Head of IT Security

1 week ago


Aberdeen, United Kingdom North Sea Transition Authority Full time £150 - £200

Head of IT Security role at North Sea Transition AuthorityRead on to find out what you will need to succeed in this position, including skills, qualifications, and experience.Brief overview of roleAs a senior member of the IT and Digital team this role is responsible for safeguarding NSTA’s digital assets, systems, and data against evolving cyber threats, providing strategic leadership in developing and ensuring compliance with security policies, proactive risk management, continuous monitoring of security posture, and rapid response to incidents to minimise operational disruption.The role acts as the primary authority on cybersecurity within the organisation, advising senior leadership on emerging risks, regulatory changes, and resilience strategies. In addition, the role champions a culture of security awareness, ensuring that employees and contractors understand their responsibilities in protecting sensitive information.Detailed job description and key responsibilitiesThe IT Security Manager plays a pivotal role within the organisation, actively engaging with the wider business to monitor, report, and evaluate the security of its digital services. In addition, they provide essential support to the Chief Digital Officer in implementing and delivering the Digital/Data and IT Strategies, ensuring alignment with business objectives and maintaining robust security standards.Transform access to informationDeliver secure and resilient IT and information security services, safeguarding networks, infrastructure, and systems through robust configurations and compliance with recognised standards.Embed security by design in all new systems, APIs, and datasets, ensuring alignment with legislation and frameworks such as GDPR, Data Protection Act 2018, NCSC guidance, and ISO27001.Implement and maintain data protection practices, including applying retention and classification labels to support compliance and effective records management.Collaborate across IT, digital, and business teams to integrate security principles into projects and change initiatives, providing expert input throughout the lifecycle.Analytics and IntelligenceImplement advanced security monitoring and risk management capabilities—including Third Party Risk Management (TPRM), vulnerability scanning, Dark Web monitoring, and annual health checks (penetration testing, vulnerability assessments)—to proactively identify and mitigate threats.Lead incident response and security operations, acting as the primary authority for IT security events, ensuring effective investigation, containment, recovery, and forensic analysis, and coordinating resolution of breaches and vulnerabilities.Provide clear visibility of security posture through regular reporting on risks, incidents, and remediation progress to senior leadership, supporting informed decision‑making and continuous improvement of cyber resilience.Collaborate, partner and assureDevelop and maintain cyber and IT strategies in collaboration with the Chief Digital Officer, including systematic reviews of legacy systems and securing leadership approval for a comprehensive five‑year security plan.Oversee delivery of IT security services and operations, including Security Operations Centre (SOC) capabilities, ensuring alignment with strategic goals, compliance with frameworks (Cyber Essentials Plus, GovAssure/CAF), and continuous improvement through regular assessments and remediation.Embed security standards and architecture across projects and systems, collaborating with IT, PMO, service providers, and directorates to ensure security‑by‑design and adherence to NCSC guidance, GDPR, and ISO27001.Manage organisational cyber risk and governance, including monitoring risk registers, enforcing policies and standards, managing budgets, and providing recommendations to strengthen security posture and resilience.InfluenceRepresent NSTA in industry and government forums, including serving as Co‑Chair of the SOCS forum, participating in cross‑industry cyber working groups, and promoting the organisation’s approach to cyber security and digital resilience at external events.Act as a subject‑matter expert (SME) for IT, cyber security, and digital enquiries, maintaining strong liaison with security networks to share best practices and enhance collaborative security initiatives.Provide governance and compliance oversight, preparing reports for Security Advisory Board (SAB), Audit Risk Committee (ARC), and leadership teams, maintaining a register of legal and regulatory obligations, and raising awareness of changes and their organisational impact.People, culture and skillsLead and manage a high‑performing records management team, ensuring compliance with regulatory requirements and organisational standards.Lead and deliver cyber security awareness initiatives—including phishing simulations, mandatory training, and information security sessions—while monitoring compliance and completion rates across the organisation and service partners.Champion a robust security culture by embedding emerging security requirements into practices and continuously improving training programmes through gap analysis and targeted interventions to strengthen cyber resilience.Specialist skills, qualifications, experience, licences, memberships or languageProfessional Certifications: CISM (Certified Information Security Manager) and/or CISSP (Certified Information Systems Security Professional).Leadership & Communication: Strong ability to lead teams, communicate effectively, and manage diverse stakeholders.Technical Expertise: Comprehensive knowledge of IT environments, including Windows servers and desktops, cloud platforms, networking, applications, security, and virtualised systems.Security Framework Implementation: Demonstrated experience in designing, developing, and implementing information security frameworks, tools, and processes at a technical level.Supplier & Contract Management: Proven track record in managing outsourced service contracts and procurement activities.IT Security Operations: experience overseeing and managing IT security operations.Risk & Compliance Awareness: In‑depth understanding of IT security risks and cyber security challenges, particularly within the public sector.Change & Transformation: Experience driving change management and implementing transformational IT security initiatives.Network & Firewall Expertise: Skilled in network and firewall design, configuration, and applying security principles, including IT auditing practices.Access Control Systems: Familiarity with tools and systems for access security control (e.g., ACF2) to prevent unauthorised system access. xpwpeyx Risk Management & Resilience: Knowledge of risk management methodologies, business impact analysis, and contingency planning for IT service disruptions, including resilience strategies, fallback locations, backups, and diversity measures.Experience of public sector / government regulatory environment / energy sectorSeniority level: Mid‑Senior levelEmployment type: Full‑timeJob function: Information TechnologyIndustries: Oil and Gas, IT Services and IT Consulting, Computer and Network Security#J-18808-Ljbffr


