King's College Hospital NHS Foundation Trust

Information Risk Manager

The closing date is 03 August 2025

Job summary

The Information Risk Manager will be responsible for managing information risks across the Trust. This role will ensure that information risk management processes are embedded within the organisation to comply with legal, regulatory, and NHS requirements. The postholder will act as the subject matter expert on information risk, providing advice and guidance to senior management, clinical and non-clinical teams. They will work closely with the Information Asset Owners, Data Protection Officer, and IT Security teams to safeguard the organisation's information assets and ensure a robust information risk management framework is in place.

Main duties of the job

  • Information Risk Management
  • Risk Assessment and Audits
  • Advisory and Guidance
  • Personal Data Breach Management
  • Information Asset Management
  • Governance and Compliance
  • Project Support
  • People Management and Performance

About us

King's College Hospital NHS Foundation Trust is one of the UK's largest and busiest teaching Trusts with a turnover of c£1.8 billion, 1.5 million patient contacts a year and more than 15,000 staff based across South East London. The Trust provides a full range of local and specialist services across its five sites. The trust-wide strategy of Strong Roots, Global Reach is our Vision to be BOLD, Brilliant people, Outstanding care, Leaders in Research, Innovation and Education, Diversity, Equality and Inclusion at the heart of everything we do. By being person-centred, digitally-enabled, and focused on sustainability, we aim to take Team King's to another level.

We are at a pivotal point in our history and we require individuals who are ready to join a highly professional team and make a real, lasting difference to our patients and our people.

King's is committed to delivering Sustainable Healthcare for All via our Green Plan. In line with national Greener NHS ambitions, we have set net zero carbon targets of 2040 for our NHS Carbon Footprint and 2045 for our NHS Carbon Footprint Plus. Everyone's contribution is required in order to meet the goals set out in our Green Plan and we encourage all staff to work responsibly, minimising their contributions to the Trust's carbon emissions, waste and pollution wherever possible.

Details

Date posted

22 July 2025

Pay scheme

Agenda for change

Band

Band 7

Salary

£56,276 to £63,176 a year per annum inclusive of HCAS

Contract

Permanent

Working pattern

Full-time

Reference number

213-CORP-7289837-A

Job locations

King's College Hospital NHS Foundation Trust

Denmark Hill

London

SE5 9RS


Job description

Job responsibilities

Information Risk Management

Lead on the identification, assessment, and management of information risks across the Trust.

Lead on, oversee, maintain and regularly update the IG risk register, ensuring all risks are logged, assessed, mitigated, and escalated appropriately.

Develop and implement information risk management policies and procedures aligned with NHS and regulatory standards (e.g. UK GDPR, DSP Toolkit).

Develop risk mitigation strategies, collaborating with risk owners and ensuring that controls are established and robust.

Provide regular reports to the SIRO, the Information Governance Steering Group (IGSG), and relevant committees, including at Board level, on information risk exposure and mitigation activities.

Support the SIRO in providing assurances to the CEO.

Risk Assessment and Audits

Maintain oversight of complex data protection and confidentiality risk assessments and develop mitigating strategies for highly complex or strategic scenarios.

Oversee the application of the principles of risk assessment, risk management processes and decision-making as they relate to information governance.

Carry out expert reviews of Data Protection Impact Assessments (DPIAs) for new systems, processes, and projects.

Advise the DPO on the risks identified via DPIAs, and recommend DPIAs for further review by the DPO.

Lead and coordinate internal audits related to information risk and compliance with relevant standards, such as ISO 27001, DSP Toolkit, etc.

Identify and provide recommendations for improving information risk controls following internal and external audit findings.

Advisory and Guidance

Act as the point of contact for expert advice and guidance on information risk to all Trust staff, including senior management and clinicians.

Support the development of a risk-aware culture within the organisation through the development and delivery of training, workshops and awareness campaigns.

Provide advice on the information risk implications of system implementations, third-party data sharing, and information security initiatives.

Personal Data Breach Management

Ensure that there are clear procedures in place on how to report, investigate and manage personal data breaches.

Manage personal data breaches and information security incidents, ensuring that all incidents are thoroughly investigated and reported in line with statutory and regulatory requirements.

Identify and ensure lessons learned from incidents are used to enhance risk management practices and reduce the likelihood of reoccurrence.

Information Asset Management

Establish a robust information risk management structure.

Lead the process of information asset management.

Develop and provide training to IAOs and support them in identifying and managing information risks.

Ensure the effective management of information assets across the Trust, in collaboration with IAOs and IAAs.

