skip navigation
skip mega-menu

Security Development and Compliance Lead - ONS - SEO

Government Digital & Data -

Full-time (Permanent)
£43,013 - £46,654. Plus a skills allowance of up to £5,000 (non-pensionable and non-contractual) may be payable.
Published on
3 July 2025
Deadline
17 July 2025

Location

The ONS operates a flexible hybrid working model across the UK, with colleagues linked to one of our contractual locations working between office and remote throughout the week. The locations for this role are Newport, Titchfield (Fareham) and Manchester.

All colleagues on office-based contracts should be working primarily in their contractually allocated site for at least 40% of their working time. The exception to this is for colleagues based at the Manchester office. Due to current capacity constraints, colleagues based there will only be required to attend the office for 20% of their work time. It is expected Manchester will move to 40% in 2025-2026.

The induction process for the role will be conducted in person.

About the job

Job summary

The Office for National Statistics (ONS) is the UK’s largest producer of official statistics, covering a range of key economic, social and demographic topics. These include measuring changes in the value of the UK economy, estimating the size, geographic distribution, and characteristics of the population, and providing indicators of price inflation, employment, earnings, crime, and migration.

The role is within the Security Development Compliance and Audit (SDCA) team which forms part of the Security and Information Management (SaIM) directorate. The SDCA team provides an advice service to stakeholders for the complete lifecycle, security and governance of sensitive information stored within data access environments. The SDCA team also acts as an interface between stakeholders to deliver data protection assurance, monitor compliance with security policies and principles as well as provide evidence to stakeholders in support of these functions.

The primary focus of the role will be leading the Security Development and Compliance team in the development and implementation of data protection assurance and audit capabilities, in line with clearly defined security strategy and data protection standards. This also includes advising internal users, stakeholders and Information Asset Owners on compliance and risk associated with use of data. The role includes line management responsibilities for Security Development and Compliance Policy Associates HEO & EO Level.

Job description

The Role

The role supports ONS core security capability, covering service management, assurance and incident response, and provides many opportunities for cross-skilling and development.

The focus, outcomes and responsibilities are primarily aligned to the Government Security Profession Cyber Security Monitoring Lead role, with elements from Corporate Enablers Security Adviser and Process Lead roles.

Responsibilities:

  • Developing, owning and implementing effective data protection assurance processes and compliance documentation (e.g. DPIAs, SyOPs, etc.) to meet regulatory and legal requirements.
  • Developing and implementing effective security auditing, monitoring and assessment capability for data systems and data use incorporating advice from security and industry best practice.
  • Establishing detailed understanding of the nature, scope, context, purposes and risk of data processing by different business areas to provide comprehensive guidance and effective oversight of compliance.
  • Developing and promoting effective training, engagement and awareness-raising activities to promote data protection and compliance best practice.
  • Investigating non-compliance incidents and breaches in conjunction with Cyber Security and directing mitigating actions.
  • Supporting the shaping of the security audit and monitoring strategy, ensuring requirements, policies and standards to govern all activities and outputs are met.
  • Supporting Cyber Security in the management of monitoring, triaging, and investigation of security alerts on protective monitoring platforms to identify security incidents and reviewing analysis of security event data to manage security incident response, reporting, or escalation where appropriate.

Person specification

Essential Criteria:

  • Detailed knowledge of data protection legislation and regulations, including understanding of their implementation in different contexts across Government.
  • Ability to assess risk of diverse data use cases across multiple business areas advise on mitigations.
  • Ability to understand and evaluate threat based on quantitative and qualitative data and recommend protective security measures.
  • Ability to effectively manage a team of specialists based across different sites within a dynamic working environment.
  • Understanding of UK Government Security Policy Framework and relevant Information Assurance Standards, e.g. ISO 27001, Data Protection Act.
  • Ability to work as part of a team in a multi-discipline environment.
  • HMG Vetting at Security Clearance (SC) level will be required prior to starting in role.

Desirable Criteria:

  • Holding or willing to work towards professional development qualifications within specialist Security discipline g.ISO 27001 Security Auditor etc. 

Behaviours

We'll assess you against these behaviours during the selection process:

  • Communicating and Influencing
  • Managing a Quality Service
  • Leadership
  • Working Together

Technical skills

We'll assess you against these technical skills during the selection process:

  • Applied Security Capability - Practitioner
  • Information Risk Assessment and Risk Management - Practitioner
  • Protective Security - Working
  • Threat Understanding - Working


