
Are you an experienced information security professional looking for your next leadership challenge? Social Security Scotland is seeking a Security Risk and Assurance Manager to join our Digital Risk & Security Branch on a 12-month temporary basis (expected to extend to 15 months) to provide maternity leave cover.
This is a fantastic opportunity to lead a skilled team of Information and Security Officers and Security Risk Advisors, ensuring the agency maintains robust security governance, risk management and assurance arrangements. You'll play a key role in safeguarding the confidentiality, integrity and availability of information across the organisation while driving forward our ambitious security assurance, governance and risk programme.
As Security Risk and Assurance Manager, you will lead the delivery of security risk management, assurance, policy development, supply chain security assurance and security awareness activities across Social Security Scotland. Working closely with the Head of Security Assurance, senior stakeholders and colleagues across Digital, Delivery & Change you will ensure security controls remain effective, proportionate and aligned to organisational risk appetite and public sector security standards.
This is a high-profile and rewarding role, offering the opportunity to influence security strategy, support critical public services and make a meaningful difference to the people who rely on Social Security Scotland.
Responsibilities
Lead and manage the Security Risk and Assurance Team, ensuring delivery of high-quality cyber risk and assurance activities.
Act as the organisation's subject matter expert for Cyber Security Risk Management and Assurance, providing advice to stakeholders and project teams.
Lead cyber security risk assessments, assurance reviews and governance activities for systems, services and projects.
Oversee system release assurance processes, ensuring security requirements are met before implementation.
Manage the planning and delivery of IT Health Checks, vulnerability assessments and remediation activities.
Prioritise and allocate team workloads, ensuring timely delivery of objectives and continuous improvement of assurance services.
Support delivery of the Cyber Security Strategy and Cyber Assessment Framework (CAF) programme.
Produce security risk and assurance reporting for governance groups, senior management and key stakeholders.
Maintain and enhance Security Risk and Assurance processes, ensuring alignment with government and industry best practice, including ISO 27001 and CAF.
Promote security awareness, training and a strong security culture across the organisation.
Contribute to leadership team activities and represent Security Risk and Assurance within relevant governance forums.
Success Profiles
We use an assessment framework called ‘Success Profiles’ which lists the elements we test and provides detailed descriptions of each. Find out more about the framework here.
For this opportunity, the following Success Profile elements will be assessed:
Experience:
Demonstrable knowledge and experience of leading and managing a security risk, assurance and compliance function.
Specialist knowledge and understanding of information security standards with demonstrable experience in interpreting and applying information assurance legislation and policies (ISO27001, NIST, SG Cyber Resilience Framework, NCSC Cyber Assessment Framework, GDPR, DPA 2018, etc)
Demonstrable experience of applying risk management methodologies and their implementation.
In-depth knowledge and understanding of both internal and external information security risks to information which could affect confidentiality, integrity and availability.
How to apply
Please apply online, providing a Supporting Statement (of no more than 500 words) providing evidence of how you demonstrate the Success Profiles noted above.
Please note that a CV is not required for this opportunity.
Artificial Intelligence (AI) tools can be used to support your application, but all statements and examples provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, and presented as your own) applications will be withdrawn and internal candidates may be subject to disciplinary action.
Please see our candidate guidance for more information on acceptable and unacceptable uses of AI in recruitment.
If you are interested in this opportunity, you should seek permission from your manager and C-band manager before applying on a level transfer (TLT) basis.If applying on Temporary Promotion you should inform your manager and C-band manager from the outset of your intention to apply. If successful in your application, your release must be agreed by your line manager and C-band manager or relevant unit head.
Please note that the post is only open to individuals who have satisfactorily completed their probationary period.
This is a Government Digital and Data (GDD) role within the Cyber Security and Information Assurance job family. Candidates who are not currently members of the GDD Profession, or who belong to a different GDD job family, will be required to complete a GDD technical assessment before an appointment can be confirmed.
If you are successful following the informal discussion and a technical assessment is required, further details will be provided in advance to allow you sufficient time to prepare.
Dates to Remember
Statement submitted by: 25th August at 12pm 2026
Informal chats: Week commencing 7th September 2026 (this may be subject to change).
Duration of Temporary Opportunity
This opportunity is for 12 months will likely be extended to 15 months to cover maternity leave.
GDD Pay Supplement
This post is part of the Government Digital and Data (GDD) profession and currently attracts a £4000 annual GDD pay supplement, which is paid monthly - pay supplements are reviewed regularly.
Hybrid Working
Our standard hours are 35 hours per week, and we offer a range of flexible working options, depending on the needs of the role. We embrace a hybrid working style where all colleagues will spend time in either our Glasgow or Dundee offices. There is an expectation of a minimum 2 days per week in your assigned location.
Further Information
This role is only available to existing permanent civil servants who have successfully completed their probation period within Social Security Scotland, Scottish Government Main or Common Citizenship organisations. Please note that applicants from Common Citizenship organisations may apply only on a promotion basis and not via a level transfer.
Social Security Scotland are a Disability Confident Employer. We will consider and implement any reasonable adjustments you may require throughout the recruitment process and during the course of your employment, should you be successful in securing a post. If you feel you may require assistance with any part of our recruitment process, please contact us at recruitment@socialsecurity.gov.scot
If you experience any difficulties accessing our website or completing the online application form, please contact the Resourcing Team via recruitment@socialsecurity.gov.scot
If you have any questions about the role please contact Antony Bernstein at Antony.Bernstein@socialsecurity.gov.scot

The devolved government for Scotland is responsible for matters that are devolved from Westminster. Areas of responsibility include the economy, health, education, justice, rural affairs, environment, and transport.