • ARM
  • Architect
  • Exposed

More:

We are Great British Energy (GBE), a national public company working to power the UKs clean energy future through renewable-project development, investment and ownership. We aim to deliver benefits for communities and taxpayers, support jobs and local economies, and expand public ownership. Based in Aberdeen, this Chief Information Security Officer role reports to our Chief Digital & Information Officer and joins the small leadership group establishing our digital function. The postholder will advise on, coordinate and assure our approach to the NCSC Cyber Assessment Framework and the security of personal data under UK GDPR, helping us meet public-body and energy-sector standards. This is a greenfield opportunity: foundational security standards and operating-model work is underway, with decisions and their rationale recorded for the incoming leader to review and own. The role will initially work through delivery partners and transition arrangements with our incumbent provider while building our permanent function as our estate grows. We offer purpose-driven work, career development in clean-energy technologies and strategic investment, collaboration and flexible working, a competitive base salary, performance-related bonus, excellent pension, life assurance at four times salary, group income protection, 38 days annual leave, professional development and training, and a supportive, inclusive working environment. We welcome applications from all backgrounds and communities and can provide reasonable adjustments during recruitment.

last updated 40 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About Public Sector Resourcing CWS

Public Sector Resourcing CWS

Public Sector Resourcing CWS

Aberdeen

IT

Skills & Technologies

GoGitAIUI

Inferred from job description

Salary Insight

£100,000

This role

£55,000

UK median

This salary is 82% above the UK median for UK tech roles (£55,000/yr).

Based on 2024–2025 UK technology sector benchmarks

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom