Manchester City Council Role Profile Policies, Standards & Governance Manager, Grade 10 ICT Service, Chief Executives Directorate Reports to: Strategy, Governance and Compliance Manager Key Role Descriptors: The roleholder will plan and deliver policies and standards and provide guidance on governance, processes, procedures, tools and techniques to the business and service based ICT teams. The roleholder will develop and manage evaluation plans, including scheduled internal and external audits, penetration testing, self assessment, evaluation following incidents and reporting. Key Role Accountabilities: Ensure appropriate and effective governance and compliance is consistently applied. Be the owner of all governance processes within the service, ensuring these are continually reviewed, updated and communicated to the appropriate audiences throughout the Council. Conduct governance and compliance self-assessments for the ICT Service, reporting on governance and compliance breaches and monitor, facilitate, and in appropriate circumstances partake in, remedial actions to help eliminate or mitigate governance and compliance risks and non compliance with legislation and regulation including independent audit findings. Analyse the impact of applicable legislation and regulation to existing operating processes, policies, procedures and standards and make recommendations for amendments as appropriate. Undertake risk assessments and make recommendations for action, ensuring that the Service Areas Business Continuity Plan and Disaster Recovery Plan are considered. Ensure the dissemination of procedures, standards and related materials. Ensure that all ICT policies, standards and processes meet legal and service requirements and are in accordance with best practice, working in conjunction with relevant managers in services to ensure effective implementation. The roleholder will be accountable for all aspects of the Information Security Management Framework. People. Pride. Place. Ensure that effective security levels are maintained and monitored, evaluating. The roleholder will ensure that relevant sections of the service level agreement (SLA) are fit for purpose, working to agree any underpinning contracts with suppliers. Act as centre of security expertise for the organisation. Ensure that a performance management culture is prevalent throughout the ICT service, and that comprehensive statistics around service provision are maintained and reported upon. Develop and maintain installation, fault diagnosis, investigative analysis and rectification standards for the organisation, ensuring they are in accordance with professional and international standards of security. Accountable for service continuity management plans and processes for the ICT Service. The roleholder will conduct regular analysis of business impact to determine priority recoveries in the event of a major incident and will own the availability plan for the information and network security, monitoring actual availability against the plan and agreed service levels. Develop effective processes to measure and monitor security and system reliability and maintainability. Work collaboratively across directorates and partners in order to achieve quality partnerships with internal and external customers, service managers and external agencies and organisations to achieve the objectives of the ICT Service. The roleholder will work with services to identify ICT security assets, threats, vulnerabilities and countermeasures. Personal commitment to continuous self development and service improvement. Through personal example, open commitment and clear action, ensure diversity is positively valued, resulting in equal access and treatment in employment, service delivery and communications. Where the roleholder is disabled every effort will be made to supply all necessary aids, adaptations or equipment to allow them to carry out all the duties of the role. If, however, a certain task proves to be unachievable, job redesign will be given full consideration. People. Pride. Place. Policies, Standards & Governance Manager– Key Competencies and Technical Requirements Behavioural Competencies Leadership & Management: The behaviours and actions of our managers define how we work and what we achieve. Change: Improving services and making the most of resources. Delivery: Delivery of high quality services is an essential part of what we do. Pride in Manchester: Demonstrating pride in our city. Influence: Effective relationships give the best results. Generic Skills Communication Skills - Ability to build and maintain strong networks of support both internally and externally and to forge effective partnerships with external agencies, voluntary and statutory, and key stakeholders for the continuous improvement of services. Ability to harness the full commitment and responsibility of key stakeholders in delivering the vision for excellence for the city. Analytical Skills - Skills to analyse a wide range of data and other sources of information to break them down into component parts, patterns and relationships; probes for further understanding of problems and makes rational judgements from the available information and analysis demonstrating and understanding of how one issue or risk may be part of a much larger system/issue. Planning and Organising - Sets clearly defined objectives, plans activities and projects well in advance and takes account of risks and changing circumstances; identifies and organises resources and manages time effectively monitoring performance against milestones and deadlines. Project Management & Change Management - Proven ability in developing complex project schedules that clearly defines the timeline required to achieve the required outcomes, with expertise in identifying and monitoring complicated interdependencies, identifying and managing the critical path and utilising the schedule in budget forecasting and planning future resource requirements. Problem Solving and Decision Making - Uses creative ability to find solutions and whilst considering policy and procedure is also confident in adopting (and justifying) novel or non standard approaches. ICT Skills - Skills to perform risk assessment, business impact analysis and accreditation for major information systems within the organisation; provide authoritative advice and guidance on security strategies to manage the identified risk. Research & Intelligence - Demonstrate the ability to analyse, organise and present research material in an appropriate format. Strategic Thinking - Contributes to the development, implementation and evaluation of strategy to shape future plans People. Pride. Place. Technical requirements (Role Specific) Qualified to ITIL v3 Foundation, or willing to work towards. Significant knowledge of the relevant legislative framework and professional standards both within the ICT industry and in particular to a Local Authority. Significant understanding of the ISO27000-series People. Pride. Place.