
Head of Cyber Security
Job summary
The UK Hydrographic Office (UKHO) is seeking an experienced cyber security leader to join its Technology Directorate as Head of Cyber Security (CISO). Reporting to the Chief Digital & Technology Officer, you will lead the organisation's cyber security strategy, governance, risk management and security operations.
As UKHO's cyber security lead, you will work with executive leaders to ensure cyber risks are identified, understood and managed effectively, protecting critical services, sensitive information and national security interests. You will provide leadership across cyber operations, incident response, security assurance, secure-by-design delivery and resilience, while strengthening security awareness and accountability across the organisation.
Working closely with the Ministry of Defence, government security partners, suppliers and internal stakeholders, you will support strategic decision-making and drive continual improvement in cyber maturity and resilience.
We are looking for a proven cyber security professional with experience of developing strategy, leading teams, managing risk in complex environments and advising senior leaders. Strong leadership, stakeholder management and governance skills are essential, alongside recognised qualifications such as CISSP, CISM, CCSP or equivalent.
This is an opportunity to lead cyber security for a nationally important organisation, ensuring the resilience, security and integrity of the UK's hydrographic and geospatial services.
Hybrid working
This job role can be worked on a hybrid basis, which is an informal, non-contractual and voluntary arrangement, working between the office in Taunton and remotely within the UK.
Office attendance is expected 60% of the time. There will be a requirement to attend meetings at higher classifications which will mean office attendance is required.
Job description
- Provide strategic leadership for cyber security across the organisation, ensuring security priorities support business objectives, operational resilience and national security requirements.
- Act as the organisation’s senior cyber security adviser, giving expert guidance to executives and senior leaders on cyber risk, threats, incidents and investment decisions.
- Own the cyber risk and assurance framework, ensuring risks are identified, assessed, reported and managed appropriately, with clear recommendations for leadership action.
- Lead the organisation’s cyber security operations, overseeing threat monitoring, vulnerability management, incident response and recovery activities to maintain a strong security posture.
- Ensure security is embedded into technology programmes, projects, procurement activities and enterprise architecture, promoting a secure-by-design approach to change delivery.
- Develop and maintain effective cyber security policies, standards and governance processes, ensuring compliance with MOD, government and regulatory requirements.
- Build and lead a high-performing cyber security capability, developing skills, setting priorities, managing suppliers and driving continuous improvement across people, process and technology.
- Strengthen organisational cyber resilience and security culture through stakeholder engagement, awareness initiatives, assurance activities and collaboration with MOD, government and industry partners.
Person specification
- Proven experience leading cyber security strategy, risk management and resilience within a complex, regulated or mission-critical organisation.
- Demonstrable ability to advise and influence executive leaders, translating complex cyber and technology risks into clear business decisions.
- Strong track record of leading cyber security operations, incident response, assurance activities and continuous security improvement programmes.
- Deep understanding of cyber security governance, secure-by-design principles, regulatory compliance and risk-based decision making.
- Experience building, leading and developing high-performing cyber security teams, including the management of suppliers and outsourced services.
- Relevant professional cyber security qualifications (e.g. CISSP, CISM, CCSP or equivalent) supported by ongoing professional development and a commitment to maintaining technical credibility.
Behaviours
We'll assess you against these behaviours during the selection process:
- Communicating and Influencing
- Leadership
- Managing a Quality Service
- Changing and Improving
Benefits
Alongside your salary of £78,600, UK Hydrographic Office contributes £22,770 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window).At the UK Hydrographic Office, it's very important to us that our people feel valued.
We offer a huge range of benefits such as training and development, well-being support, flexible/ homeworking, a fantastic state of the art building, high spec equipment, and so much more.
See our attached Candidate Information Pack for more details.
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.Selection process details
This vacancy is using Success Profiles (opens in a new window), and will assess your Behaviours and Experience.How to Apply:
When you click "Apply Now" at the bottom of this page, you will be required to attach your anonymised CV for information, together with a 750 word supporting statement on the experience criteria below.
Timeline:
- Advert Closes for applications: 18th October 2026
- Shortlisting: w/c 26th October 2026
- Fireside chat via MS TEAMS : w/c 9th November 2026
- Interviews : w/c 16th October 2026
We will try to meet the dates set out in the advert. There may be occasions when these dates change. You will be provided with sufficient notice of the confirmed dates.
