Head of Information Security & Business Continuity

Moorfields Eye Hospital NHS Foundation Trust

Information:

This job is now closed

Job summary

We are at a pivotal stage of our digital journey and have an ambitious portfolio of digital technology initiatives ahead of us, all grounded around - empowering patients and service users; improving the experience navigating the healthcare system and joining up systems and data to better meet the needs of citizens.

With the ever-increasing need and interest in the use of digital technology in healthcare, you will be part of a team of Digital, Data and Technology experts that delivers service improvements and keeps at the forefront of new technology.

Main duties of the job

This role is part of our Information Security & Business Continuity team, responsible for:

  • Ensuring the protection of the information in our organisation throughout the information lifecycle - that ensures the confidentiality, integrity, purpose, and availability of information, so that the organisation's information is safeguarded from unauthorised access and misuse.
  • Ensuring the availability of minimum services at a sufficient level for the business to sustain in the event of disasters.
  • Horizon scanning across industry, identifying emerging trends and their potential impact and opportunity for the organisation.
  • Be responsible for ensuring the availability of minimum services at a sufficient level for the business to sustain in the event of disasters.
  • Lead the information security and business continuity team, including managed services and accountability for performance and quality measures.
  • Evolve and define governance, taking ownership and responsibility for ensuring adherence to IT requirements in the Data Security & Protection Toolkit (DSPT), and other appropriate governance frameworks.
  • Develop, maintain, and improve our data and technology Business Continuity & Disaster Recovery Plans, enabling us to respond to and recover from business continuity events - ensuring we can provide a safe level of service to the public during the event, and ensuring we can manage the recovery process and incorporating learning.

About us

At Moorfields, we provide more than just an excellent career and great colleagues to work with. We also offer:

  • Salary including High-Cost Area Supplement
  • Opportunity to join the NHS Pension Scheme
  • Free 24/7 independent counselling service
  • Learning and development opportunities
  • Easy and quick transport links
  • A range of attractive benefits and discounts
  • Access to Blue Light Card and other NHS Discount Schemes
  • Free Pilates classes
  • Full support and training to develop your skills
  • Flexible working friendly organisation

And so much more! To see the full range of benefits we offer please see our Moorfields benefits document.

Date posted

03 May 2024

Pay scheme

Agenda for change

Band

Band 8c

Salary

£78,163 to £88,884 a year per annum pro rata including HCAS

Contract

Permanent

Working pattern

Full-time, Flexible working

Reference number

273-DS-3314-A

Job locations

Moorfields Eye Hospital NHS Foundation Trust

162 City Road

London

EC1V 2PD


Job description

Job responsibilities

At this role level, you will:

  • be involved in strategic decision-making and be central to assuring services to improve the security and resilience of our organisational infrastructure.
  • lead the information security and business continuity team, including managed services and accountability for performance and quality measures.
  • regularly collaborate and find agreement with senior stakeholders, providing direction and challenge
  • be proactive in identifying problems and translating these into non-technical descriptions that can be widely understood.

Skills required for this role

Leadership

  • Provide leadership and direct line management for staff in the Information Security and Business Continuity team and vendors / managed service providers and provide subject matter expertise to wider directorate service teams.
  • Mentor, coach, and line manage teams and services (including managed services) - developing their skills and capabilities to meet the needs of the organisation and healthcare partners, as well as building on existing recruiting capabilities to address new needs or skill gaps.
  • Develop and lead the implementation of long-term strategic plans for information security and business continuity, identifying risks and issues and developing mitigation strategies with clear outcome measures.

Communicating between the technical and non-technical

  • Identify the needs of business and technical stakeholders, ensuring information security and business continuity principles are embedded in all we do.
  • Effectively manage stakeholder expectations
  • Demonstrate excellent communication skills and can manage difficult conversations or negotiations, including highly complex, sensitive and/or contentious information.
  • Present, interpret and explain complicated information to large groups of people to influence understanding and change.
  • Represent information security and business continuity on various internal and external groups, including Trust board-level and/or committee meetings.

Data protection and freedom of information

  • Act as the main point of contact for data protection or freedom of information queries and issues
  • Instigate, commission, oversee or conduct information system searches and investigations to meet data protection or freedom of information needs.
  • Provide advice and expert knowledge to projects / programmes / operational services to ensure that information systems are designed to meet data protection requirements.

