22151 - Lead Security Specialist
United Kingdom • Permanent • Competitive
Back to Job Search

22151 - Lead Security Specialist

Easy Apply
United Kingdom On-site Permanent 7 Applications
Competitive
Full-time
Posted 11 Sep 2026
Expires 11 Oct 2026

Job description

HMPPS Band 9

Lead Security Specialist - Education, Skills and Employment Digital

The Role

We are seeking an experienced security specialist to lead the security and assurance of innovative digital services across His Majesty’s Prison and Probation Service (HMPPS).

The role will support the Education, Skills and Employment Digital portfolio, including the Innovation Catalyst Programme (ICP), Streaming Education, virtual reality solutions and future digital services for people in prison and operational staff.

These services present distinctive security challenges. They must provide meaningful access to digital content and capabilities while operating safely within a custodial environment, protecting individuals, prison operations, information and the wider public.

The successful candidate will combine strong cyber and information security expertise with practical experience of HMPPS, prisons and custodial operations. They will understand that security in a prison setting extends beyond conventional cyber controls and must account for physical security, operational procedures, prisoner behaviour, safeguarding, fraud, misuse and threats to good order and discipline.

The role will work closely with product and delivery teams, HMPPS operational security, prison technology services, cyber security teams, service owners, suppliers and colleagues across the prison estate. The postholder will help teams make proportionate, evidence-based security decisions that enable innovation while managing risk responsibly.

Key Responsibilities

  • Lead security activity across the Education, Skills and Employment Digital portfolio, including ICP, Streaming Education, virtual reality and emerging technology initiatives.
  • Provide authoritative security advice throughout the service lifecycle, from discovery and design through procurement, implementation, live operation and continuous improvement.
  • Apply detailed knowledge of HMPPS operations and prison security to identify threats, vulnerabilities and potential misuse scenarios that may not be apparent through conventional cyber security assessments.
  • Translate HMPPS operational security requirements into practical technical, procedural and contractual controls.
  • Develop a deep understanding of each service, its users, information flows, technical architecture and operational context.
  • Lead threat assessments, security risk assessments, control evaluations and security assurance activities.
  • Ensure security is embedded within product, architecture, delivery and service management processes from the outset.
  • Advise service owners and senior leaders on security risks, control effectiveness, risk tolerance and proportionate risk treatment.
  • Support service owners in preparing risk submissions and making informed risk acceptance decisions.
  • Review solution designs, technical architectures, data flows and supplier proposals to ensure that security requirements have been addressed.
  • Define and maintain security requirements, security management plans, risk registers, assurance evidence and supporting security documentation.
  • Work with suppliers and internal teams to identify, prioritise and remediate security vulnerabilities and control weaknesses.
  • Establish appropriate protective monitoring, alerting and investigation capabilities for each service, proportionate to its risk and operating environment.
  • Ensure that monitoring approaches support the detection of cyber threats, inappropriate use, attempts to circumvent controls and activity that could create operational or safeguarding risks.
  • Develop and maintain security incident management processes, including clear routes for escalation into HMPPS operational security, cyber security and prison management structures.
  • Provide specialist support during security incidents and investigations, ensuring that technical evidence is handled appropriately and operational impacts are understood.
  • Define and oversee security testing, including vulnerability assessment, penetration testing, configuration review and scenario-based testing relevant to the prison environment.
  • Coordinate security assurance ahead of pilots, deployments, significant service changes and national rollouts.
  • Assess the security implications of introducing new technologies into prisons, including consumer devices, streaming services, immersive technology, wireless connectivity and cloud-hosted services.
  • Work directly with prisons and operational colleagues to ensure that national security controls can be implemented consistently and effectively at a local level.
  • Identify where operational procedures, staff guidance, training or communications are required to support technical controls.
  • Develop meaningful security reporting covering risk, incidents, vulnerabilities, assurance activity, control effectiveness and emerging threats.
  • Support internal and external audits, inspections and assurance reviews, including the tracking of findings through to resolution.
  • Build productive relationships across HMPPS, MoJ security functions, digital and technology teams, suppliers and relevant government security communities.
  • Promote a positive security culture in which security is treated as an enabler of safe digital innovation.

Essential Skills and Experience

The successful candidate will have:

  • Substantial experience working within HMPPS or in direct support of HMPPS services, with a strong practical understanding of prison operations and custodial security.
  • Experience of applying cyber, information or technical security principles within prisons or another complex, high-risk operational environment.
  • A clear understanding of the security risks associated with providing people in prison with access to digital devices, services, content and connectivity.
  • Experience of security architecture, security assurance, operational security management or a comparable senior security role.
  • Experience of conducting security risk assessments and translating identified risks into proportionate technical and operational controls.
  • The ability to assess risk across cyber, information, physical, personnel, operational and safeguarding domains.
  • Experience of reviewing technical designs, architectures, data flows, cloud services and supplier security arrangements.
  • Knowledge of protective monitoring, vulnerability management, incident response and security testing.
  • Experience of advising service owners, senior leaders and governance bodies on complex security risks and decisions.
  • Strong stakeholder-management skills, with the ability to work effectively with technical specialists, operational prison colleagues, commercial teams and suppliers.
  • The ability to communicate complex security issues clearly to both technical and non-technical audiences.
  • The confidence to challenge constructively while remaining pragmatic and focused on enabling delivery.
  • The ability to work across multiple initiatives, balancing immediate delivery needs with longer-term security strategy and service development.

Desirable Skills and Experience

It would be advantageous for candidates to have:

  • Experience supporting digital services used directly by people in prison.
  • Experience of in-cell technology, prison education technology or digital rehabilitation services.
  • Knowledge of HMPPS security policies, the National Security Framework and relevant prison operating procedures.
  • Experience of security assurance within MoJ or wider government.
  • Knowledge of government security frameworks and guidance, including the Government Security Function, NCSC guidance, Cyber Assessment Framework and Secure by Design principles.
  • Experience of Microsoft Azure, endpoint security, mobile device management, content filtering, secure streaming or cloud-native security controls.
  • Experience assessing virtual reality, immersive technology, wireless devices or other emerging technologies.
  • Experience working with multidisciplinary agile delivery teams.
  • Relevant professional qualifications or certifications in cyber security, information security, security architecture or risk management, including but not limited to ISO 27001, Cyber Essentials and IASME Cyber.

Key Outcomes

The postholder will ensure that:

  • Education, Skills and Employment digital services are introduced into prisons safely, securely and responsibly.
  • Security risks are identified early and managed throughout the service lifecycle.
  • Security controls reflect the realities of the custodial environment as well as recognised cyber security practice.
  • Service owners and senior leaders have clear, evidence-based information on which to make risk decisions.
  • Suppliers and delivery teams understand their security responsibilities and can demonstrate that appropriate controls are operating effectively.
  • Security incidents, vulnerabilities and assurance findings are managed consistently and transparently.
  • Security enables the organisation to extend valuable digital opportunities to people in prison without creating unacceptable risks to individuals, establishments or the public.

Working Relationships

The role will work closely with:

  • Education, Skills and Employment Digital service owners, product managers and delivery teams
  • HMPPS operational and national security teams
  • Prison technology and digital teams
  • Governors, Heads of Security and local prison colleagues
  • MoJ cyber security, security architecture and assurance teams
  • Commercial, data protection and information assurance colleagues
  • Technology and service suppliers
  • Education, rehabilitation and operational policy teams

Security Requirements

The successful candidate will be required to hold, or be willing and able to obtain, the appropriate level of security clearance for the role. The role may require travel to prisons and other HMPPS or MoJ locations.

Is there something wrong with this job listing? Let us know.