Instruct and support IAOs and IAAs to understand their responsibilities for information security and risk.

Conduct regular information asset audits and risk reviews, ensuring that information is classified, handled, and protected appropriately.

Governance and Compliance

Support the Information Governance Manager in ensuring that the Trust complies with relevant legal, regulatory, and NHS requirements related to information governance and risk.

Ensure compliance with DSP Toolkit requirements around risk management.

Monitor changes in legislation and regulations that impact information risk, and ensure the Trusts risk management framework is updated accordingly.

Project Support

Provide information risk assessments and expert guidance for Trust projects, including new technology implementations, system upgrades, and third-party data sharing agreements.

Collaborate with project managers and technical teams to ensure that risks are identified, assessed, and mitigated during project planning and execution.

People Management and Performance

Lead, coach and manage the performance of the team in line with good people management practices, ensuring excellence is recognised and underperformance is addressed.

Participate in regular performance appraisal meetings and ensure that each member of the team has a clear set of objectives and development plans.

Ensure the team is compliant with all statutory, mandatory, and other professional training requirements.

Manage team absences, including sickness, in line with Trust policy, ensuring the appropriate return-to-work meetings occur, e-roster is updated, and productivity is maintained at the highest possible level.

Identify and fill any vacancies that arise within the team in line with the Trusts recruitment policy and process.

Identify talent and support the internal talent management process in order to attract and retain a succession plan for your people.

Review the teams skills mix at regular intervals in order to identify any potential opportunities to maximise resource utilisation / allocation, ensuring job descriptions are kept up-to-date.

Ensure overall wellbeing of the team, continuously supporting in improving morale and encouraging a culture of zero-tolerance for bullying and harassment.

General

The post-holder has a general duty of care for their own health, safety and wellbeing and that of work colleagues, visitors and patients within the hospital, in addition to any specific risk management or clinical governance accountabilities associated with this post.

The post-holder must observe the rules, policies, procedures and standards of King's College Hospital NHS Foundation Trust, together with all relevant statutory and professional obligations.

We want to be an organisation where everyone shares a commitment to delivering the very best care and feels like their contribution is valuable and valued.

At Kings we are a kind, respectful team:

Kind. We show compassion and understanding and bring a positive attitude to our work

Respectful. We promote equality, are inclusive and honest, speaking up when needed

Team. We support each other, communicate openly, and are reassuringly professional

The post-holder should observe and maintain strict confidentiality of personal information relating to patients and staff.

The post-holder must be responsible, with management support, for their own personal development, and actively contribute to the development of colleagues.

This job description is intended as a guide to the general scope of duties and is not intended to be definitive or restrictive. It is expected that some of the duties will change over time and this description will be subject to review in consultation with the post-holder.

All employees must hold an 'nhs.net' email account, which is the Trust's formal route for email communication.

Safeguarding

The Trust takes the issues of Safeguarding Children, Adults and addressing Domestic Abuse very seriously. All employees have a responsibilityto support the organisation in our duties by:

Attending mandatory training on safeguarding children and adults

Familiarising themselves with the Trust's processes for reporting concerns

Reportingany safeguarding child or adult concerns appropriately

Infection Control Statement

The post-holder has an important responsibility for and contribution to infection control and must be familiar with the infection control and hygiene procedures and requirements when in clinical areas.

The post-holder has an important responsibility for and contribution to infection control and must be familiar with the infection control and hygiene requirements of this role.

These requirements are set out in the National Code of Practice on Infection Control and in local policies and procedures which will be made clear during your induction and subsequent refresher training. These standards must be strictly complied with at all times.

Job description

Job responsibilities

Information Risk Management

Lead on the identification, assessment, and management of information risks across the Trust.

Lead on, oversee, maintain and regularly update the IG risk register, ensuring all risks are logged, assessed, mitigated, and escalated appropriately.

Develop and implement information risk management policies and procedures aligned with NHS and regulatory standards (e.g. UK GDPR, DSP Toolkit).

Develop risk mitigation strategies, collaborating with risk owners and ensuring that controls are established and robust.

Provide regular reports to the SIRO, the Information Governance Steering Group (IGSG), and relevant committees, including at Board level, on information risk exposure and mitigation activities.

Support the SIRO in providing assurances to the CEO.

Risk Assessment and Audits

Maintain oversight of complex data protection and confidentiality risk assessments and develop mitigating strategies for highly complex or strategic scenarios.

Oversee the application of the principles of risk assessment, risk management processes and decision-making as they relate to information governance.