  • Head of IT Security

    1 week ago


    Aberdeen City, United Kingdom North Sea Transition Authority Full time

    Head of IT Security role at North Sea Transition Authority Brief overview of role As a senior member of the IT and Digital team this role is responsible for safeguarding NSTA’s digital assets, systems, and data against evolving cyber threats, providing strategic leadership in developing and ensuring compliance with security policies, proactive risk...

  • Head of IT Security

    7 days ago


    Aberdeen City, United Kingdom North Sea Transition Authority Full time

    Brief overview of role As a senior member of the IT and Digital team this role is responsible for safeguarding NSTA’s digital assets, systems, and data against evolving cyber threats, providing strategic leadership in developing and ensuring compliance with security policies, proactive risk management, continuous monitoring of security posture, and rapid...

  • Head of IT Security

    7 days ago


    Aberdeen City, United Kingdom North Sea Transition Authority Full time

    Brief overview of roleAs a senior member of the IT and Digital team this role is responsible for safeguarding NSTA’s digital assets, systems, and data against evolving cyber threats, providing strategic leadership in developing and ensuring compliance with security policies, proactive risk management, continuous monitoring of security posture, and rapid...

  • IT Security Manager

    3 weeks ago


    Aberdeen, United Kingdom Hays Technology Full time

    IT Security Manager Location: Aberdeen (Hybrid - 40% in office attendance each quarter) Package: Up to £76,000 plus generous pension (28% employer contribution) About the Role I'm working with an Aberdeen-based client who are looking for an IT Security Manager (Head of) to safeguard its digital assets and systems against evolving cyber threats. This is a...

  • IT Security

    1 week ago


    Aberdeen, United Kingdom North Sea Transition Authority Full time £150 - £200

    An entity in the energy sector is seeking a Head of IT Security to safeguard digital assets against cyber threats.Be one of the first applicants, read the complete overview of the role below, then send your application for consideration.This role requires strategic oversight of IT security operations, policy compliance, and risk management.The ideal...

  • IT Security Manager

    7 days ago


    Aberdeen, United Kingdom Hays Full time

    IT Security ManagerLocation: Aberdeen (Hybrid - 40% in office attendance each quarter)Package: Up to £76,000 plus generous pension (28% employer contribution)About the RoleI'm working with an Aberdeen-based client who are looking for an IT Security Manager (Head of) to safeguard its digital assets and systems against evolving cyber threats. This is a senior...

  • IT Security Manager

    7 days ago


    Aberdeen, United Kingdom Hays Full time

    IT Security Manager Location: Aberdeen (Hybrid - 40% in office attendance each quarter) Package: Up to £76,000 plus generous pension (28% employer contribution) About the Role I'm working with an Aberdeen-based client who are looking for an IT Security Manager (Head of) to safeguard its digital assets and systems against evolving cyber threats. This is a...

  • IT Security

    1 week ago


    Aberdeen City, United Kingdom North Sea Transition Authority Full time

    An entity in the energy sector is seeking a Head of IT Security to safeguard digital assets against cyber threats. This role requires strategic oversight of IT security operations, policy compliance, and risk management. The ideal candidate possesses professional certifications (CISM or CISSP) and has extensive experience in IT security frameworks. The...


  • Aberdeen, United Kingdom Scottish Legal Aid Board Full time

    We are seeking to recruit a **Head of Office** (Grade 7) for the Civil Legal Assistance Office (CLAO) in Aberdeen. This is an excellent career progression opportunity for an experienced litigator with an interest in social welfare law and leading a team. **Starting salary** is £49,420, within a pay band up to £57,490 (pro rata if part time). **About...


  • Aberdeen, United Kingdom Acteon Group Full time £150 - £200

    Job Details: Head of Engineering and TechnologyFull details of the job.Vacancy NameVacancy Name Head of Engineering and TechnologyVacancy NoVacancy No VN3598Operating CompanyOperating Company Claxton Engineering Services GroupAdvertAdvert Claxton is a part of Acteon Group of subsea services businesses. We combine experienced Project Engineering and fast...