Financial management

  • Understand how to balance cost versus value.
  • Consider the impact of user needs.
  • Responsible for the budget for your services (pay and non-pay) and know how and when to escalate issues.
  • Contribute and develop economic investment cases for information security, including business planning processes covering sounds financial models for implementation, and running of the services.

Governance and assurance

  • Evolve and define governance, taking ownership and responsibility for ensuring adherence to IT requirements in the Data Security & Protection Toolkit (DSPT), and other appropriate governance frameworks.
  • Take responsibility for working with and supporting other staff in wider governance.
  • Assure services across sets of services.
  • Use tools such as standards, guardrails, and principles to effectively govern delivery.

Information Security and Business Continuity

  • Demonstrate in-depth knowledge of information security and business continuity, including analysing + testing Trust-wide capabilities and identifying improvement areas.
  • Ensure that our security posture is maintained, monitored/measured and be responsible for leading interventions where standards are not met (example: security patching)
  • Develop, maintain, and improve our data and technology Business Continuity & Disaster Recovery Plans, enabling us to respond to and recover from business continuity events ensuring we can provide a safe level of service to the public during the event, and ensuring we can manage the recovery process and incorporating learning.
  • Lead, plan and execute all required vulnerability audits, security & penetration tests, forensic audits, or related investigations ensuring all findings are evaluated, and where appropriate, fed into continuous service improvement activities to continuously improve our security posture and resilience.
  • Responsible for supporting the design, development, testing and transition of any new information security services into operations.
  • Provide subject matter expert leadership in major incidents and events caused by or affecting information security.
  • Act as the Problem Owner for information security and business continuity matters (ITIL)
  • Responsible for the Information Security Assessment lifecycle, and Information Risk Management documentation for IT systems and data
  • Responsible for ensuring that access to Trust systems is appropriately managed, regularly audited, and lead investigations as required.
  • Provide expertise on information transfer agreements with partner organisations in support of the Information Governance function.
  • Partner with the Organisational Development and Information Governance teams in the planning, development and delivery of information security awareness and training.

Making and informing risk-based decisions

  • Act as a point of escalation
  • Be trusted by senior risk owners as an expert in information security and business continuity.
  • Apply risk methodologies at the most complex levels of risk.

Policies, procedures, and processes

  • Responsibility for information security and business continuity for data and technology, ensuring that policies and procedures are both effective in terms of protection, but realistic and enabling for the business.
  • Develop, maintain, and improve all directorate information security and business continuity policies & procedures, considering regional and national policies and practices, ensuring that both manual and electronic information across the Trust is included in-scope.

Risk management

  • Responsible for the management of information security and data and technology business continuity risks, including identifying new risks and ensuring we are actively managing risk controls.

Service focus, monitoring, and reporting

  • See the bigger picture and investigate how to get the best out of the underlying services to support the organisations strategic objectives and business priorities.
  • Monitor and enforce information security and business continuity principles, policies, and procedures both on a regular basis, and on-demand (as/when required)
  • Take complex reporting data from multiple sources, compare, and interpret against service baseline and industry standards and provide a supporting narrative.
  • Responsible for service reporting for information security and business continuity, in-line with Trust-agreed reporting measures

Strategy

  • Apply strategy, using and challenging patterns, standards, policies, roadmaps, and vision statements. You can provide guidance.
  • Challenge and lead changes to policy and processes that support business outcomes, with business architecture, legal and political implications.
  • Ensure alignment of operating procedures and policies in-line with national, sector (ICS) and industry best practice where it makes sense to do so.

Understanding the whole context

  • Understand trends and practices outside your team and how these will impact your work.
  • See how your work fits into the broader strategy and historical context.
  • Consider the patterns and interactions on a larger scale.

User focus

  • Explain the difference between user needs and the desires of the user.
  • Champion user research to focus on all users.
  • Prioritise and define approaches to understand the user story, guiding others in doing so.

Community of practice

  • Responsible for research and development activities relating to the highly complex field of information security and business continuity.
  • Develop and maintain a network of professionals to enable continuous learning and a community which can share, learn, and keep up to date on the information security and business continuity landscape, within the wider Digital, Data and Technology teams.