Carry out expert reviews of Data Protection Impact Assessments (DPIAs) for new systems, processes, and projects.

Advise the DPO on the risks identified via DPIAs, and recommend DPIAs for further review by the DPO.

Lead and coordinate internal audits related to information risk and compliance with relevant standards, such as ISO 27001, DSP Toolkit, etc.

Identify and provide recommendations for improving information risk controls following internal and external audit findings.

Advisory and Guidance

Act as the point of contact for expert advice and guidance on information risk to all Trust staff, including senior management and clinicians.

Support the development of a risk-aware culture within the organisation through the development and delivery of training, workshops and awareness campaigns.

Provide advice on the information risk implications of system implementations, third-party data sharing, and information security initiatives.

Personal Data Breach Management

Ensure that there are clear procedures in place on how to report, investigate and manage personal data breaches.

Manage personal data breaches and information security incidents, ensuring that all incidents are thoroughly investigated and reported in line with statutory and regulatory requirements.

Identify and ensure lessons learned from incidents are used to enhance risk management practices and reduce the likelihood of reoccurrence.

Information Asset Management

Establish a robust information risk management structure.

Lead the process of information asset management.

Develop and provide training to IAOs and support them in identifying and managing information risks.

Ensure the effective management of information assets across the Trust, in collaboration with IAOs and IAAs.

Instruct and support IAOs and IAAs to understand their responsibilities for information security and risk.

Conduct regular information asset audits and risk reviews, ensuring that information is classified, handled, and protected appropriately.

Governance and Compliance

Support the Information Governance Manager in ensuring that the Trust complies with relevant legal, regulatory, and NHS requirements related to information governance and risk.

Ensure compliance with DSP Toolkit requirements around risk management.

Monitor changes in legislation and regulations that impact information risk, and ensure the Trusts risk management framework is updated accordingly.

Project Support

Provide information risk assessments and expert guidance for Trust projects, including new technology implementations, system upgrades, and third-party data sharing agreements.

Collaborate with project managers and technical teams to ensure that risks are identified, assessed, and mitigated during project planning and execution.

People Management and Performance

Lead, coach and manage the performance of the team in line with good people management practices, ensuring excellence is recognised and underperformance is addressed.

Participate in regular performance appraisal meetings and ensure that each member of the team has a clear set of objectives and development plans.

Ensure the team is compliant with all statutory, mandatory, and other professional training requirements.

Manage team absences, including sickness, in line with Trust policy, ensuring the appropriate return-to-work meetings occur, e-roster is updated, and productivity is maintained at the highest possible level.

Identify and fill any vacancies that arise within the team in line with the Trusts recruitment policy and process.

Identify talent and support the internal talent management process in order to attract and retain a succession plan for your people.

Review the teams skills mix at regular intervals in order to identify any potential opportunities to maximise resource utilisation / allocation, ensuring job descriptions are kept up-to-date.

Ensure overall wellbeing of the team, continuously supporting in improving morale and encouraging a culture of zero-tolerance for bullying and harassment.

General

The post-holder has a general duty of care for their own health, safety and wellbeing and that of work colleagues, visitors and patients within the hospital, in addition to any specific risk management or clinical governance accountabilities associated with this post.

The post-holder must observe the rules, policies, procedures and standards of King's College Hospital NHS Foundation Trust, together with all relevant statutory and professional obligations.

We want to be an organisation where everyone shares a commitment to delivering the very best care and feels like their contribution is valuable and valued.

At Kings we are a kind, respectful team:

Kind. We show compassion and understanding and bring a positive attitude to our work

Respectful. We promote equality, are inclusive and honest, speaking up when needed

Team. We support each other, communicate openly, and are reassuringly professional

The post-holder should observe and maintain strict confidentiality of personal information relating to patients and staff.

The post-holder must be responsible, with management support, for their own personal development, and actively contribute to the development of colleagues.

This job description is intended as a guide to the general scope of duties and is not intended to be definitive or restrictive. It is expected that some of the duties will change over time and this description will be subject to review in consultation with the post-holder.

All employees must hold an 'nhs.net' email account, which is the Trust's formal route for email communication.

Safeguarding

The Trust takes the issues of Safeguarding Children, Adults and addressing Domestic Abuse very seriously. All employees have a responsibilityto support the organisation in our duties by:

Attending mandatory training on safeguarding children and adults

Familiarising themselves with the Trust's processes for reporting concerns

Reportingany safeguarding child or adult concerns appropriately

Infection Control Statement

The post-holder has an important responsibility for and contribution to infection control and must be familiar with the infection control and hygiene procedures and requirements when in clinical areas.

