HS2 is Britain's new high-speed railway that supports the government's number one mission growth. When it's fully operational, the line will connect London and Birmingham in just 49 minutes. This will create better journeys for passengers. The railway links our two biggest economic centres, connects people with jobs and is attracting major investment before services begin. It then extends north of Birmingham to Handsacre in Staffordshire. Here, HS2 trains will connect to the West Coast Main Line for the Northwest and Scotland.
HS2 provides benefits for everyone faster, more reliable journeys for passengers; better connections to markets and people for businesses; and investment in infrastructure and skills for local communities.
As a Head of Information and Cyber Security, your main responsibilities will be:
- Direct the development, implementation, and improvement of a pan HS2 Information & Cyber Security Strategy aligned to overall business objectives.
- Accountable for the successful end-to-end management of Information & Cyber Security budget, resourcing, and suppliers.
- Lead the provision of security expertise, guidance, and systems needed to execute the Information & Cyber Security Strategy, responsible for compliance between business objectives, regulatory requirements, and industry best practice.
- Act as HS2's designated "Senior officer responsible for security information " and "Incident Manager " roles under Government Functional Standard GovS 007, providing executive accountability for cyber risk posture.
- Develop policies, standards, processes, approach and guidelines for all relevant activity to ensure the continuous physical and electronic security of Information & Technology at HS2 (including but not limited to Security Operations, Governance Risk & Compliance, Information Governance, Data Protection, Identity & Access Management, and Security Architecture).
- Direct the definition, implementation, and monitoring of the security, identity, governance, risk and compliance framework to meet HS2's obligations under regulation, law, or contracts and provides leadership, direction and oversight for Security Governance, Risk and Compliance activity and ensure clear reporting through governance forums.
- Direct the implementation of an industry best practice Information Security Management System that provides strategy, policies, leadership with appropriate governance and controls to ensure compliance, alignment with risk appetite and continued maturity of the organisation.
- Oversee the provision of specialist advice on security issues and implications, including review of new business proposals and clearly communicating security and identity risks to stakeholders.
- Direct on resolution of security incidents, remediation, risk, and impact assessments.
- Act as the sole subject-matter expertise to the HS2 Board & Executive, advising on level of Information and Cyber Risk through relevant reporting channels.
Essential:
- Experience in developing and delivering a Cyber Security strategy and Information Security Management Systems
- Experience of leading cross-functional Information & Cyber Security teams through the full lifecycle of security capability delivery and continuous improvement.
- Experience of risk management and delivery of audit remediation activities.
- Experience of leading live cyber incidents and the remediation actions
- Experience of partnering with supplier teams for managed services and agile delivery of improvements.
Please be aware that this role can only be worked within the UK and not Overseas.
In applying for this role, you acknowledge the following this role falls in scope of the Off Payroll Working in the Public Sector legislation. Any rates of payment quoted will reflect the gross rate per day for the assignment and will be subject to appropriate taxes and statutory costs. As such the payment to the intermediary and your income resulting from this contract will be different.