Psst! Infosec bigwigs: Wanna be head of security at HM Treasury for £50k?
- Reference: 1680262806
- News link: https://www.theregister.co.uk/2023/03/31/job_ad_hm_treasury/
- Source link:
They'd be sorely disappointed: the starting salary for the right candidate is £50,550 (c. $62,500), which many infosec hounds in the private sector may balk at.
The job, listed on [1]LinkedIn – where CVs go to die – is a permanent post that could be either full or part time, and flexible working hours can be accommodated, working from London, Darlington or Norwich.
[2]
"We're looking for a Head of Cyber Security to join the team and provide advice to seniors on cyber risks across our services and systems," the posting reads. "This is an exciting and meaningful opportunity to work on cyber security at the heart of Government in a time of momentous change."
[3]
[4]
HM Treasury says it is seeking a candidate who has "a consistent track record of managing cyber risk management services and people," and the ability to "empower, lead and drive a team providing critical services to the organization" will also be key.
Oh, and money mustn't be that important to you. After all, who cares about paying the bills at a time of the highest inflation hike for decades?
[5]
The Head of Cyber Security is only regarded as being a "Mid-Senior level" role, according to the Treasury. Perhaps that is why the salary government is offering is in the range of £50,550 to £57,500, while a quick glance at a few job sites shows that the going rate for a Head of IT Security in London is more like £85,000 to £100,000.
This is the government's economic and finance ministry we are talking about here – the department with overall control of public spending and setting the direction of the UK's economic policy – so you would think that being in overall charge of IT security would be a pretty demanding role.
In fact, the job ad says the Head of Cyber Security will be responsible for service delivery, people and service management, budget and supplier relationship management, security governance, monitoring and assurance. The winning candidate will also have oversight of "specialist security processes" and the provisioning of device security throughout the organization.
[6]
That sounds like quite a demanding job to us – especially as it is in an organization where a security breach could cause serious damage.
Some in the security industry itself are even more critical. Tom Lysemose Hansen, CTO and co-founder of Norwegian cybersecurity outfit Promon claimed that comparable jobs in the private sector are worth five to seven times the salary on offer.
"Such a startlingly low salary for a position as strategically important as this should concern UK taxpayers. If you pay peanuts, you get monkeys," he said.
"Frankly, this gives the impression that the British government isn't taking its cyber security seriously. If cyber security firms can see it, then you can bet that malicious actors can too."
[7]Head of Big Tech Expertise? Believe it or not, it's a UK.gov vacancy for a Whitehall job
[8]Fancy joining the SAS's secret hacker squad in Hereford as an electronics engineer for £33k?
[9]Be careful, 007. It's just had a new coat of paint: Today is D-day for would-be Qs to apply to MI6
[10]IBM job ad calls for 12 years' experience with Kubernetes – which is six years old
Such a senior cyber position comes with inherent stresses – especially as it is at such a financially and economically important institution – Hansen added, and so it is crucial the UK public sector pay a competitive salary to attract high caliber candidates well suited to the role.
"Otherwise, from a national security perspective, the UK is flirting with disaster and just waiting for the next major cyber attack or data breach."
The government should recognize this – especially as the foreword to last year's [11]National Cyber Strategy states that "basic cyber security remains central to our efforts as we toughen up our response to those who attack the UK and our citizens. Our focus is also on making the public sector more resilient."
Still, at least the successful candidate will have access to a cycle-to-work salary sacrifice scheme and season ticket advances. ®
Get our [12]Tech Resources
[1] https://www.linkedin.com/jobs/view/head-of-cyber-security-at-hm-treasury-3533259069/?originalSubdomain=uk#SALARY
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZCcDokt9CyeM2TkYpUyOjgAAAM8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCcDokt9CyeM2TkYpUyOjgAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCcDokt9CyeM2TkYpUyOjgAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCcDokt9CyeM2TkYpUyOjgAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCcDokt9CyeM2TkYpUyOjgAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/01/26/head_of_big_tech_expertise_job_ad/
[8] https://www.theregister.com/2021/08/13/sas_mab5_secret_hacker_squad_hereford/
[9] https://www.theregister.com/2021/05/26/q_job/
[10] https://www.theregister.com/2020/07/13/ibm_kubernetes_experience_job_ad/
[11] https://www.gov.uk/government/publications/national-cyber-strategy-2022/national-cyber-security-strategy-2022
[12] https://whitepapers.theregister.com/
Re: Can't pay more
The joys of public sector pay scales and exactly that - we can't be seen to have somebody paid more than their boss (despite the fact that as I've argued until I'm blue in the face the scoring for grades means there's technically no reason why this can't happen).
