About this role
Details
A Civil Service Pension with an employer contribution of 28.97%
GBP
Job grade
C1
Type of role
Digital
Working pattern
Full-time
Number of jobs available
1
Contents
- Location
- About the job
- Benefits
- Things you need to know
- Apply and further information
About the job
Job summary
Lead the cyber security agenda for a critical public service, protecting sensitive information while enabling digital transformation across Disclosure Scotland.
Disclosure Scotland is an executive agency of the Scottish Government, supporting safer recruitment and helping to protect vulnerable groups through trusted disclosure services. As Cyber Security Manager, you will join our Digital team at a pivotal point in our transformation journey, leading a specialist team whose mission is to enable secure, resilient, and accessible digital services that meet the needs of citizens, organisations, and government.
In this role, you will provide strategic leadership for cyber security across the organisation, working collaboratively with senior leaders, delivery teams, and external partners to embed security into our services, systems, and decision-making processes. Your primary objective will be to ensure that cyber security supports and enables organisational goals, protecting critical services and information while helping Disclosure Scotland deliver its vision for modern, innovative, and trusted public services.
Job description
- Lead engagement with key stakeholders across Disclosure Scotland and the wider Scottish Government, acting as the primary point of contact for cyber security matters.
- Provide expert cyber security advice and guidance, supporting the effective implementation and operation of security controls across the organisation.
- Develop a strong understanding of user needs and emerging technologies, ensuring cyber security policies and controls align with business requirements.
- Deliver cyber security initiatives arising from the Cyber Security Strategy, supporting the effective management of cyber risk and information protection requirements.
- Lead the development and continuous improvement of cyber incident management, investigation and response capabilities, processes and procedures.
- Manage the assessment of cyber threats and vulnerabilities, implementing appropriate controls to protect organisational systems, information and services.
- Conduct and oversee cyber security risk assessments, providing recommendations to support effective risk management and informed decision-making.
- Manage the delivery of penetration testing and security assurance activities, ensuring findings are addressed and drive continuous improvement in organisational security.
- Lead multidisciplinary teams through the planning, delivery and evaluation of security testing activities in line with organisational policies, standards and best practice.
- Develop and maintain cyber security policies, standards and guidance in line with business needs, legislative requirements and industry best practice.
Person specification
Success profile
Success profiles are specific to each job and they include the mix of behaviours, experience and technical criteria (if applicable) that candidates will be assessed on.
Experience
- Lead criteria - Experience of leading and developing cyber security teams, with the ability to design, implement and continuously improve Security Operations capabilities, including threat detection, automation, orchestration and the development of security processes and procedures to meet evolving business and threat requirements.
- Experience of advising on organisational and technical responses to cyber security incidents, with responsibility for developing and driving incident investigation, response policies, processes and procedures.
- Expert knowledge of system architectures, with the ability to assess and articulate the impact of vulnerabilities on existing and future systems, services and designs.
- Experience of working in a multidisciplinary team environment, and delivering quality security objectives in a timely manner, among other competing digital priorities.
Technical Skills
This role is aligned to the Cyber Security Analyst role in the Digital, Data and Technology Profession.
These skills will be tested during the Technical Assessment if you are successful at sift stage. They will be not be assessed at application stage. Please review the following to understand the skill expectations Cyber Security Operations - Government Digital and Data Profession Capability Framework.
Benefits
Alongside your salary of £62,111, Scottish Government contributes £17,993 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides .
- Learning and development tailored to your role
- An environment with flexible working options
- A culture encouraging inclusion and diversity
- A Civil Service pension with an employer contribution of 28.97%
Things you need to know
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance for more information on appropriate and inappropriate use.
Selection process details
Candidates will have their applications assessed against all Experience criteria. In the event of a high volume of applications, candidates will have their applications initially assessed against the *Lead experience*criteria. Candidates who pass this initial sift will have their applications fully assessed against the listed criteria.
Candidates who are successful at sift stage will be invited to attend an Interview and Technical Assessment. The interview will further assess the Experience and Behaviours listed in the job advert and the Technical Assessment will evaluate the Technical Skills relevant to the role.
Assessments are scheduled for w/c 14 September 2026 however this may be subject to change.
Feedback will only be provided if you attend an interview or assessment.
Security
Successful candidates must undergo a criminal record check.
People working with government assets must complete baseline personnel security standard (opens in new window) checks.
Nationality requirements
This job is broadly open to the following groups
- UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Further information on nationality requirements
Working for the Civil Service
The Civil Service Code sets out the standards of behaviour expected of civil servants.
We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles .
The Civil Service embraces diversity and promotes equal opportunities.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in Glasgow →Why this fits a police background
- Evidence & case files
- Incident command & response
- Investigative casework
- Risk & threat assessment
- Security operations
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |