MoD-DV ISO Security Advisor (Public Sector Transformation)
- Job Title: ISO Security Advisor
- Location: On-site / hybrid (UK)
- Clearance: MoD-DV (active)
- Employment Type: Contract
- Sector: Public sector / highly regulated environment (secure on prem / data centre / supercomputing)
Overview:
We’re looking for a MoD-DV cleared ISO Security Advisor / Information Security SME to support a highly regulated organisation running a secure on?prem environment (including data-centre hosted, high-performance computing). The focus is information security, governance and assurance-driving and evidencing compliance while the organisation moves through a significant public-sector transformation / operating model change and associated cost pressures.
This is not a “hands-on cyber engineering” role. It is a policy, process, assurance and ISO transformation position, working closely with technical and leadership stakeholders to ensure controls remain robust, auditable, and practical throughout change.
Key Responsibilities:
- Lead/advise on ISO 27001 compliance and improvement activities, including:
- ISMS design/refresh, control mapping, risk treatment, SoA updates, and audit readiness.
- Support broader standards alignment where required (e.g., CAF and related assurance expectations).
- Provide governance and assurance across a secure on?prem cloud / data centre environment, ensuring controls are: clearly defined, operationalised, evidenced, and continuously improved.
- Drive ISO-led transformation: align security controls to changing operating models, ensuring compliance remains achievable during organisational change.
- Develop and maintain information security policies, processes and procedures, including ownership, adoption, and training/awareness where needed.
- Run/control security assurance activities (control testing, evidence packs, internal audits, nonconformity remediation, improvement plans).
- Engage senior stakeholders to articulate risk, compliance posture, and options under constraints (budget reductions, transformation impacts, changing delivery models).
- Support and/or compensate for temporary capacity gaps in information governance (as needed), ensuring BAU compliance obligations remain covered.
- Advise on AI / information governance requirements, including:
- Safe use of corporate AI tools,
- Retention/audit needs (e.g., capture/record-keeping requirements),
- Guidance for staff on handling sensitive data in AI-enabled workflows.
Required Skills & Experience:
- Active MoD DV clearance (essential).
- Demonstrable track record delivering ISO 27001 compliance in complex, regulated organisations.
- Experience delivering ISO transformation programmes (not just maintaining BAU compliance).
- Strong background in public sector transformation (operating model change, governance redesign, constrained budgets, assurance under change).
- Excellent knowledge of information security governance and assurance:
- policies, standards, risk management, audit, evidence-based compliance.
- Comfortable working with technical teams supporting secure infrastructure environments (on?prem, data centre, private cloud) while remaining focused on governance/assurance outcomes.
- Ability to communicate clearly with both technical and non-technical stakeholders, including directors/senior leadership.
Desirable:
- Exposure to environments with high assurance expectations and client-driven compliance requirements.
- Experience with secure compute / HPC / supercomputing environments (helpful but not required).
- Familiarity with Cyber Essentials and supporting accreditation readiness alongside ISO work.
- Knowledge of data retention / records management considerations in regulated settings.
Deliverable Example (typical):
- Updated ISMS artefacts (SoA, risk register, policies/standards, control ownership).
- Audit-ready evidence packs; internal audit findings and remediation plans.
- Operating model-to-controls mapping and compliance impact assessments during transformation.
- Pragmatic guidance and governance for AI tool usage and retention/audit requirements.