Job summary
Are you a security operations professional with a passion for developing positive relationships, programme delivery and leadership? If so, NHS Business Services Authority have the perfect opportunity for you to take the next step in your career! We are looking for a Security Operations Team Manager to join our community of Digital, Data and Technology professionals to support the development and operation of systems which currently support over 7800 internal and external users.
You will engage with stakeholders to facilitate collaborative, professional and customer centric approaches to the delivery of an array of change initiatives, projects, and programmes of work. In addition, you will lead and manage the ICT Security Operations team to develop and support a range of products and services, ultimately playing a key role in NHSBSA's journey to become a multi-sourcing digital business.
You will be based in our Newcastle office with the opportunity to work largely remotely in an organisation with real social value.
What do we offer?
- 27 days leave (increasing with length of service) plus 8 bank holidays
- Flexible working (we are happy to discuss options such as compressed hours)
- Flexi time
- Hybrid working model
- Career development
- Active wellbeing and inclusion networks
- Excellent pension(20.6% employer contribution)
- NHS Car lease scheme
- Access to a wide range of benefits and high street discounts!
Main duties of the job
- Lead and manage a Security Operations function including the selection, design, justification, implementation and operation of information security controls, management strategies and standards and line management of staff within multi-disciplinary teams.
- Functional management of activities including vulnerability management, security incident and event management. Maintenance of threat monitoring alarms/indicators to mitigate threats.
- Keeping abreast of technological and maintain an excellent understanding of the use of technology in delivering business objectives.
- Establishes and maintains communication with individuals and groups about difficult or highly complex matters overcoming any problems in communication. Communicates effectively at all levels to both technical and non-technical audiences, verbally and in writing taking account of confidentiality and sensitivity constraints where appropriate.
- Handles sensitive commercial & financial information, ensuring that the ICT solution architectural designs adhere to relevant legislation and standards including for example, Information Security, NHS Confidentiality and Data Protection legislation.
- Drives the strategic direction of the ICT security operation function by the development, maintenance, promotion and stewardship of ICT Security Procedures and Standards, in accordance with the NHS BSA's requirements, IG policies and procedures, legislation and EU Directives.
About us
At the NHS Business Services Authority (NHSBSA) we deliver a range of essential national services to NHS organisations and contractors, patients and the public.
You may already be using some of our services. Do you have a prescription pre-payment certificate? Perhaps you found this vacancy through NHS Jobs? We're behind these, and much more.
Being one of the UK's Best Big Companies to work for, our values are to be Collaborative, Adventurous, Reliable and Energetic. We CARE about what we do and support each other in achieving our objectives.
Our people are the heart of our organisation. We strive to ensure they feel trusted, valued and empowered. We're passionate about nurturing and developing people. When you join us, we want you to grow, and we offer many opportunities for you to do that.
We welcome applications from people of all backgrounds. With wellbeing and inclusion central to our ethos, our BAME, Disability and Neurodiversity, LGBTQ+, Armed Forces and Women's networks help our colleagues to be their authentic selves at work.
At the NHSBSA we value and respect the diversity of our colleagues and are committed to being a flexible employer. We are proud to offer flexible working opportunities. Whether you're interested in hybrid working, working from home, flexible hours or job sharing, apply today and we can discuss available options with you at the interview stage.
We are the NHS delivering for the NHS.
Job description
Job responsibilities
In this role, you are accountable for:
Specialist Skills
- Lead and Manage a Security operations function including the selection, design, justification, implementation and operation of information security controls, management strategies and standards.
- Functional management of the Organisations Security operations centre activities including vulnerability management, security incident and event management. Maintenance of threat monitoring alarms/indicators to mitigate threats.
- Monitor the development of new and emerging tools, technologies and products to assess potential value and identifying opportunities to enhance capabilities, products and services within the organisation.
- Drive new ideas to improve on all services within the team by way of technology or procedural improvements, which has an impact on other teams/directorates across the organisation
- Responsible for the research and development of technical products and services with potential for offering service improvement and, where appropriate, the evaluation and justification of costs and benefits to customers
- Promotes and assists Information Governance in the establishment and implementation of procedures to enhance and maintain the NHS BSAs Information Security Management System and attain compliance with ISO27001, ISO20000 and other relevant ICT standards.
- Manage the ICT security incident process, reviewing security incidents, weaknesses and malfunctions relating to the NHS BSAs systems, taking appropriate remedial action
- Actively monitor and undertake activities that mitigate threats to the integrity of the NHS BSAs Information Assets. Assesses the effectiveness of firewalls, Gateways, IDS (Intrusion Detection Systems) and IPS (Intrusion Prevention Systems) to improve network/system resilience
Staff Management
- Line management of staff within multi-disciplinary teams operating within the NHS BSA discipline, absence and work performance policies, management information and resource requests to inform forward planning and resource management, whilst completing own assigned tasks to a high quality and within agreed timelines.
