Whitehall ‘not cool enough’ to attract top cyber security talent
The government needs to offer tech specialists more freedom and creativity if it wants to recruit the most talented people, according to a recruiter in the Ministry of Justice.
Whitehall departments aren't members of the 'cool' population - Photo credit: Flickr, Alan Levine
In a blogpost on the MoJ’s digital blog, the department's lead security engineer describes a recent string of unsuccessful recruitment processes for a security engineer role.
They conclude that government has to learn some “hard lessons” and work to shake off the perception that all civil service jobs are about churning out reports and fixing legacy IT systems.
The MoJ employs what is described as “ethical hackers” – people who work inside the department and try to hack into its systems on a constant basis to improve the department’s security systems.
The anonymous recruiter said that there were two rounds that didn’t attract the right level of expertise or enough “original thinkers”, after which they decided to advertise in places that would reach hackers themselves.
However, although this brought in more people at the right level, some of those were “scooped up” by industry instead of taking the government job.
This, the post said, demonstrated a problem faced by government when recruiting for specialist technology roles: that Whitehall isn’t seen as exciting enough.
“Security-minded folk who can think originally still don’t think working for government (which is not all about intelligence agencies) is cool,” it said.
“And for good reason; some see government IT to be a massive legacy monolithic monster (partially true) where they will forever be in a dank corner, trying to troubleshoot memory issues in a some mid-90s middleware, and be valued by how many colour-coordinated reports they can churn out (not true).”
As such, government needs to ensure that people are aware they can be creative in government, can work flexible hours and from wherever they want.
“We need to incentivise these talented people with (nearly) free reign, explain the stakes to them, let them shape security practices in a department along the lines they feel comfortable,” the blogpost said.
“They already have the expertise to know what goes in a good policy and what broken guidance looks like. Let us show them how their efforts can make a difference.”
Meanwhile, the MoJ is also looking to appoint two deputy directors in its digital and technology team, both offering salaries of £90,000.
This article was amended to say that the blogpost was written by the MoJ's lead security engineer, following extra information from the MoJ.
Chair of arm’s-length body praises government response but identifies lower payments for recipients of legacy benefits as one of several ‘rough edges’
New teams, standards and projects are being launched, according to update provided to PAC
PHE also reveals outsourcers Serco and Sitel will process sensitive information and claims length of retention is ‘because Covid-19 is a new disease’
Experts discuss what the lasting impact of the pandemic might be for government and the public sector
PublicTechnology talks to Rich Turner about why organisations need to adopt a ‘risk-based approach’ to security – but first make sure they get the basics right
CyberArk's David Higgins explores the cyber risks of hiring independent contractors
CyberArk's John Hurst looks at the true cost of GDPR breaches
Stephen Twynam of Citrix argues that by adjusting Bring Your Own Device to Use Your Own Device, the sentiment shifts and the negative connotations of BYOD are alleviated