Job summary
An opportunity has arisen for the key role of Senior Cyber Security Technician within the Royal Wolverhampton NHS Trust.This role is key to the operational effectiveness of cyber security measures across the organisation and will play a significant part in contributing to its compliance with national cyber security standards in line with mandated national policy and our internal Governance, Risk and Compliance Framework.Working as part of the IT Cyber Security Team you will be responsible for penetration testing, security vulnerability assessment, patch management, managing malware detection, anti-exploit, anti-ransomware, advanced threat protection, web filtering, encryption, security information event management (SIEM) and mobile control security solutions.
You will work directly with specialties across IT and the wider organisation to ensure cyber security best practice and principles are embedded into core IT functions ensuring robust monitoring and adherence to cyber security policies and standards. Excellent communications skills are required together with an in-depth knowledge of cyber risks.
You will assist in the production of action plans and documentation across a range of cyber activities. You will assist in the provision of evidence to support the National Data Protection and Security Toolkit and assist in the assurance process for cyber security aspects of Data Protection Impact Assessments.
Main duties of the job
To design, manage, monitor and maintain ICT security systems to prevent compromise of data and hardware owned or maintained by or on behalf of the Trust. This includes, but is not limited to, systems with restricted access or security reasons, such as antivirus, malicious code prevention, web filtering, encryption, patch management software, security vulnerability scanners, network and firewall configurations.
To design, implement and enforce ICT Security policies in conjunction with the Head of Cyber Security and Trust Governance Team. To ensure provision of relevant ICT Security documents and procedures for use as evidence toward the Trust's commitment to meeting full compliance with Information Governance data security requirements.
To resolve user reported ICT security related incidents and service requests.
To manage and lead on IT Security breaches including containment, resolution and where necessary provision of information for investigations.
To deputise for the Head of Cyber Security.
To perform regular auditing of ICT systems and analysis of results.
About us
The Royal Wolverhampton NHS Trust is one of the largest NHS trusts in the West Midlands providing primary, acute and community services and we are incredibly proud of the diversity of both our staff and the communities we serve. We are building a workforce that can help us to fulfil our values, improve the quality of care for patients, and solve the health care problems of tomorrow. We're passionate about the value that diversity of thinking and lived experience brings in enabling us to become a learning organisation and leader in delivering compassionate care for our patients.
We are delighted that we have been rated as "Good" by CQC. We have achieved numerous awards; The Nursing Times Best Diversity and Inclusion Practice and Best UK Employer of the Year for Nursing Staff in 2020.
The Trust is a supportive working environment committed to creating flexible working arrangements that suit your needs and as such will consider all requests from applicants who wish to work flexibly.
Job description
Job responsibilities
Please see attached Job Description/Person Specification for a full detail of role and main responsibilities
Job description
Job responsibilities
Please see attached Job Description/Person Specification for a full detail of role and main responsibilities
Person Specification
Education
Essential
- Achieved or working towards SSCP or equivalent
- IT related Degree Plus Post Grad diploma or equivalent experience.
Desirable
- CISSP, CISM, risk management and/or ITIL (1)
Experience and Skills
Essential
- experience working in a technical cyber security environment
- Good understanding of technical ICT security, TCP/IP, networks and architecture
- Able to demonstrate knowledge and proven management of malicious code prevention, web filtering, encryption, patch management. Mobile device management and security vulnerability scanner/systems.
- Demonstrate a good understanding of risk management and be able to log and report identified ICT risk events
- Ability to resolve complex facts or situations which requiring analysis, interpretation, comparison of a range of options. Analyses, investigates and resolves complex IM&T queries and issues/problem
- Ability to work unsupervised within a clear accountable framework. Ability to work well in a team and under pressure.
- Demonstrates a systematic, disciplined and analytical approach to fault finding and problem solving.
Desirable
- Ability to manage and/or understand enterprise firewall configurations.
Communication Skills
Essential
- Ability to liaise with staff and third parties at all levels in order to resolve issues and/or involve external specialists for problem resolution. Ability to communicate highly complex technical information
- To train other members of staff at all levels in ICT security related skills
- Knowledge of change control processes; to be able to accurately describe in writing the impact and configurations required to action an ICT security change
- Plans effectively and clearly prioritises to get the best possible results
Desirable
Person Specification
Education
Essential
- Achieved or working towards SSCP or equivalent
- IT related Degree Plus Post Grad diploma or equivalent experience.
Desirable
- CISSP, CISM, risk management and/or ITIL (1)
Experience and Skills
Essential
- experience working in a technical cyber security environment
- Good understanding of technical ICT security, TCP/IP, networks and architecture
- Able to demonstrate knowledge and proven management of malicious code prevention, web filtering, encryption, patch management. Mobile device management and security vulnerability scanner/systems.
- Demonstrate a good understanding of risk management and be able to log and report identified ICT risk events
- Ability to resolve complex facts or situations which requiring analysis, interpretation, comparison of a range of options. Analyses, investigates and resolves complex IM&T queries and issues/problem
- Ability to work unsupervised within a clear accountable framework. Ability to work well in a team and under pressure.
- Demonstrates a systematic, disciplined and analytical approach to fault finding and problem solving.
Desirable
- Ability to manage and/or understand enterprise firewall configurations.
Communication Skills
Essential
- Ability to liaise with staff and third parties at all levels in order to resolve issues and/or involve external specialists for problem resolution. Ability to communicate highly complex technical information
- To train other members of staff at all levels in ICT security related skills
- Knowledge of change control processes; to be able to accurately describe in writing the impact and configurations required to action an ICT security change
- Plans effectively and clearly prioritises to get the best possible results
Desirable
Disclosure and Barring Service Check
This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.
Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).
From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).
Additional information
Disclosure and Barring Service Check
This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.
Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).
From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).