It also highlights that at this moment in time with certain specialisms within IT paying out like a casino the public sector just can't compete on salaries. My area has had job vacancies repeatedly advertised but we're shooting way below market rate so we barely even get applicants, never mind good ones - so we hire in contractors getting paid very well instead. *shrug*
Re: Can't pay more
As a counterpoint Renfrewshire Council in Scotland have a Security and Governance Manager job up right now - £56-59k.
But tbh I don't really know any qualified security guy who would even look at a salary like that for a job that is likely going to be one to drive you into an early grave whilst ministers use you as a blamehound for their failings.
Re: Can't pay more
I think the latter part of your post is a key point here.
You know full well that in such a role, if anything went wrong you would be the person scapegoated as the root of the problem. That's one of the reasons you pay people in high risk roles more - high risk? High reward. Such a failure and loss of the job at the Treasury would effectively be the end of your career.
Re: Can't pay more
"Such a failure and loss of the job at the Treasury would effectively be the end of your career."
If the Treasury gets pwned, the possible material losses could be 9-figures plus plus. The loss of confidence alone would be a gigantic economic blow. Far FAR more than paying a decent salary to the right person to prevent it
Re: Can't pay more
Errrmmmm That's common sense, but this is the UK Government we are talking about.
Only reason to take the job
Give lucrative contracts to your mates
Re: Only reason to take the job
Like Crapita? That being the Crapita who [1]only this morning had what could well be a cyberattack
One of the sad things about The Americanised Register these days is that you now have to read about stories like this in the mainstream press...
[1] https://www.theguardian.com/business/2023/mar/31/capita-it-systems-fail-cyber-attack-nhs-fears
Re: Only reason to take the job
Same for the story about the police call centre sending thousands of emergency calls to a non-existent patrol car in order to hit their response targets
https://www.bbc.co.uk/news/uk-scotland-tayside-central-65086107
Hackers of the world already headed to the UK
Now the treasury have announced they couldn't care less about InfoSec. Not in words (naturally). But certainly in deeds.
Top-up
I am sure Russia or another rouge state will happily top up the wage by another £50k.
But reality is that, these jobs are likely posted this way so that nobody with necessary qualification applies and then CS can apply to fill the role with a worker from one of the well known big consultancies, where consultancy will get paid £xxxx per day to fill the role.
That's how grifting works in public sector.
Re: Top-up
Presumably someone with a BTEC Level 4 Diploma in Information Security Professional Competence will apply for the job?
They will know about installing anti-virus software and stuff like that.
Re: rouge state?
Gave me a laugh for a wet Friday when the alternative to reading this site is editing a 86,000 word manuscript that is as boring as hell.
Rouge : the stuff that goes on the cheeks of women in a certain profession.
Rogue : The word that you were looking for.
Re: rouge state?
No, in that case the UK is definitely a Rouge state
The whole UK Government approach to IT is wrong.
I have a friend, he's a contractor, he's very good. He does a lot of work for UK Gov, for which he charges a huge day rate.
This seems common amongst IT in government, we seem to be supported mainly by well paid contractors. People who are generally motivated by money, and will leave if a more lucrative opportunity presents itself; taking all their accumulated knowledge with them. (There's nothing wrong with this, this is what contractors do).
Personally I think the UK needs it's own IT department, the government should build a department for IT, staff it with competent well paid professionals. This could then be used as the source of staff for government IT projects. The DWP needs a new system developing then it contracts it out to the internal IT department.
That way you'll get a department staffed with competent professionals, who should enjoy the variety of work they end up doing, but will also not walk out at the end of each project taking all their tax payer funded experience with them.
After a few years you're going to have a department with the necessary skills, and more importantly, experience and systems knowledge to deliver decent IT to the British public.
It'll never happen though, no one would want to risk having to actually hire someone properly. Plus it probably comes out of capex rather than opex or some other accounting bullshit that seems to matter to people.
Ahh well, like Professor Farnsworth said 'A man can dream... a man can dream'
CCTA
You mean something like this ?
https://en.wikipedia.org/wiki/Central_Computer_and_Telecommunications_Agency
Well, arguably, that is what some of the large consultancies do: they have Government practices, which have staff who work on these projects long term and their knowledge has the chance to be reused on other projects. They do have some very good people, with masses of relevant experience. Effectively they are the government IT dept.
But, of course, they charge much, *much* higher rates than anyone actually working in the Civil Service can be paid.