Lead Criteria:
We have identified a lead criterion for this role, which we may use to differentiate between applications in the following scenarios:
- To conduct an initial-sift in a high volume of applicants (over 20 applications). This would be conducted after the above pre-sift on the mandatory criteria.
- To establish a merit-order in the event of a tie
The lead criteria for this role are identified below.
Pre-sift criteria:
- Do you hold a relevant CISSP or CISM qualification?
This will be assessed from your CV. If you do not hold this qualification, you will not be taken through to the next stage of the process.
Sift/Shortlist Criteria:
All applications are processed anonymously. You will be short-listed against the following criteria:
- Proven experience leading cyber security strategy, risk management and resilience within a complex, regulated or mission-critical organisation (lead criteria).
- Demonstrable ability to advise and influence executive leaders, translating complex cyber and technology risks into clear business decisions.
- Strong track record of leading cyber security operations, incident response, assurance activities and continuous security improvement programmes.
- Experience building, leading and developing high-performing cyber security teams, including the management of suppliers and outsourced services.
Please ensure that you cover all the above criteria in your 750 word supporting statement.
Interview Criteria:
Experience:
- Demonstrate significant experience operating in a senior cyber security leadership role, with clear accountability for setting cyber security direction, managing enterprise-level cyber risk, and improving organisational resilience in a complex, regulated or mission-critical environment - evidence how they have led cyber strategy, influenced senior decision-makers, managed security operations or assurance activity, and delivered measurable improvements to cyber maturity, governance or incident preparedness (lead criteria).
Civil Service Behaviours (Grade 6 level):
- Comminating and Influencing
- Leadership
- Managing a Quality Service (assessed by the presentation)
- Changing and Improving
See here for further information: Success Profiles - Civil Service Behaviours (publishing.service.gov.uk)
Process:
- All shortlisted candidates with be invited to a MS TEAMS fireside chat and face-to-face interview, which will include a presentation.
- The fireside chat will be with take place with the hiring manager, Alex Bowen, Chief Digital and Technology Officer on Microsoft teams. This element is not scored and will not contribute towards the decision process but is a way for candidates to ask questions about the role and organisation.
- The interviews will be a face-to-face at our Headquarters in Taunton. It will be with a panel of 3 people and will last approximately 60 minutes.
- You will be required to give a 10 minute presentation a part of this interview. More details will be given in the Invitation to Interview email.
- You will be contacted to book a suitable slot if you are shortlisted.
Onboarding Checks:
In the event you are offered a role with us, you will be required to go through Basic Personnel Security Standard (BPSS) checks which will include Employment and Right to Work Checks. You will also need to apply for DV (Developed Vetting) and it is unlikely you will be able to start your role before gaining this. Please see our attached Candidate Pack for further details and Terms.
Please note, we are unable to offer visa sponsorship.
Residency Requirements:
DV – reserved
This is a Ministry of Defence reserved post and open to sole UK nationals only. Successful applicants will require Developed Vetting (DV) and therefore need to have resided in the UK for a minimum of 24 consecutive months within the last 10 years.
Feedback will only be provided if you attend an interview or assessment.
Security
Successful candidates must undergo a basic (or equivalent) criminal record check.Successful candidates must meet the security requirements before they can be appointed. The level of security needed is developed vetting (opens in a new window).See our vetting charter (opens in a new window).People working with government assets must complete baseline personnel security standard (opens in new window) checks.
Nationality requirements
Open to UK nationals only.Working for the Civil Service
The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.
Diversity and Inclusion
The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see theCivil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).Apply and further information
This vacancy is part of the Great Place to Work for Veterans (opens in a new window) initiative.Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.Contact point for applicants
Job contact :
Recruitment team
- Email : recruitment.queries@ukho.gov.uk
Further information
Further InformationThe Department’s recruitment processes are underpinned by the requirement of selection for appointment based on merit, open and fair competition as outlined in the Civil Service Commissioners’ Recruitment Principles, details of which can be found at http://civilservicecommission.independent.gov.uk If you feel your application has not been treated in accordance with the Recruitment principles and you wish to make a complaint, you should in the first instance contact recruitment.queries@ukho.gov.uk If you are not satisfied with the response you receive, you can further contact the Civil Service Commission at: civilservicecommission.independent.gov.uk or view more details at http://civilservicecommission.independent.gov.uk
Attachments
20210309 additional pay info Opens in new window (pdf, 163kB)UKHO Candidate Information Pack - Tech Opens in new window (pdf, 5887kB)Salary range
- £78,600 per year