The post-holder has an important responsibility for and contribution to infection control and must be familiar with the infection control and hygiene requirements of this role.

These requirements are set out in the National Code of Practice on Infection Control and in local policies and procedures which will be made clear during your induction and subsequent refresher training. These standards must be strictly complied with at all times.

Person Specification

Education and Qualifications

Essential

  • Educated to post-graduate degree level in relevant subject or equivalent level qualification or significant experience of working at a similar level in specialist area.

Desirable

  • Further training or significant experience in project management or supporting change management processes.

Skills and Competencies

Essential

  • Thorough understanding of information risk management, information security, and data protection principles (including UK GDPR, Data Protection Act 2018).
  • Knowledge of NHS Information Governance standards and best practices.
  • Strong analytical skills, with the ability to assess risks and propose effective mitigation strategies.
  • Excellent written and verbal communication skills, with the ability to present complex information to senior management.
  • Ability to work independently and as part of a multidisciplinary team.
  • Strong problem-solving skills, with the ability to work under pressure and manage competing priorities.
  • High level of attention to detail, excellent organisational and presentation skills.
  • Ability to engage and influence stakeholders at all levels, including senior management.

Desirable

  • Understanding of clinical processes and the associated information risks.
  • Familiarity with relevant NHS policies and governance frameworks, including Care Quality Commission (CQC) standards and ICO guidelines.

Knowledge and Experience

Essential

  • Demonstrable experience managing information risks within a complex organisation (preferably within the public sector or NHS).
  • Proven experience in leading risk assessments, developing risk mitigation plans, and maintaining risk registers.
  • Experience in personal data breach management.
  • Experience of establishing SIRO and Information Asset Owners (IAOs) network and maintaining Information Asset Registers (IARs).

Desirable

  • Experience with the Data Security and Protection Toolkit (DSPT)
Person Specification

Education and Qualifications

Essential

  • Educated to post-graduate degree level in relevant subject or equivalent level qualification or significant experience of working at a similar level in specialist area.

Desirable

  • Further training or significant experience in project management or supporting change management processes.

Skills and Competencies

Essential

  • Thorough understanding of information risk management, information security, and data protection principles (including UK GDPR, Data Protection Act 2018).
  • Knowledge of NHS Information Governance standards and best practices.
  • Strong analytical skills, with the ability to assess risks and propose effective mitigation strategies.
  • Excellent written and verbal communication skills, with the ability to present complex information to senior management.
  • Ability to work independently and as part of a multidisciplinary team.
  • Strong problem-solving skills, with the ability to work under pressure and manage competing priorities.
  • High level of attention to detail, excellent organisational and presentation skills.
  • Ability to engage and influence stakeholders at all levels, including senior management.

Desirable

  • Understanding of clinical processes and the associated information risks.
  • Familiarity with relevant NHS policies and governance frameworks, including Care Quality Commission (CQC) standards and ICO guidelines.

Knowledge and Experience

Essential

  • Demonstrable experience managing information risks within a complex organisation (preferably within the public sector or NHS).
  • Proven experience in leading risk assessments, developing risk mitigation plans, and maintaining risk registers.
  • Experience in personal data breach management.
  • Experience of establishing SIRO and Information Asset Owners (IAOs) network and maintaining Information Asset Registers (IARs).

Desirable

  • Experience with the Data Security and Protection Toolkit (DSPT)

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).

Additional information

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).

Employer details

Employer name

King's College Hospital NHS Foundation Trust

Address

King's College Hospital NHS Foundation Trust

Denmark Hill

London

SE5 9RS


Employer's website

https://www.kch.nhs.uk/ (Opens in a new tab)


Employer details

Employer name

King's College Hospital NHS Foundation Trust

Address

King's College Hospital NHS Foundation Trust

Denmark Hill

London

SE5 9RS


Employer's website

https://www.kch.nhs.uk/ (Opens in a new tab)


Employer contact details

For questions about the job, contact:

Business Manager IG&M (KCH & GSTT)

Riana Mahtani

riana.mahtani@nhs.net

Details

Date posted

22 July 2025

Pay scheme

Agenda for change

Band

Band 7

Salary

£56,276 to £63,176 a year per annum inclusive of HCAS

Contract

Permanent

Working pattern

Full-time

Reference number

213-CORP-7289837-A

Job locations

King's College Hospital NHS Foundation Trust

Denmark Hill

London

SE5 9RS


Supporting documents

Privacy notice

King's College Hospital NHS Foundation Trust's privacy notice (opens in a new tab)