
Chief Information Security Officer
Job summary
DBS was established under the Protection of Freedoms Act 2012 on 1 December 2012, working
from two sites, which are Liverpool and Darlington. We operate on behalf of government
delivering Disclosure functions in England, Wales, Jersey, Guernsey and the Isle of Man, and
Barring functions for England, Wales, and Northern Ireland. We function within a framework of
legal and regulatory requirements and that includes work with a range of external organisations
including other government departments, regulators, and trade bodies.
We provide a service that enables organisations in the public, private and voluntary sectors to
make better informed, safer recruitment and other decisions. We do this by providing information
to enable them to determine whether individuals are unsuitable or unable to undertake certain
work, particularly with occupations involving regular contact with vulnerable groups, including children.
Our Strategy
Our current Strategy sets out our purpose, vision, and the impacts we want to achieve. Our
strategy was co-created with our staff and has been supported by insight from our various
partners, and throughout, you will find our ambitions to be achieved. Everything that we do within
DBS, from developing our strategic intent, to the day-to-day operational delivery of our services,
is underpinned by constant considerations of safeguarding, quality, sustainability, value for
money, and diversity and inclusion. Our strategic objectives aim to enhance our effectiveness,
influence, and customer satisfaction while fostering a supportive environment for everyone.
Equality, Diversion, and Inclusion at DBS
DBS is committed to fostering an environment that values individual differences and ensures fair
treatment to unlock the full potential of staff and better support customers. Equality, diversity,
and inclusion (EDI) are core to driving organisational success and we have developed specific
equality objectives for DBS.
Every decision and activity will be considered through an EDI lens, aiming to build an inclusive
culture, improve policies and practices, gain external assurances, and become a leading voice of
good practice in EDI.
Read More
For further information, please see below for a collection of DBS strategies and business plans:
• DBS strategies - GOV.UK
• DBS business plans - GOV.UK
Job description
Job Purpose:
The Chief Information Security Officer will provide senior organisational leadership for
information, cyber, operational security and data protection across DBS, setting and
implementing a clear strategy that supports DBS’s organisational strategy, safeguarding
mission, digital transformation priorities, statutory data protection duties and wider government
security expectations. The role will also act as DBS’s Data Protection Officer, providing
independent advice, challenge and assurance on compliance with UK GDPR, the Data
Protection Act 2018, law enforcement processing requirements where applicable,
organisational data protection policies and ICO expectations. The role will be accountable for
the effective operation of security controls, monitoring, incident management, vulnerability
management, supplier security and operational security assurance across live services and
change activity. The role will evaluate DBS’s current information and cyber security maturity,
define the level of maturity needed for a modern, resilient and digitally enabled safeguarding
organisation, and lead the practical plan to close that gap. The post holder will create the
environment, culture and operating model needed to protect DBS information, personal data,
technology and services, enabling innovation to happen safely, lawfully and securely while
ensuring DBS can prepare for, detect, respond to and recover from cyber attacks.
This is a senior leadership role, not a purely technical cyber post. The successful candidate will
be expected to understand risks across DBS, advise the Board, Executive Team, SIRO and
senior leaders on how to mitigate cyber, information and data protection risks in their areas and
future plans, and ensure the information security, cyber security and data protection aspects of
crisis management are effective. As Data Protection Officer, they must be involved in a timely
manner in issues relating to the protection of personal data, provide expert advice on data
protection obligations and DPIAs, monitor compliance, support awareness and training, and act
as a contact point for the Information Commissioner’s Office. They will translate complex cyber,
information risk, privacy and resilience issues into clear choices for executive decision-makers,
while building a capable, sustainable and accountable security and data protection function that
supports DBS’s transition to modern digital services, a secure-by-design model and a stronger
Target Operating Model.
Corporate Duties:
• Act as DBS’s senior organisational leader for information security, cyber security,
operational security and data protection, setting direction and providing clear, evidence
based advice to the Executive Director of Technology and Innovation, Board, Executive
Team, Audit and Risk Committee, SIRO and senior risk owners.
• Create, own and lead the DBS information, cyber and operational security strategy and
roadmap, ensuring it directly supports the organisation’s strategy, safeguarding mission,
digital transformation, live service resilience and wider government security strategy,
including Government Functional Standard GovS 007: Security, the Government Cyber
Security Standard, the Cyber Assessment Framework, GovAssure, Secure by Design
principles and relevant NCSC guidance.
• Lead the organisation in implementing the information, cyber and operational security
strategy, turning strategic intent into clear priorities, funded delivery plans, measurable
outcomes, operational controls and mature security practices embedded across DBS.
