Indeed
Lead Security Architect
**Details**
-----------
### **Reference number**
418052
### **Salary**
£74,480 - £85,964
This post is part of the Scottish Government Digital, Data and Technology (DDAT) profession, as a member of the profession you will join the professional development system. This post currently attracts a £5,000.00 annual DDAT pay supplement, applicable after a 3-month competency qualifying period. The payment will be backdated to your start date in the role. Pay supplements are reviewed regularly and there is one currently underway. Changes will be communicated when the review is concluded.
A Civil Service Pension with an employer contribution of 28.97%
GBP
### **Job grade**
Grade 6
C2
### **Contract type**
Permanent
### **Type of role**
Digital
### **Working pattern**
Full-time
### **Number of jobs available**
1
**Contents**
------------
* Location
* About the job
* Benefits
* Things you need to know
* Apply and further information
**Location**
------------
Leith, Scotland, EH6 6QQ : Glasgow, Scotland, G2 8LU
**About the job**
-----------------
### **Job summary**
Do you want to help shape the future of secure digital public services in Scotland?
The Scottish Government's digital strategy, *A Changing Nation: How Scotland Will Thrive in a Digital World* , sets out specific actions for transforming government, aligned to the National Performance Framework. Of most relevance to this role is the aim to build a suite of common platforms to be adopted across the public sector.
This role sits within the Digital Components \& Infrastructure Division, part of the Scottish Government's Digital Directorate. The division brings together three key programmes Digital Identity, SG Payments, and the SG Cloud Platform---focused on achieving this strategic outcome. All three are aligned with the 2021 Digital Strategy's commitment to developing common platforms and component technologies to improve efficiency in the delivery of public services across Scotland's public sector.
As a divisional role, this post will initially be part of a multi-disciplinary SG Cloud Platform Service team working to transform how the Scottish Government facilitates cloud hosting across the Scottish public sector and the Digital Identity team providing people with a secure and simple way to access public services online.
Both services are central to the wider common platforms' objective outlined in the Digital Strategy. They play a key role in ensuring that valuable public services are delivered securely, efficiently, and accessibly.
In addition to supporting the development and operation of these platforms, as Lead Security Architect you will contribute to the wider division's efforts and help promote the adoption of common platforms across the Scottish public sector. Working at scale and with a wide variety of public service users, our work is technically complex, varied, and rewarding---offering a real sense of pride in making a positive, tangible difference in people's lives.
### **Job description**
* Lead the SG Cloud Platform Service and other platforms within the division security architecture (including SABSA and NIST CSF).
* Own and maintain security vision, strategy, and baseline standards.
* Evaluate security risks and lead architectural decisions balancing business needs.
* Act as the escalation point for all security architecture matters.
* Support secure practices and toolchains.
* Influence stakeholders and advise on security across the division.
* Contribute to service decision making forums, design authorities and cross-government security communities.
* Support assurance processes and digital service assessments.
* May line manage Security Architects, Engineers, and/or Analysts.
### **Person specification**
**Success Profile**
Success profiles are specific to each job, and they include the mix of experience, skills and behaviours candidates will be assessed on.
**Experience:**
* **Lead Criteria 1:**Understand security implications of digital transformation; challenge and lead changes to policy and processes to support business outcomes, business architecture, and legal and political implications with associated experience in designing secure solutions using industry standard tools and techniques.
* **Lead Criteria 2:** Demonstrate a deep understanding of security concepts and can apply them to a technical level and effectively translate and accurately communicate security and risk implications to technical and non-technical stakeholders.
* Experience of both assuring 3rd party architecture designs ensuring adherence to agreed policies, standards, and design patterns and also assuring project outputs against agreed architectural design.
* Experience of implementing technical security controls and standards in a variety of modern cloud applications using autonomic infrastructure including Amazon Web Services and/or Azure environments. Standards should ideally include ISO 27001, NCSC CAF, OWASP ASVS and CIS Benchmark.
**Technical Skills:**
This role is aligned to the Security Architect within the Cyber Security and Information Assurance job family.
You can find out more about the skills required, here.
These skills are assessed by technical assessment, designed to represent the role. Candidates reaching this stage will receive a Technical Assessment Candidate Pack which outlines the specific skills to be assessed, plus the method of assessment.
**Behaviours:**
* Making Effective Decisions -- (Level 4)
* Working Together - (Level 4)
You can find out more about Success Profiles Behaviours, here.
Behaviours are assessed at interview. Full details will be shared in advance with all candidates invited to this stage.
**Benefits**
------------
Alongside your salary of £74,480, Scottish Government contributes £21,576 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.
* Learning and development tailored to your role
* An environment with flexible working options
* A culture encouraging inclusion and diversity
* A Civil Service pension with an employer contribution of 28.97%
**Things you need to know**
---------------------------
### **Selection process details**
**How to apply**
Apply online, providing a CV and Supporting Statement (of no more than 750 words) which provides evidence of how you meet each of the **4 Experience** criteria listed in the Success Profile above.
Candidates will have their applications assessed against all Experience criteria. If a large number of applications are received an initial sift will be conducted on the Lead Criteria highlighted above. Candidates who pass the initial sift will have their applications fully assessed.
If invited for further assessment, this will consist of an interview and DDaT Technical assessment where the behaviours, experiences and technical skills outlined in the Success Profile will be assessed.
The sift is scheduled for w/c 11th August.
Interviews and DDaT Technical assessments are scheduled for w/c 25th August, however these may be subject to change.
Feedback will only be provided if you attend an interview or assessment.
### **Security**
Successful candidates must undergo a criminal record check.
People working with government assets must complete baseline personnel security standard (opens in new window) checks.
### **Nationality requirements**
This job is broadly open to the following groups:
* UK nationals
* nationals of the Republic of Ireland
* nationals of Commonwealth countries who have the right to work in the UK
* nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS)
* nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
* individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
* Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Further information on nationality requirements
### **Working for the Civil Service**
Please note this Post is NOT regulated by the Civil Service Commission.
The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.
### **Diversity and Inclusion**
The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan and the Civil Service Diversity and Inclusion Strategy .
**Apply and further information**
---------------------------------
This vacancy is part of the Great Place to Work for Veterans initiative.
Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.
### **Contact point for applicants**
#### **Job contact :**
* Name : Digital Recruitment Service
* Email : Digitalcareers@gov.scot
#### **Recruitment team**
* Email : scottishgovernmentrecruitment@gov.scot

Leith, Edinburgh, UK