Other Duties:

  • Deputise for other members of the CIO Leadership Team as required.
  • Occasional work may be required outside of core business hours to support major projects / programmes.
  • All other reasonable requests

Job description

Job responsibilities

At this role level, you will:

  • be involved in strategic decision-making and be central to assuring services to improve the security and resilience of our organisational infrastructure.
  • lead the information security and business continuity team, including managed services and accountability for performance and quality measures.
  • regularly collaborate and find agreement with senior stakeholders, providing direction and challenge
  • be proactive in identifying problems and translating these into non-technical descriptions that can be widely understood.

Skills required for this role

Leadership

  • Provide leadership and direct line management for staff in the Information Security and Business Continuity team and vendors / managed service providers and provide subject matter expertise to wider directorate service teams.
  • Mentor, coach, and line manage teams and services (including managed services) - developing their skills and capabilities to meet the needs of the organisation and healthcare partners, as well as building on existing recruiting capabilities to address new needs or skill gaps.
  • Develop and lead the implementation of long-term strategic plans for information security and business continuity, identifying risks and issues and developing mitigation strategies with clear outcome measures.

Communicating between the technical and non-technical

  • Identify the needs of business and technical stakeholders, ensuring information security and business continuity principles are embedded in all we do.
  • Effectively manage stakeholder expectations
  • Demonstrate excellent communication skills and can manage difficult conversations or negotiations, including highly complex, sensitive and/or contentious information.
  • Present, interpret and explain complicated information to large groups of people to influence understanding and change.
  • Represent information security and business continuity on various internal and external groups, including Trust board-level and/or committee meetings.

Data protection and freedom of information

  • Act as the main point of contact for data protection or freedom of information queries and issues
  • Instigate, commission, oversee or conduct information system searches and investigations to meet data protection or freedom of information needs.
  • Provide advice and expert knowledge to projects / programmes / operational services to ensure that information systems are designed to meet data protection requirements.

Financial management

  • Understand how to balance cost versus value.
  • Consider the impact of user needs.
  • Responsible for the budget for your services (pay and non-pay) and know how and when to escalate issues.
  • Contribute and develop economic investment cases for information security, including business planning processes covering sounds financial models for implementation, and running of the services.

Governance and assurance

  • Evolve and define governance, taking ownership and responsibility for ensuring adherence to IT requirements in the Data Security & Protection Toolkit (DSPT), and other appropriate governance frameworks.
  • Take responsibility for working with and supporting other staff in wider governance.
  • Assure services across sets of services.
  • Use tools such as standards, guardrails, and principles to effectively govern delivery.

Information Security and Business Continuity

  • Demonstrate in-depth knowledge of information security and business continuity, including analysing + testing Trust-wide capabilities and identifying improvement areas.
  • Ensure that our security posture is maintained, monitored/measured and be responsible for leading interventions where standards are not met (example: security patching)
  • Develop, maintain, and improve our data and technology Business Continuity & Disaster Recovery Plans, enabling us to respond to and recover from business continuity events ensuring we can provide a safe level of service to the public during the event, and ensuring we can manage the recovery process and incorporating learning.
  • Lead, plan and execute all required vulnerability audits, security & penetration tests, forensic audits, or related investigations ensuring all findings are evaluated, and where appropriate, fed into continuous service improvement activities to continuously improve our security posture and resilience.
  • Responsible for supporting the design, development, testing and transition of any new information security services into operations.
  • Provide subject matter expert leadership in major incidents and events caused by or affecting information security.
  • Act as the Problem Owner for information security and business continuity matters (ITIL)
  • Responsible for the Information Security Assessment lifecycle, and Information Risk Management documentation for IT systems and data
  • Responsible for ensuring that access to Trust systems is appropriately managed, regularly audited, and lead investigations as required.
  • Provide expertise on information transfer agreements with partner organisations in support of the Information Governance function.
  • Partner with the Organisational Development and Information Governance teams in the planning, development and delivery of information security awareness and training.

Making and informing risk-based decisions

  • Act as a point of escalation
  • Be trusted by senior risk owners as an expert in information security and business continuity.
  • Apply risk methodologies at the most complex levels of risk.

Policies, procedures, and processes

  • Responsibility for information security and business continuity for data and technology, ensuring that policies and procedures are both effective in terms of protection, but realistic and enabling for the business.
  • Develop, maintain, and improve all directorate information security and business continuity policies & procedures, considering regional and national policies and practices, ensuring that both manual and electronic information across the Trust is included in-scope.

