Head of Cyber Security and Assurance

Introduction to the department:
The IT & Digital department is responsible for the force’s adoption and use of information and digital technology.


The department consists of three core functions as follows:

  • Architecture Management (responsible for identifying and selecting the right technologies for the force)
  • Delivery Management (responsible for delivering and implementing the right technologies for the force)
  • Service Management (responsible for managing and maintaining all live, operational technology for the force)

     

Outline of the role:
West Midlands Police have completed a large-scale digital transformation programme, and therefore technologies such as Cloud, Artificial Intelligence, Automation and Mobility are no longer visionary – they underpin policing today.  


The next stage in our technology ambition is focused around the concept of Synergy and delivering secure, resilient and exceptional services. This role will focus and shape our path in the Synergy strategy as it relates to cyber security and assurance—strengthening our ability to prevent, detect, respond and recover from cyber threats—thus driving real-world impact on policing technology and our mission to prevent crime, protect the public and help those in need.


Aligned to IT&D Synergy 2030, this role will embed security as an enabler. Security must be seamless, invisible and silent in enablement—delivering frictionless, secure user journeys while assuring risk, compliance and resilience.  You will continue to embed security from the start of projects utilising SbD (Secure by Design) principles.


In this fast-paced and diverse role you will be responsible for West Midlands Police’s technical cyber security and information assurance capabilities. You’ll be instrumental in ensuring that the department can effectively understand, detect, investigate and respond to cyber security threats and vulnerabilities.


This is a senior leadership opportunity. Leading a specialist team, you will own the operational cyber security and information assurance function, ensuring our capability to understand, detect, investigate and respond to threats and vulnerabilities across a large-scale organisation (~15,000 employees) and associated cloud/on‑prem infrastructure. You will work closely with the Deputy for IT&Digital to design and drive implementation of the cyber security strategy and roadmap, deputising at senior- governance forums (Digital Senior Leadership Team, Technical Design Authority, and programme boards).


This is a one-of-a-kind opportunity, leading a small team - we want you to help take our policing technology cyber security and information assurance level to exceptional.  This new role will own the “Defend as One” security arm of the Synergy 2030 technology strategy.  You will be joining a dept that is consider a highly regarded “technology partner” to our organisation and post our digital transformation we need someone to think creatively around some of the existing and new security, information and cyber challenges that our organisation faces.



Key Responsibilities: 

  • Strategic Leadership & Team Management: Lead and coordinate the Cyber Security and Assurance function. Act as the independent, expert voice of security, managing six-figure budgets and directing a team of specialized information security managers and advisors.
  • Incident Response & Operations: Act as the technical lead for major cyber security incidents and critical vulnerabilities impacting West Midlands Police. Establish operational frameworks, playbooks, security monitoring (SIEM/XDR), and simulated wargaming exercises.
  • Governance, Policy & Compliance: Own and update Information Assurance policies aligned with national frameworks (NCSC, NIST CSF, ISO 27001). Chair the Cyber Security Assurance Board (CSAB) and manage the Security Assessment in Policing (SyAP) national submission and legal/ICO compliance.
  • Risk Management & "Secure by Design": Embed risk-based decision-making and Secure by Design (SbD) principles across all programmes. Govern the IT&D departmental risk register, define risk tolerances with executive leadership, and manage Data Protection Impact Assessments (DPIAs).
  • Stakeholder Engagement & Culture: Partner with National Technical Authorities (NTB-National Technology Board, PDS) to share intelligence. Brief senior leadership on evolving threats through executive reporting, while championing a proactive cyber security culture across the entire force

    Click here to view the full details of the role including the Essential, Desirable and any educational requirements for the role. 

 

Salary and Shifts
Salary: Grade 11 £69,102.00 - £75,177.00
Hours: This is a full-time position working between core hours of 08:00 to 16:00, Monday to Friday.  The role is hybrid working with 60% of working days on-site.

 

Selection Process

  1. Online Application and Sift - You will complete an online application form, which will be reviewed against the skills, experience and behaviours required for the role.   

    Closing Date: Sunday 1st November 2026 

  2. Assessment and Interview  - Candidates who successfully pass the application stage will be invited to attend an interview and assessment. This will provide you with the opportunity to demonstrate your suitability for the role.

    Proposed date(s): TBC for November 2026 

  3. Pre-Employment Checks - If you are selected as the preferred candidate, you will be required to successfully complete relevant pre-employment checks before receiving a formal offer. For internal candidates, some checks may not be required. Checks may include:

    1. Vetting Checks - You must successfully complete the required level of Management vetting and Security clearance before starting the role. This may include providing information relating to your background and financial history as part of the vetting process. Click here for more information.

    2. Medical Checks - Appointment to this role is subject to successfully completing medical checks. This may include a drugs test and, where required, a fitness assessment.

    3. Reference Checks - You will need to provide details covering at least five years of employment, education or other relevant activity history.

 


 We are committed to supporting candidates throughout the recruitment process and reasonable adjustments are available for those who need them.

Apply