- Enabling the performance of others, including objectives setting fully aligned to departmental and organisational objectives and goals, and the development and motivation of staff to achieve them.
- Conducting meaningful appraisals and 1-1s, identifying and meeting development needs, implementing, monitoring, evaluating and reporting on the impact and success of implemented training plans
- Undertake recruitment and selection in line with organisational processes and participate in the implementation and delivery of initiatives to secure suitable resources, increase skills levels and develop talent pools to meet the changing needs of the business landscape.
Financial Management
- Responsibility for budget management processes in accordance with NHS BSAs policies, standing orders, financial regulations, and legislative requirements.
- Managing and monitoring budget spend, including resource estimates against projects and change initiatives, ongoing management of product licenses, ensuring sufficient coverage whilst controlling costs
- Contribute to and prepare proposals for change including producing necessary estimates, mandates, and business cases within the technology department.
Knowledge Management
- Keeping abreast of technological and maintain an excellent understanding of the use of technology in delivering business objectives.
- Identify and support opportunities for the team to further develop their skills to meet the changing needs of the business Taking ownership for decision making within own area, seeking support and feedback to develop well thought out solutions, processes and work as required, and in conjunction with agreed procedures.
- Maintain own knowledge and expertise at the forefront of sector knowledge. Investigate research and development to support future business needs. Develop an understanding of emerging technologies and business opportunities
Relationship Management
- Establishes and maintains communication with individuals and groups about difficult or highly complex matters overcoming any problems in communication. Communicates effectively at all levels to both technical and non-technical audiences, verbally and in writing taking account of confidentiality and sensitivity constraints where appropriate. Ensures good and effective communication channels are in place with all internal and external stakeholders.
- Required to build working relationships, maintain communication and resolve complex issues with external suppliers and business leads relating to service delivery to ensure Incidents, Problems and Change Requests are resolved. Work is delivered against agreed quality criteria and monitor to ensure within agreed budget & timescales.
- Brings together technical specialists from different teams across in-house delivery and 3rd party suppliers to ensure joined up approach to both operational service delivery and to roadmap and improvement planning with the technical knowledge to convene and lead both service improvement and innovation workshops and major problem management activities.
- Work with organisations external to the NHSBSA (e.g. the DHSC and Track and Trace when necessary to assist in clarifying their needs and requirements and be capable of devising options for ICT security solutions, along with full assessment and cost estimation.
Information Management
- Handles sensitive commercial & financial information, ensuring that the ICT solution architectural designs adhere to relevant legislation and standards including for example, Information Security, NHS Confidentiality and Data Protection legislation.
- Implement, monitor and report on a number of areas including agreed service levels, KPI's and standards within team, reviewing individual and team performances including outputs from appraisals, development needs, and trends are identified, and anomalies understood and reports generated and delivered to agreed frequency, methods and processes.
- Monitoring, reviewing accuracy and authorising a number of activities including financial claims leave requests and timesheet submissions at both team and individual level to both assure accuracy and to inform forward planning and resource management.
Delivery Management
- Drives the strategic direction of the ICT security operation function by the development, maintenance, promotion and stewardship of ICT Security Procedures and Standards, in accordance with the NHS BSAs requirements, IG policies and procedures, legislation and EU Directives.
- Managing staff workload and completing own assigned tasks, to a high quality and within agreed timelines. Delivering continuous improvements to enhance own and business areas; co-ordinating and delivery of work across multiple strands such as continuous improvement, project related work, and operational tasks, and escalating issues at appropriate times.
- Preparing plans to enable the delivery and management of projects and programmes undertaken by the team. Providing operational direction in the preparation of plans to deliver systems and service across the organisation.
- Manage and implement approaches strategies, standards, practices and policies across the team, ensuring and monitoring the timely delivery of business objectives within budget through the management of projects and programmes.
- Providing feedback on functional and non-functional requirements to ensure the overall needs of the business are met from an ICT perspective
- Participating in procurement processes for hardware and software. Reviewing functional requirements and providing non-functional requirements to ensure the overall needs of the business are met from an ICT perspective.
Job description
Job responsibilities
In this role, you are accountable for:
Specialist Skills
- Lead and Manage a Security operations function including the selection, design, justification, implementation and operation of information security controls, management strategies and standards.
- Functional management of the Organisations Security operations centre activities including vulnerability management, security incident and event management. Maintenance of threat monitoring alarms/indicators to mitigate threats.
- Monitor the development of new and emerging tools, technologies and products to assess potential value and identifying opportunities to enhance capabilities, products and services within the organisation.
