Chief Information Security Officer
Disclosure & Barring Service · GB
Chief Information Security Officer at Disclosure & Barring Service, based in GB, paying £100,000 - £110,000 per annum. This is a permanent role.
- Salary
- £100,000 - £110,000 per annum
- Location
- GB
- Contract
- Permanent
- Posted
- 21 hours ago
- Closes
- 5 Oct 2026
- Sector
- Security Officer
About 104% above the going rate for security officer
Reference b9db69d20e4d760457ecbe0177cfed6fde5e67c7
About the role
Job summary
DBS was established under the Protection of Freedoms Act 2012 on 1 December 2012, working
from two sites, which are Liverpool and Darlington. We operate on behalf of government
delivering Disclosure functions in England, Wales, Jersey, Guernsey and the Isle of Man, and
Barring functions for England, Wales, and Northern Ireland. We function within a framework of
legal and regulatory requirements and that includes work with a range of external organisations
including other government departments, regulators, and trade bodies.
We provide a service that enables organisations in the public, private and voluntary sectors to
make better informed, safer recruitment and other decisions. We do this by providing information
to enable them to determine whether individuals are unsuitable or unable to undertake certain
work, particularly with occupations involving regular contact with vulnerable groups, including children.
Our Strategy
Our current Strategy sets out our purpose, vision, and the impacts we want to achieve. Our
strategy was co-created with our staff and has been supported by insight from our various
partners, and throughout, you will find our ambitions to be achieved. Everything that we do within
DBS, from developing our strategic intent, to the day-to-day operational delivery of our services,
is underpinned by constant considerations of safeguarding, quality, sustainability, value for
money, and diversity and inclusion. Our strategic objectives aim to enhance our effectiveness,
influence, and customer satisfaction while fostering a supportive environment for everyone.
Equality, Diversion, and Inclusion at DBS
DBS is committed to fostering an environment that values individual differences and ensures fair
treatment to unlock the full potential of staff and better support customers. Equality, diversity,
and inclusion (EDI) are core to driving organisational success and we have developed specific
equality objectives for DBS.
Every decision and activity will be considered through an EDI lens, aiming to build an inclusive
culture, improve policies and practices, gain external assurances, and become a leading voice of
good practice in EDI.
Read More
For further information, please see below for a collection of DBS strategies and business plans:
• DBS strategies - GOV.UK
• DBS business plans - GOV.UK
Job description
Job Purpose:
The Chief Information Security Officer will provide senior organisational leadership for
information, cyber, operational security and data protection across DBS, setting and
implementing a clear strategy that supports DBS’s organisational strategy, safeguarding
mission, digital transformation priorities, statutory data protection duties and wider government
security expectations. The role will also act as DBS’s Data Protection Officer, providing
independent advice, challenge and assurance on compliance with UK GDPR, the Data
Protection Act 2018, law enforcement processing requirements where applicable,
organisational data protection policies and ICO expectations. The role will be accountable for
the effective operation of security controls, monitoring, incident management, vulnerability
management, supplier security and operational security assurance across live services and
change activity. The role will evaluate DBS’s current information and cyber security maturity,
define the level of maturity needed for a modern, resilient and digitally enabled safeguarding
organisation, and lead the practical plan to close that gap. The post holder will create the
environment, culture and operating model needed to protect DBS information, personal data,
technology and services, enabling innovation to happen safely, lawfully and securely while
ensuring DBS can prepare for, detect, respond to and recover from cyber attacks.
This is a senior leadership role, not a purely technical cyber post. The successful candidate will
be expected to understand risks across DBS, advise the Board, Executive Team, SIRO and
senior leaders on how to mitigate cyber, information and data protection risks in their areas and
future plans, and ensure the information security, cyber security and data protection aspects of
crisis management are effective. As Data Protection Officer, they must be involved in a timely
manner in issues relating to the protection of personal data, provide expert advice on data
protection obligations and DPIAs, monitor compliance, support awareness and training, and act
as a contact point for the Information Commissioner’s Office. They will translate complex cyber,
information risk, privacy and resilience issues into clear choices for executive decision-makers,
while building a capable, sustainable and accountable security and data protection function that
supports DBS’s transition to modern digital services, a secure-by-design model and a stronger
Target Operating Model.
Corporate Duties:
• Act as DBS’s senior organisational leader for information security, cyber security,
operational security and data protection, setting direction and providing clear, evidence
based advice to the Executive Director of Technology and Innovation, Board, Executive
Team, Audit and Risk Committee, SIRO and senior risk owners.
• Create, own and lead the DBS information, cyber and operational security strategy and
roadmap, ensuring it directly supports the organisation’s strategy, safeguarding mission,
digital transformation, live service resilience and wider government security strategy,
including Government Functional Standard GovS 007: Security, the Government Cyber
Security Standard, the Cyber Assessment Framework, GovAssure, Secure by Design
principles and relevant NCSC guidance.
• Lead the organisation in implementing the information, cyber and operational security
strategy, turning strategic intent into clear priorities, funded delivery plans, measurable
outcomes, operational controls and mature security practices embedded across DBS.
• Act as DBS’s Data Protection Officer, operating with the independence, senior access,
expertise and resources required by data protection law, and providing advice, challenge
and assurance on UK GDPR, the Data Protection Act 2018, law enforcement processing
requirements where applicable and wider data protection obligations.
• Shape a new cyber operating model for DBS, defining the right balance of in-house
capability, specialist consultancy, supplier support and managed services, with clear
accountabilities, decision rights and routes for increasing maturity over time.
• Be accountable for operational security across DBS technology services, ensuring
effective security monitoring, protective controls, access management, vulnerability
management, threat intelligence, security operations, incident triage and remediation are
in place and operating effectively.
• Build organisational confidence in cyber security by translating technical risk into plain
English, proportionate choices and practical action for executive, operational and
delivery audiences.
• Advise the Board, Executive Team and senior leaders on organisational cyber and
information risk, helping them understand their accountabilities and make proportionate
decisions to mitigate risk in current operations, change programmes and future plans.
• Advise the Board, Executive Team, SIRO, Information Asset Owners and senior leaders
on data protection risk, privacy by design, lawful processing, data sharing, retention,
data subject rights, personal data breaches and the implications of new services,
technology and operating models.
• Promote a c
Reference: b9db69d20e4d760457ecbe0177cfed6fde5e67c7 · Posted 21 hours ago · Closes 5 Oct 2026 · Listed via Disclosure & Barring Service
Apply for this job
This role is listed via Disclosure & Barring Service. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.