• Act as DBS’s Data Protection Officer, operating with the independence, senior access,
expertise and resources required by data protection law, and providing advice, challenge
and assurance on UK GDPR, the Data Protection Act 2018, law enforcement processing
requirements where applicable and wider data protection obligations.
• Shape a new cyber operating model for DBS, defining the right balance of in-house
capability, specialist consultancy, supplier support and managed services, with clear
accountabilities, decision rights and routes for increasing maturity over time.
• Be accountable for operational security across DBS technology services, ensuring
effective security monitoring, protective controls, access management, vulnerability
management, threat intelligence, security operations, incident triage and remediation are
in place and operating effectively.
• Build organisational confidence in cyber security by translating technical risk into plain
English, proportionate choices and practical action for executive, operational and
delivery audiences.
• Advise the Board, Executive Team and senior leaders on organisational cyber and
information risk, helping them understand their accountabilities and make proportionate
decisions to mitigate risk in current operations, change programmes and future plans.
• Advise the Board, Executive Team, SIRO, Information Asset Owners and senior leaders
on data protection risk, privacy by design, lawful processing, data sharing, retention,
data subject rights, personal data breaches and the implications of new services,
technology and operating models.
• Promote a culture where secure behaviours, cyber awareness and good information
handling are understood as core responsibilities for everyone, not just the security
function.
• Work as a senior member of the Technology and Innovation leadership team,
contributing to departmental strategy, prioritisation, culture, financial control, supplier
management and the successful delivery of DBS’s technology ambitions.
• Represent DBS with Home Office, Cabinet Office, Government Security, NCSC and
other external partners where required, ensuring DBS is aligned to relevant government
security policy, standards, assurance expectations and good practice.
Operational Delivery Duties
• Evaluate the current status and maturity of DBS information and cyber security, using
recognised government and industry frameworks where appropriate, and define thepractical route to the level of maturity required for a modern, resilient and digitally
enabled safeguarding organisation.
• Establish effective cyber governance, reporting and assurance, giving senior leaders a
clear view of risk, control effectiveness, investment choices, incidents, vulnerabilities and
supplier exposure.
• Own and continually improve the operational security model for DBS, including security
operations, monitoring, alerting, incident triage, vulnerability management, patching
oversight, privileged access controls, protective monitoring, threat-led assurance and
supplier operational security performance.
• Ensure DBS can demonstrate alignment with relevant government security requirements
and assurance routes, including GovS 007, the Government Cyber Security Standard,
CAF profiles, GovAssure, Secure by Design, NCSC guidance, the Technology Code of
Practice and applicable data protection and information assurance obligations.
• Monitor DBS compliance with UK GDPR, the Data Protection Act 2018, applicable law
enforcement processing requirements, organisational data protection policies and ICO
expectations, ensuring responsibilities are clear, evidence is maintained and
improvement actions are tracked to completion.
• Provide advice on Data Protection Impact Assessments, privacy by design, records of
processing activity, data sharing, data subject rights, retention, lawful basis, special
category data, criminal offence data and personal data breach management.
• Act as the primary contact point for the Information Commissioner’s Office on data
protection matters and ensure DBS can evidence timely, well-governed handling of
regulatory engagement, personal data breaches and data protection assurance activity.
• Work with service owners, product teams, architecture, suppliers and operational teams
to ensure security controls remain effective in live service, are monitored through clear
metrics, and are improved where risk, threat or operational performance requires it.
• Determine the controls, capabilities, investment, skills, supplier arrangements and
behavioural changes needed to reach the target level of maturity and hold delivery
partners to account for progress.
• Ensure DBS is prepared for cyber-attacks and can detect, respond to and recover from
incidents, with clear crisis arrangements, tested playbooks, escalation routes,
communication plans and links into wider business continuity, operational resilience and
crisis management arrangements.
• Provide senior security leadership into major change and digital transformation,
including any major transformation of platforms, data, integration and service
modernisation activity.
• Lead proportionate security assurance across new products, systems, services and
suppliers so that security is designed in early, risks are understood, decisions are
auditable and innovation can proceed safely rather than being slowed by late-stage
security intervention.
• Develop cyber awareness, data protection awareness, information handling discipline
and good security behaviours across DBS, embedding practical guidance, learning and
leadership messages that make secure, lawful and responsible handling of information
part of everyday work.