- Drive new ideas to improve on all services within the team by way of technology or procedural improvements, which has an impact on other teams/directorates across the organisation
- Responsible for the research and development of technical products and services with potential for offering service improvement and, where appropriate, the evaluation and justification of costs and benefits to customers
- Promotes and assists Information Governance in the establishment and implementation of procedures to enhance and maintain the NHS BSAs Information Security Management System and attain compliance with ISO27001, ISO20000 and other relevant ICT standards.
- Manage the ICT security incident process, reviewing security incidents, weaknesses and malfunctions relating to the NHS BSAs systems, taking appropriate remedial action
- Actively monitor and undertake activities that mitigate threats to the integrity of the NHS BSAs Information Assets. Assesses the effectiveness of firewalls, Gateways, IDS (Intrusion Detection Systems) and IPS (Intrusion Prevention Systems) to improve network/system resilience
Staff Management
- Line management of staff within multi-disciplinary teams operating within the NHS BSA discipline, absence and work performance policies, management information and resource requests to inform forward planning and resource management, whilst completing own assigned tasks to a high quality and within agreed timelines.
- Enabling the performance of others, including objectives setting fully aligned to departmental and organisational objectives and goals, and the development and motivation of staff to achieve them.
- Conducting meaningful appraisals and 1-1s, identifying and meeting development needs, implementing, monitoring, evaluating and reporting on the impact and success of implemented training plans
- Undertake recruitment and selection in line with organisational processes and participate in the implementation and delivery of initiatives to secure suitable resources, increase skills levels and develop talent pools to meet the changing needs of the business landscape.
Financial Management
- Responsibility for budget management processes in accordance with NHS BSAs policies, standing orders, financial regulations, and legislative requirements.
- Managing and monitoring budget spend, including resource estimates against projects and change initiatives, ongoing management of product licenses, ensuring sufficient coverage whilst controlling costs
- Contribute to and prepare proposals for change including producing necessary estimates, mandates, and business cases within the technology department.
Knowledge Management
- Keeping abreast of technological and maintain an excellent understanding of the use of technology in delivering business objectives.
- Identify and support opportunities for the team to further develop their skills to meet the changing needs of the business Taking ownership for decision making within own area, seeking support and feedback to develop well thought out solutions, processes and work as required, and in conjunction with agreed procedures.
- Maintain own knowledge and expertise at the forefront of sector knowledge. Investigate research and development to support future business needs. Develop an understanding of emerging technologies and business opportunities
Relationship Management
- Establishes and maintains communication with individuals and groups about difficult or highly complex matters overcoming any problems in communication. Communicates effectively at all levels to both technical and non-technical audiences, verbally and in writing taking account of confidentiality and sensitivity constraints where appropriate. Ensures good and effective communication channels are in place with all internal and external stakeholders.
- Required to build working relationships, maintain communication and resolve complex issues with external suppliers and business leads relating to service delivery to ensure Incidents, Problems and Change Requests are resolved. Work is delivered against agreed quality criteria and monitor to ensure within agreed budget & timescales.
- Brings together technical specialists from different teams across in-house delivery and 3rd party suppliers to ensure joined up approach to both operational service delivery and to roadmap and improvement planning with the technical knowledge to convene and lead both service improvement and innovation workshops and major problem management activities.
- Work with organisations external to the NHSBSA (e.g. the DHSC and Track and Trace when necessary to assist in clarifying their needs and requirements and be capable of devising options for ICT security solutions, along with full assessment and cost estimation.
Information Management
- Handles sensitive commercial & financial information, ensuring that the ICT solution architectural designs adhere to relevant legislation and standards including for example, Information Security, NHS Confidentiality and Data Protection legislation.
- Implement, monitor and report on a number of areas including agreed service levels, KPI's and standards within team, reviewing individual and team performances including outputs from appraisals, development needs, and trends are identified, and anomalies understood and reports generated and delivered to agreed frequency, methods and processes.
- Monitoring, reviewing accuracy and authorising a number of activities including financial claims leave requests and timesheet submissions at both team and individual level to both assure accuracy and to inform forward planning and resource management.
Delivery Management
- Drives the strategic direction of the ICT security operation function by the development, maintenance, promotion and stewardship of ICT Security Procedures and Standards, in accordance with the NHS BSAs requirements, IG policies and procedures, legislation and EU Directives.
- Managing staff workload and completing own assigned tasks, to a high quality and within agreed timelines. Delivering continuous improvements to enhance own and business areas; co-ordinating and delivery of work across multiple strands such as continuous improvement, project related work, and operational tasks, and escalating issues at appropriate times.
- Preparing plans to enable the delivery and management of projects and programmes undertaken by the team. Providing operational direction in the preparation of plans to deliver systems and service across the organisation.
- Manage and implement approaches strategies, standards, practices and policies across the team, ensuring and monitoring the timely delivery of business objectives within budget through the management of projects and programmes.