Risk management

  • Responsible for the management of information security and data and technology business continuity risks, including identifying new risks and ensuring we are actively managing risk controls.

Service focus, monitoring, and reporting

  • See the bigger picture and investigate how to get the best out of the underlying services to support the organisations strategic objectives and business priorities.
  • Monitor and enforce information security and business continuity principles, policies, and procedures both on a regular basis, and on-demand (as/when required)
  • Take complex reporting data from multiple sources, compare, and interpret against service baseline and industry standards and provide a supporting narrative.
  • Responsible for service reporting for information security and business continuity, in-line with Trust-agreed reporting measures

Strategy

  • Apply strategy, using and challenging patterns, standards, policies, roadmaps, and vision statements. You can provide guidance.
  • Challenge and lead changes to policy and processes that support business outcomes, with business architecture, legal and political implications.
  • Ensure alignment of operating procedures and policies in-line with national, sector (ICS) and industry best practice where it makes sense to do so.

Understanding the whole context

  • Understand trends and practices outside your team and how these will impact your work.
  • See how your work fits into the broader strategy and historical context.
  • Consider the patterns and interactions on a larger scale.

User focus

  • Explain the difference between user needs and the desires of the user.
  • Champion user research to focus on all users.
  • Prioritise and define approaches to understand the user story, guiding others in doing so.

Community of practice

  • Responsible for research and development activities relating to the highly complex field of information security and business continuity.
  • Develop and maintain a network of professionals to enable continuous learning and a community which can share, learn, and keep up to date on the information security and business continuity landscape, within the wider Digital, Data and Technology teams.

Other Duties:

  • Deputise for other members of the CIO Leadership Team as required.
  • Occasional work may be required outside of core business hours to support major projects / programmes.
  • All other reasonable requests

Person Specification

Education and qualifications

Essential

  • Masters degree, or extensive equivalent experience including people management
  • Relevant management / leadership qualification or equivalent experience to masters level
  • Relevant information security qualification or equivalent experience (example: CISM, CISSP, or plan to obtain within 12 months)
  • Service management qualification or equivalent experience (example: ITIL)

Desirable

  • Delivery management qualification or equivalent experience (Agile, PRINCE2, etc)

Experience

Essential

  • Experience in delivering and developing information security and business continuity services, in highly complex and regulated environments
  • Experience of developing and implementing organisation-wide information security and business continuity related strategies, policies, and procedures
  • Experience of solving complex business problems for users using technology - balancing usability with security
  • Experience of supporting the transition of products from Delivery into Live Service
  • Experience of working with conflicting, highly complex, highly contended, and/or highly sensitive information
  • Experience in managing critical incidents, and problem investigation + resolution (including managing security incident response, and information security breaches)
  • Experience of contributing to, and developing enabling strategies (example: information security)
  • Coaching, mentoring and supervision of others
  • Management of financial budgets for a service (pay, on-call, consumables, relevant 3rd party provision contracts) and developing investment cases

Desirable

  • Experience in conducting or managing information security audits, penetration testing, table-top / simulation exercises, and incident investigations
  • Experience of management products / services in healthcare (NHS)

Skills and knowledge

Essential

  • Deal with complex business problems and translate into information security and business continuity requirements and solutions
  • Strong domain knowledge in at least two of the following areas, and the ability to acquire an adequate understanding of the other areas: oEnterprise Architecture oHMG Secure Policy Framework (SPF) and Information Assurance Maturity Model (IAMM) oISO27001 oRisk assessment and management oData security and protection toolkit (DSPT)
  • Broad knowledge of enterprise technology and data solution(s) and how information security and business continuity should be considered
  • Identify training needs and develop a professional development framework to build and sustain information security and business continuity capability
  • Prioritisation of work - within the team and across the wider Digital, Data and Technology teams
  • Meet set targets or metrics for service
  • Autonomous working and can delegate appropriately
  • Good communication skills - tailoring your message for your audience, providing, and receiving highly complex, sensitive and/or contentious information, able to communicate complex technical information in a simple way to stakeholders
  • Present complex, sensitive, and contentious information to large groups
  • Strong domain knowledge and ability to keep ahead of information security and business continuity initiatives
  • Design and develop our information security and business continuity tools and processes
  • Systematic and methodical approach to problem solving