• Lead, develop and hold to account a multidisciplinary cyber function, including
permanent staff, contractors, consultants and suppliers, ensuring knowledge transfer
and growth of sustainable internal capability.
Management of Finances:
Be accountable for allocated information and cyber security budgets, ensuring value for
money, effective prioritisation and transparent investment decisions.
• Provide clear recommendations on cyber investment, balancing risk reduction,
regulatory expectations, operational resilience, affordability and the pace of DBS
transformation.
Person specification
Essential Criteria:
Ability to operate credibly at senior level, advising Boards, Executive Teams, SIROs, Information Asset Owners and senior risk owners on cyber, information, operational security and data protection risk, resilience, investment, crisis readiness and security trade-offs across current operations and future plans.
Significant experience of leading information security, cyber security, operational security and data protection in a complex organisation, including strategy
creation and implementation, maturity assessment, operating model design, governance, risk management, assurance, incident response, crisis management,
cultural change, supplier security and regulatory engagement.
Significant experience of leading information security, cyber security, operational security and data protection in a complex organisation, including strategy
creation and implementation, maturity assessment, operating model design, governance, risk management, assurance, incident response, crisis management,
cultural change, supplier security and regulatory engagement.
Desirable Criteria:
Ability to lead through ambiguity, build confidence across a changing organisation and translate complex security issues into clear, proportionate
action.
Experience of operating in government, policing, justice, safeguarding, regulated services or another high-trust environment where public confidence,
legal duties and operational resilience are critical.
Knowledge of government security standards, data protection obligations and assurance expectations, including GovS 007, the Government Cyber
Security Standard, CAF, GovAssure, Secure by Design, NCSC guidance, ICO guidance, ISO 27001, NIST, UK GDPR, the Data Protection Act 2018 and the
Government Digital and Data / Government Security profession frameworks.
Benefits
Alongside your salary of £100,000, Disclosure & Barring Service contributes £28,970 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).The DBS offers a number of excellent benefits for its employees. These can include:
- Generous annual leave entitlement
- Excellent maternity, paternity and adoption schemes (after a qualifying period)
- Commitment to the health and wellbeing of our employees
- Employee Assistance Programme
- Flexible working opportunities
- Eyecare voucher scheme
- Occupational Health Service including referrals for counselling and physiotherapy
- 24/7 Counselling and Wellbeing Service
- A Civil Service Pension with an employer contribution of 28.97%
The DBS vision and purpose is to make people safer by being a visible, trusted and influential organisation, providing an outstanding quality of service to all our customers and partners, where our people understand the important safeguarding contributions they make and feel proud to work here. To do this, the DBS is committed to being an employer that is able to attract, develop, retain and engage diverse talent that is representative of the communities we serve, and to be an organisation providing outstanding service to all our existing and new customers, who are diverse and have a range of different needs. We want all our staff to be able to bring their ‘whole self’ to work.
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.Selection process details
DBS has appointed executive search specialists Gatenby Sanderson to support us with this appointment.
To apply for this please click the link below:
Your application should include:
- A current CV, including your educational and professional qualifications and full employment history (explaining any gaps), with details of budgets and teams managed and highlighting key achievements.
- A covering letter, no more than two A4 pages, explaining why this appointment interests you and how you meet the criteria set out in the candidate profile (please note that references and open-source due diligence checks (including into social media accounts) may be undertaken for all short-listed candidates)
The anticipated timetable is as follows:
Closing Date: 9am on Monday 5 October 2026
Long Listing: Week commencing 12 October 2026
Preliminary Interviews: Weeks commencing 19 and 26 October 2026
Short Listing: Week commencing 2 November 2026
Informal Discussions: Week commencing 9 November 2026
Final Panel: Week commencing 16 November 2026
Feedback will only be provided if you attend an interview or assessment.
Security
Successful candidates must undergo a basic (or equivalent) criminal record check.Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check (opens in a new window).See our vetting charter (opens in a new window).People working with government assets must complete baseline personnel security standard (opens in new window) checks.
Nationality requirements
This job is broadly open to the following groups:
- UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Working for the Civil Service
Please note this Post is NOT regulated by the Civil Service Commission.The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.Diversity and Inclusion
The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see theCivil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).Apply and further information
Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.Contact point for applicants
Job contact :
- Name : dbsciso@gatenbysanderson.com
- Email : dbsciso@gatenbysanderson.com
Recruitment team
- Email : dbsciso@gatenbysanderson.com
Attachments
Job Description - Chief Information Security Officer August 26 Opens in new window (pdf, 385kB)Salary range
- £100,000 - £110,000 per year