CON-18-103 – Manager – Strategy, Governance & Capability, Cyber & Information Resilience
Details
- Value
- GBP/day 1,500
- Published
- 16 July 2018
- Submission
- 23 July 2018
- Source
- uk:digital_marketplace
Tender description
Summary of the work We are looking for a Cyber Security Manager to implement and operate our information security management system and associated governance, compliance and risks processes and drive our cyber and information culture and capability agendas. This is a high-profile role reporting that reports directly to the CISO. Specialist role Cyber security consultant Expected Contract Length 9 months Latest start date Monday 6 August 2018 Maximum Day Rate £1500 (ex. VAT) Who Speclialist Work With The candidate will be leading and working with a small team responsible for delivering the strategy, governance and capability agenda. What Specialists Work On • Definition, development and maintenance of the Cyber and Information Resilience Strategy for the FCA, and associated policies, procedures, standards and implementation roadmaps. • Promote the FCA’s Cyber and Information Resilience strategy internally and drive the awareness of cyber security risks, data privacy obligations and good information management practices. • Drive the FCA’s behavioural change agenda to establish a robust information security and privacy culture across the organisation. • Define, implement and drive the compliance regime to ensure that the updated security policies and standards are being embedded. Skills & Experience • Experienced in the selection and implementation of appropriate security controls and governance strategy across the financial services sector or regulatory environment. • In-depth knowledge of Information Security Risk Management principles with demonstrative practical experience of supporting security risk frameworks within a complex organisation. • Demonstrable experience in the creation of high quality information security policy frameworks, including the definition, roll-out and maintenance of policies, standards and practices that are suitable for the FCA. • Knowledgeable about the legal and regulatory requirements for information security and information management. • Experience of developing and operating information security strategies and governance frameworks • Experience of developing information security policies and standards • Experience of information security controls, vulnerabilities and threats to be able to effectively assess information security risks. • Experience of applying ISO 27000 and/or NIST security standards in order to ensure an effective, integrated approach to information security controls for mitigation of information security risks to the business. Nice to Haves • Knowledge of Information Management principles. • Knowledge of data privacy regulation, including the new EU General Data Protection Regulations. • Experience in leading the delivery of security awareness and culture change. • Professional Accreditations (CISM, CISA, CISSP, M Inst ISP). Work Location 12 Endeavour Square, London, E20 1JN Working Arrangments The specialist will be expected to work on-site 5 days a week, though flexible working arrangements (including working from home) can be discussed. Security Clearance None required. Additional T&Cs In addition to the employer's statutory requirements, the individual must be subject to following checks prior to the commencement of the engagement: 1. A check on the financial history of the individual using reputable services such as Experian or Equifax. 2. Verification of employment or academic references covering the last five years or a lesser period as appropriate in the individual’s circumstances but covering a minimum of 3 years. No. of Specialists to Evaluate 6 Cultural Fit Criteria • Resourceful - delivering the greatest public value for our money • Public first - putting the public's needs first • Informed - we always know what we're talking about when we talk about consumers and markets • Open and honest - we say exactly what we'll do - and then do it • Courageous - stand up for what is right not what is easy, even under pressure • Accountable - we take responsibility for our decisions and actions • Fast and fair - staying focused, keeping things simple and delivering at pace • Challenging - using our judgement to challenge and change the status quo • Forward thinking - actively anticipating and preparing for the future • Keep an open mind - always be objective and fair, put your preconceptions in a box • Get the full picture - actively seek the input of others with different experiences • Be a good colleague - being caring, helpful, supportive and challenging so we can work at our best • Forge productive links - create collaborative relationships across and outside the FCA • Join things up - seek ways to share knowledge and integrate work • Support and challenge - stay focused on our priorities and support each other when under pressure Evaluation Weighting Technical competence 60% Cultural fit 10% Price 30% Questions from Suppliers 1. Does the Cyber security Manager need to hold SC clearance? As per the published requirements, the specialist is not required to hold any security clearance. 2. We potentially have a specialist who is ideal for the role but his day rate exceeds our ceiling rate, would you be able to consider a revised day rate at later stages? Unfortunately not; in order for the call-off contract to remain compliant with the Digital Outcomes and Specialists 2 framework, day rates must not exceed the maximum rates set under the framework. 3. Is the role deemed outside of IR35? All proposed specialists should fall outside of IR35 regulations. 4. Is there a current incumbent already in the role? The role is currently filled by a permanent member of FCA staff, though they are due to be leaving the FCA on Friday 27 July 2018. 5. Is there a current incumbent and if so will he or she be applying? The role is currently filled by a permanent member of FCA staff, though they are due to be leaving the FCA on Friday 27 July 2018. They are moving to another company and have no plans to re-join the FCA as a consultant any time in the foreseeable future. 6. Do you have an IR35 status on this role please? Please refer to previous clarification question responses. 7. Can the offer be a small team of suitably qualified individuals which would allow FCA to benefit from the wider company's skills (3 x CISSP and other qualifications). At this time, we are looking for an individual specialist to fill the role. If this changes in the future, it is unlikely we will use the Digital Outcomes and Specialists 2 framework - which is geared towards individual specialists. 8. Will the individual be able to take annual leave during the secondment / assignment (subject to agreement with management)? The specialist will not be an employee of the FCA so will not be eligible for annual leave. We will however accommodate pre-agreed periods of absence during the term of the agreement, provided they are highlighted a good time in advance and are not excessive in length (i.e. in excess of two weeks). 9. We have suitable considerate for the role, but can't start on the date suggested. Would you consider a later start date? Ideally we would like the specialist to start as soon as possible. However, for the right candidate we would be willing to consider a later start date than that listed in the requirements, provided than can start by September 2018, 10. Our specialist candidate has a wealth of experience relevant to point 1 in the essential skills list. However, this experience has been gained within a high-security government dept, not specifically in the financial services sector. Is this experience likely to be deemed acceptable? Yes, it is not imperative that the candidate has financial services experience, as long as the individual can demonstrate the correct level of skills and experience aligned to the skills list. 11. The successful applicant will lead a small team. Does this involve line management responsibilities? If so, can you say in outline what they are please? The role holder will be expected to align with the FCA’s line management responsibilities; providing 2 colleagues with support and coaching/guidance to deliver and achieve defined objectives. 12. The role is described in terms of strategy and governance. Will the post holder also have operational duties, e.g. being part of an incident management response team? Yes, the individual may be asked to support incidents as part of the CISO’s management team’s overall responsibilities but it this would be on an exceptional basis. Oversight/leadership is needed to ensure formal/mandatory operational risk reporting is delivered as part of the CISO’s governance responsibilities.
Timeline
- Completed: Tender published16 July 2018Current notice
- Completed: Submission date23 July 2018
About the buyer
Financial Conduct Authority is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@financial-conduct-authority.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@financial-conduct-authority.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@financial-conduct-authority.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@financial-conduct-authority.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@financial-conduct-authority.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@financial-conduct-authority.gov |
Related buyers
Buyers similar to Financial Conduct Authority.
- 1,716£205.5bn
- 461£2.1bn
- 372£250.0m
- 364£15.0bn
- 294£2.8bn
- 267£19.9bn
- 203£1.0bn
- 142£900.0m
- 126£60.5m
- 102£954.3m
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