Personal qualities

Essential

  • Relentless focus on user needs and experience
  • Problem-solving mindset - focusing on improving outcomes
  • Seeing the bigger picture - understand how your work and the work of your team supports wider objectives and meets the diverse needs of stakeholders
  • Able to work well within a busy environment
Person Specification

Education and qualifications

Essential

  • Masters degree, or extensive equivalent experience including people management
  • Relevant management / leadership qualification or equivalent experience to masters level
  • Relevant information security qualification or equivalent experience (example: CISM, CISSP, or plan to obtain within 12 months)
  • Service management qualification or equivalent experience (example: ITIL)

Desirable

  • Delivery management qualification or equivalent experience (Agile, PRINCE2, etc)

Experience

Essential

  • Experience in delivering and developing information security and business continuity services, in highly complex and regulated environments
  • Experience of developing and implementing organisation-wide information security and business continuity related strategies, policies, and procedures
  • Experience of solving complex business problems for users using technology - balancing usability with security
  • Experience of supporting the transition of products from Delivery into Live Service
  • Experience of working with conflicting, highly complex, highly contended, and/or highly sensitive information
  • Experience in managing critical incidents, and problem investigation + resolution (including managing security incident response, and information security breaches)
  • Experience of contributing to, and developing enabling strategies (example: information security)
  • Coaching, mentoring and supervision of others
  • Management of financial budgets for a service (pay, on-call, consumables, relevant 3rd party provision contracts) and developing investment cases

Desirable

  • Experience in conducting or managing information security audits, penetration testing, table-top / simulation exercises, and incident investigations
  • Experience of management products / services in healthcare (NHS)

Skills and knowledge

Essential

  • Deal with complex business problems and translate into information security and business continuity requirements and solutions
  • Strong domain knowledge in at least two of the following areas, and the ability to acquire an adequate understanding of the other areas: oEnterprise Architecture oHMG Secure Policy Framework (SPF) and Information Assurance Maturity Model (IAMM) oISO27001 oRisk assessment and management oData security and protection toolkit (DSPT)
  • Broad knowledge of enterprise technology and data solution(s) and how information security and business continuity should be considered
  • Identify training needs and develop a professional development framework to build and sustain information security and business continuity capability
  • Prioritisation of work - within the team and across the wider Digital, Data and Technology teams
  • Meet set targets or metrics for service
  • Autonomous working and can delegate appropriately
  • Good communication skills - tailoring your message for your audience, providing, and receiving highly complex, sensitive and/or contentious information, able to communicate complex technical information in a simple way to stakeholders
  • Present complex, sensitive, and contentious information to large groups
  • Strong domain knowledge and ability to keep ahead of information security and business continuity initiatives
  • Design and develop our information security and business continuity tools and processes
  • Systematic and methodical approach to problem solving

Personal qualities

Essential

  • Relentless focus on user needs and experience
  • Problem-solving mindset - focusing on improving outcomes
  • Seeing the bigger picture - understand how your work and the work of your team supports wider objectives and meets the diverse needs of stakeholders
  • Able to work well within a busy environment

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Employer details

Employer name

Moorfields Eye Hospital NHS Foundation Trust

Address

Moorfields Eye Hospital NHS Foundation Trust

162 City Road

London

EC1V 2PD


Employer's website

https://www.moorfields.nhs.uk/work-for-us (Opens in a new tab)


Employer details

Employer name

Moorfields Eye Hospital NHS Foundation Trust

Address

Moorfields Eye Hospital NHS Foundation Trust

162 City Road

London

EC1V 2PD


Employer's website

https://www.moorfields.nhs.uk/work-for-us (Opens in a new tab)


For questions about the job, contact:

Recruitment

Sean Hassani

sean.hassani@lafosse.com

Date posted

03 May 2024

Pay scheme

Agenda for change

Band

Band 8c

Salary

£78,163 to £88,884 a year per annum pro rata including HCAS

Contract

Permanent

Working pattern

Full-time, Flexible working

Reference number

273-DS-3314-A

Job locations

Moorfields Eye Hospital NHS Foundation Trust

162 City Road

London

EC1V 2PD


Supporting documents

Privacy notice

Moorfields Eye Hospital NHS Foundation Trust's privacy notice (opens in a new tab)