More jobs at Government Digital & Data

Interaction Designer - GDS
Full-time (Permanent)
Test Engineer - GDS - SEO
£46,725 - £50,220 (London) / £42,893 - £45,653 (National) plus additional allowance
Full-time (Permanent)
Director Platform Engineering, Resilience & Cyber - DSIT - SCS2
£100,000 - £163,000
Full-time (Permanent)
Test Engineer - Welsh Revenue Authority - HEO
£37,111 - £45,378 plus additional DDaT allowance
Full-time (Permanent)
Senior Test Engineer - Infected Blood Compensation Authority - SEO
£47,258 plus additional £3,544 after completing probation
Full-time (Permanent)
Lead Interaction Designer - Crown Prosecution Service - G7
£58,330 - £67,450 (National) / £62,820 - £73,520 + £3,150 RRA (London)
Full-time (Permanent)
Service Transition Manager - Welsh Government - HEO
£37,111
Full-time (Permanent)
Software Developer - HMRC - HEO
National £37,682 - £40,705. London £42,631 - £46,077
Full-time (Permanent)
Lead DevOps Engineer - Insolvency Service - G7
National: £57,367 - £63,319 London: £59,463 - £66,290 up to £5,150 allowance
Full-time (Permanent)
Senior DevOps Engineer - Insolvency Service - SEO
National: £48,429 - £52,222 London: £51,661 - £54,686 plus £5,150 allowance
Full-time (Permanent)
Senior Infrastructure Manager - HMRC - SEO
£45,544 - £49,523
Full-time (Permanent)
Deputy Director DDaT in HO Digital Enterprise Services Technology - Home Office - SCS1
£81,000 - £91,000
Full-time (Permanent)
£55,575
£55,575 plus allowances. London offers an additional £4,218
Full-time (Permanent)
Test Assurance Analyst - National Crime Agency - HEO
£45,326 plus additional allowance. London additional £4,218
Full-time (Permanent)
Supporting Services Senior Officer - National Crime Agency - HEO
£45,326 plus an additional £4,218 for London
Full-time (Permanent)
Senior Dynamics Developer - Intellectual Property Office - SEO
£47,766 up to £58,575 with additional pay allowance
Full-time (Permanent)
Senior Enterprise Architect (Data Analytics) - HMRC - G7
£58,541 - £64,624
Full-time (Permanent)
Test Engineer - Welsh Revenue Authority - HEO
£37,111 - £45,378
Full-time (Permanent)
Senior Test Engineer - Infected Blood Compensation Authority - SEO
£47,258 plus additional £3,544 after probationary period
Full-time (Permanent)
Lead Services Manager - Office for Standards in Education, Children's Services and Skills - G7
£68,635 per annum. Rising to £69,322 per annum on successful completion of probation.
Full-time (Permanent)
Software Developer - Ministry of Housing, Communities and Local Government - SEO
£49,548 (London), £45,928 (National) may also qualify for additional allowance
Full-time (Permanent)
Lead Developer - Department for Transport - G7
Base pay £57,515 plus an additional allowance up to £22,885
Full-time (Permanent)
Lead Technical Architect - Home Office - G7
National £62,109 London £66,229 plus up to £18,291 additional allowance
Full-time (Permanent)
Senior Technical Architect - Crown Commercial Service - G7
£59,877 - £66,869 plus up to £9,000 technical allowance
Full-time (Permanent)
Principal Technical Architect, Networks & Infrastructure - Home Office - G6
National £76,117 London £80,237 plus up to £19,483 additional allowance
Full-time (Permanent)
SOC Technical Team Lead - Registers of Scotland - SEO
£48,544 - £57,155 plus Digital, Data and Technology Annual Pay supplement of 20%
Full-time (Permanent)
Senior DevOps Engineer - UK Health Security Agency - SEO
£41,983 - £52,113 This role attracts a Market Pay Supplement of up to £5,000.
Full-time (Permanent)
IT Ops Student Placement - HM Land Registry - EO
£32,114
Full-time (Permanent)
Agile Delivery Manager - Intellectual Property Office - SEO
£47,766 earn up to £58,575 with additional allowances
Full-time (Permanent)
Data Analyst - Government Digital Service - SEO
£46,725 - £50,220 (London) & £42,893 - £45,653 (National) including additional allowance
Full-time (Permanent)
Head of Engineering and Operations - Cabinet Office - SCS1
£81,000 - £117,800
Full-time (Permanent)
Deputy Director, Digital Project and Change Delivery - HM Courts and Tribunals Service - SCS1
£81,000 - £117,800
Full-time (Permanent)
Chief Technology Officer - Department for Culture, Media and Sport - SCS1
£81,000
Full-time (Permanent)
Director General for Technology, Digital and Data - Department of Health and Social Care - SCS3
Up to £285,000 per annum dependent upon experience
Full-time (Permanent)
Software Developer - Ofgem - HEO
National £34,123-£45,831 / London £36,824-£48,561
Full-time (Permanent)
Senior Developer - Department for Transport - SEO
Base pay £44,241 plus an additional allowance up to £13,159
Full-time (Permanent)
Delivery Manager - Ofgem - HEO
London £36,824-£48,561 National £34,123-£45,831
Full-time (Permanent)
Agile Delivery Manager - Intellectual Property Office - SEO
£47,766 up to £58,575 with additional allowances
Full-time (Permanent)
Associate IT Delivery Manager - HMRC - HEO
£37,682 - £40,705
Full-time (Permanent)
Principal Delivery Manager - HM Courts and Tribunals Service - G7
National £58,511 - £65,329 London £63,343 - £70,725
Full-time (Permanent)
Head of Transformation for Emergencies - Ministry of Housing, Communities and Local Government - G6
£73,423 (London) or £66,620 (National)
Full-time (Permanent)
AI Delivery and Oversight Lead - Department for Transport - G7
National Minimum Salary: £57,515; London Minimum Salary: £62,034
Full-time (Permanent)
Senior Product Manager (Private Rented Sector Database) - Ministry of Housing, Communities and Local Government - G7
£56,167
Full-time (Permanent)
Technical Product Manager - Companies House - HEO
£42,923 - £47,044
Full-time (Permanent)

Subscribe to our newsletter

Sign up here