"they charge much, *much* higher rates than anyone actually working in the Civil Service can be paid"
Yep, and its a wonder they get away with it!! Imagine if a few private companies between them hired all the nurses and doctors in UK, paid them slightly more than government rate, and then contracted them out to local NHS trusts at double that rate. But to the consultancy-led Tory* government , that's a far better outcome than simply paying the nurses and doctors a proper salary, because it shovels money into their mates pockets, who shovel it back into theirs'.
Not saying Labour hasn't done or won't do the same, but orders of magnitude difference of scale.
Give it a couple of years...
...we're nearly there when it comes to doctors and nurses.
That's already happening to an extent.
There was an article on the radio about it a few days ago, medical agencies have seen their profits skyrocket.
Think they said that the staff they hire out are often more interested in the flexibility compared to the actual money although of course they aren't turning down the bump.
I can well believe it, when daughter was born only reason wife was able to go back to nursing full time, 12 hour night shifts on a rota, was because the nursery was able to be flexible.
Our nursery were quite happy to work with her rota as long as they got a note of shifts at least 2 weeks ahead.
All the other ones were "you can have complete flexibility, you can have whatever days you want as long as they are the same days every week" so we'd have ended up having to put her in 5 days a week.
I can understand why the others weren't able to do be so flexible but it makes life very hard for parents on rotas.
Wouldn’t the heavy lifting of providing cyber security for all government departments be the responsibility of the intelligence services? Maybe, despite the title, the job would be a little more mediocre, aka implementing the measures they’re told to implement.
Public Sector & Pay
The problem with pay in the public sector is that they can't separate out "management skills" from "specalist/technical skills".
i.e. You can only get paid a certain amount before you have to become management.
The pay band looks like it's at the top of the technical scale before you pivot to managerial.
Then they (management) wonder why they can't employ any half-decent specalist/technical staff and so resort to contractors & consultants - which we all know cost way more than properly paid staff.
Disclaimer: I still work in the public sector.
Re: Public Sector & Pay
That's why I left. Have less responsibility, less stress and double the salary.
The public sector is terrible at managing professional roles even more so where there is market demand.
"successful candidate will have access to a cycle-to-work salary sacrifice scheme"
So the already pathetically low salary will be docked if the appointee chooses not to use public transport?
I love the concept. Maybe it could be docked it further if they choose to bring their own sandwiches for lunch?
Reg readers might expect the vacancy would come with a salary that reflects its criticality
I think we're far more likely to expect that anything IT related done by the government will be a farcical disaster. This yearly salary is similar to some of the daily rates they hand out to contract agencies for useless work. It's also similar to the daily rates ex-ministers have been asking for jobs on the side recently. And the many responsibilities listed should be about 10 different jobs if they were to be done properly.
I'd be expecting the head of security at the treasury to come from GCHQ or MI5, not LinkedIn, but sadly this story shows just how degraded government thinking has become about the running of government itself.
Re: Reg readers might expect the vacancy would come with a salary that reflects its criticality
Yeah, it's very weird.
Mid-senior would be an infastructure team lead at Foreign Office for same band.
I used to work for a UK government ministry and the guy in charge of a very important system came to visit us. A lovely bloke. Beforehand we had been told by a very hierarchy minded manager that he was a 'Band A' grade and we should mind our Ps and Qs. I told him that when we were alone, and he rolled his eyes and said 'they had to give me that grade to make me stay - I'm no different from you'. A band A was on around 50k at the time.
Parliament is little better
Head of Infosec Risk HMG Pariliamentary Digital services - £75k.
That's still joke money to deal with teh risk associated with the loonies that are using WhatsApp and TikTok to move government secrets around
It may be that the Civil Service doesn't want anyone from outside the club getting the role and upsetting the apple cart. Making the job unattractive to the right candidates leaves the way open for one of the First Division brigade to walk into the job and continue to deliver piss poor performance.
Somebody knows the way the Whitehall machine works. Outside scrutiny? Oh there are security implications.
Harding
What's Baroness Harding up to these days?
Lots of prior experience
Things will even themselves out
Bad news - low salary
Good news - plenty of opportunity to explore the cyber weaknesses of the UK national bank
I'd assume this is part time, £50k for five-days a year, after all, a head of cybersec must be worth at least as much as a useless ex-minister.
The results will be
Only three types of people will take this job;
1. Retired IT person that is board and wants to get out of the house.
2. Underqualified person that will use it as a stepping stone for 6 months while trying not to get fired.
3. A criminal that will be creating and selling back doors, that won't be outed for years.
Oh wait, there is option 4, use a human service program for an offended group, and give them a job they have no skills for so they can tell the world they are doing good - while really setting up the person, position and tech to fail. nope, this is option 2.
Can't pay more
Well, they can't pay any more can they? As they'd then have to pay that person's manager more, and *their* manager more. Where does it end?!