Head of Incident Management (Response) - Government Digital Service - G6
Government Digital & Data -
Location
London
About the job
Job summary
Please note this role requires DV Clearance
The Government Cyber Unit's mission is to protect public services from cyber threats and digital resilience failures. We are working to achieve a step change in our cyber and digital resilience across government, through delivery of the Government Cyber Action Plan, and working closely with departments and national technical authorities including the National Cyber Security Centre to deliver. This is a challenging time to be working in cyber security and digital resilience, but we have an incredible opportunity to make a difference to people’s lives and promote national security by protecting the public services and national infrastructure they rely on. We work at the forefront of shaping the UK’s national response to emerging cyber and technology issues - from the increasingly complex range of state-sponsored cyber-attacks and supply chain compromises, through to the transformational benefits and security challenges of frontier AI and quantum computing.
We are committed to creating an inclusive and supportive working environment where people can learn, develop and do their best work. Continuous professional development and a focus on wellbeing is core to our unit culture. We welcome applications from candidates who share this ethos and are excited by our mission.
The Government Cyber Coordination Centre (GC3), part of GCU, coordinates the cross-Government response to cyber security vulnerabilities, threats, and incidents, and enables cyber defenders across Government to work together and to “defend as one”. The GC3 is a joint initiative sponsored by the Department for Digital, Culture, Media and Sport (DCMS) and the National Cyber Security Centre (NCSC). This role is based in DCMS, but you should expect to work closely alongside colleagues from both sponsoring organisations, and wider Government and the public sector.
Job description
We are looking for an experienced incident management professional to coordinate the cross-government response to significant cyber security and digital resilience incidents, drive resilience through exercising and lessons learned, and lead a high-performing joint team. This role reports to the Deputy Director for Government Cyber Operations.
In this role, you can expect to:
- work closely with GC3 Policy teams to ensure the national and government policies (including the Government Cyber Incident Response Plan) aligned with GC3 Incident Management requirements
- establish and deliver a cross-government cyber and digital resilience exercising programme, including delivering sector-level exercising, providing sector-wide support such as templates and guidance, and supporting exercising within departments through training and hands-on support
- lead the operational cross-government response to critical and cross-cutting threats, vulnerabilities and incidents, enabling a rapid understanding of risk, clear communications to decision makers, and a coordinated and informed response across government
- work closely with the Government Cyber Unit’s accountability team to establish and operate governance, policy, assurance and risk/performance reporting structures for cyber and digital resilience incident management across government
- advise ministers, senior officials, and IT and cyber security leadership across government on the effective response to cyber and digital resilience incidents
- establish and operate the structures to enable the effective identification, documentation, sharing and implementation of lessons from cyber and digital resilience incidents across government and within departments
- build, implement and continually improve processes and technology across GC3 Incident Management, and the structures to ensure staff are suitably knowledgeable and experienced
- engage closely with stakeholders and customers across government, including wider DCMS, the NCSC, and departmental IT and cyber security teams
- line manage lead analysts in the incident management team, and provide coaching and support to staff across the GC3
The post holder may be required to support out of hours on call rotas for responding to cyber and digital resilience incidents, for which remuneration and/or flexible working arrangements will be available.
Person specification
We’re looking for someone with:
- significant experience leading the response to cyber and/or digital resilience incidents within large, complex organisations, or at a sectoral or national level
- significant experience building and embedding incident response capabilities within large, complex organisations or at a sectoral or national level, for example, incident response planning and documentation, incident exercising, crisis simulation, post-incident reviews, and lessons management
- high levels of personal resilience, with the ability to make effective decisions despite ambiguity and uncertainty, provide clear direction, and adapt to rapidly changing circumstances
- strong stakeholder engagement and influencing skills, with the ability to build trusted relationships, manage competing priorities, and achieve consensus
- the ability to provide clear and highly credible advice to senior decision makers, including translating complex cybersecurity incident detail for a non-technical audience
- the ability to balance strategic objectives, operational risks, and competing stakeholder requirements