- Providing feedback on functional and non-functional requirements to ensure the overall needs of the business are met from an ICT perspective
- Participating in procurement processes for hardware and software. Reviewing functional requirements and providing non-functional requirements to ensure the overall needs of the business are met from an ICT perspective.
Person Specification
Qualifications
Essential
- Degree caliber with relevant in-depth knowledge of the subject matter and
- A Professional Certification or qualification in Information Security (CISA, CISMP, CISM, CISSP, CRISC) or other relevant professional IT security qualification.
Desirable
- Master's Degree or equivalent Post Graduate qualification
- IT Security Officer at CCP practitioner or Senior Practitioner Level: With the capability to enable effective IT security across a wide portfolio of ICT
- ITIL foundation
- Project Management Foundation (Prince 2)
Personal Qualities, Knowledge and Skills
Essential
- Developing, implementing and maintaining effective control monitoring activities, ensuring compliance with Information Security Standards ISO27001
- Extensive experience of managing security technologies including; firewalls, anti-malware, IDS/IPS, web filtering, email filtering, SIEM, patch management, MDM, DLP
- Designing and recommending appropriate controls to enable the achievement of ICT security and wider business goals. oBusiness change, rationalisation and transformation
- Evaluation of threat intelligence data from multiple sources to inform decision making
- A range of skills and specialism across a diverse and detailed technical knowledge, covering web technology applications and services, information, infrastructure, cloud and managed service architectures.
- Planning and organisational skills across a broad range of activities to support the delivery of project planning and resource management.
- Communicating and negotiating with internal and external bodies, suppliers and organisations to reach satisfactory outcomes for the organisation.
Desirable
- Has a real interest in information security and ensures they keep up-to-date with the latest Security news - such as monitoring GovCertUK, CiSP, CareCERT and vendors as appropriate.
Experience
Essential
- Proven team leader and motivator with a demonstrable track record of the Management and development of security operation teams
- Leading and managing staff to deliver organisational goals and objectives
- Engaging and building relationships with a range of stakeholders to support delivery of business outcomes
- Experience of working within a variety of IT support environments.
- Leading businesses ICT security activities
- The production of ICT security reports/MI for relevant parties
- Experience in security due diligence and security assurance reviews of 3rd party suppliers.
- Working within a combination of outsourced and in house ICT provision.
- Hands on experience with the design of ICT security mitigation measures to meet Information Security work-based assessments
Desirable
- Cloud Security & monitoring
- Development of a security architecture design
Person Specification
Qualifications
Essential
- Degree caliber with relevant in-depth knowledge of the subject matter and
- A Professional Certification or qualification in Information Security (CISA, CISMP, CISM, CISSP, CRISC) or other relevant professional IT security qualification.
Desirable
- Master's Degree or equivalent Post Graduate qualification
- IT Security Officer at CCP practitioner or Senior Practitioner Level: With the capability to enable effective IT security across a wide portfolio of ICT
- ITIL foundation
- Project Management Foundation (Prince 2)
Personal Qualities, Knowledge and Skills
Essential
- Developing, implementing and maintaining effective control monitoring activities, ensuring compliance with Information Security Standards ISO27001
- Extensive experience of managing security technologies including; firewalls, anti-malware, IDS/IPS, web filtering, email filtering, SIEM, patch management, MDM, DLP
- Designing and recommending appropriate controls to enable the achievement of ICT security and wider business goals. oBusiness change, rationalisation and transformation
- Evaluation of threat intelligence data from multiple sources to inform decision making
- A range of skills and specialism across a diverse and detailed technical knowledge, covering web technology applications and services, information, infrastructure, cloud and managed service architectures.
- Planning and organisational skills across a broad range of activities to support the delivery of project planning and resource management.
- Communicating and negotiating with internal and external bodies, suppliers and organisations to reach satisfactory outcomes for the organisation.
Desirable
- Has a real interest in information security and ensures they keep up-to-date with the latest Security news - such as monitoring GovCertUK, CiSP, CareCERT and vendors as appropriate.
Experience
Essential
- Proven team leader and motivator with a demonstrable track record of the Management and development of security operation teams
- Leading and managing staff to deliver organisational goals and objectives
- Engaging and building relationships with a range of stakeholders to support delivery of business outcomes
- Experience of working within a variety of IT support environments.
- Leading businesses ICT security activities
- The production of ICT security reports/MI for relevant parties
- Experience in security due diligence and security assurance reviews of 3rd party suppliers.
- Working within a combination of outsourced and in house ICT provision.
- Hands on experience with the design of ICT security mitigation measures to meet Information Security work-based assessments
Desirable
- Cloud Security & monitoring
- Development of a security architecture design
Additional information
Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).
From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).