Digital Health and Care Wales

Cyber Resilience Principal

The closing date is 09 October 2025

Job summary

An exciting opportunity has arisen to join the NHS Wales Cyber Resilience Unit as a Cyber Resilience Principal. We are looking for someone with a proven background in Information/Cyber security and Audit, a flexible 'can do' attitude and approach to work and the ability to provide advice and assurance that security risk across NHS Wales is being managed appropriately.

The role of the Cyber Resilience Principal is to provide support to the Cyber Resilience Unit to ensure the auditing and reporting structure is of an excellent standard in order to establish the CRU as world-class national service.

The Cyber Resilience Principal will be responsible for ensuring the reporting and auditing process is carried out in a consistent, concise and professional manner, and are developed to ensure compliance with the cyber security legislation such as CSRB, NIS regulations, best practice and Welsh Government requirements.

Who are the CRU?

The NHS Wales Cyber Resilience Unit (CRU), is an independent team hosted by Digital Health and Care Wales (DHCW). It's core purpose is to increase the security and resiliency of information systems across NHS Wales.

The CRU has been delegated responsibility by the Welsh Government to lead the implementation and monitoring of compliance with the Network and Information Systems Regulations (NIS) across the NHS in Wales.

Main duties of the job

As Cyber Resilience Principal, you will act as a specialist in your own area, using your judgement to make decisions and to coach and mentor others in your profession, both within the team and in the wider Community of Practice you will:

Work autonomously,initiating action and reporting to a senior level, assisting and deputising as required.

Lead the development of the CRU auditing and reporting processes based on new and updated regulation.

Lead Cyber Resiliency Unit audits, and support CRU team members in conducting audits, asrequired.

Helpestablish the reputation of the CRU as a world-class national service.

Develop a consistent and concise report template for reporting to NHS Wales organisations and Welsh Government.

Develop dashboards to present reports and KPIs to Management, NHS Walesorganisations and Welsh Government.

Review and quality assess reports produced by CRU before distribution to third parties.

Present reports asrequired to Management, NHS Wales organisations and Welsh Government.

Advise NHS Wales organisations on how to improve their compliance status and security posture based on CAF audit results.

About us

Digital Health and Care Wales (DHCW) is an expert national body and part of NHS Wales. We work in partnership with NHS Wales colleagues and other key stakeholders to provide national digital and data services which support the delivery of health and social care in Wales. Modern health and care services depend on good digital tools, data and information. DHCW runs or works with more than 100 services and delivers major national digital transformation programmes to support this. In addition, DHCW provides expert advice in relation to cyber security and information governance. We give frontline staff the digital tools which help them provide safer and more efficient care. We are also giving patients and the public digital tools to better manage their own health and wellbeing, empowering people to live healthier lives. We put people at the heart of what we do, working to the highest standards to deliver quality and make digital a force for good in health and care.

Working for DHCW offers lots of employee benefits, including flexible working, a competitive salary, 28 days of annual leave plus Bank Holidays and opportunities for career development. We are committed to recognising and celebrating our staff as the most valuable part of our organisation.

Details

Date posted

29 September 2025

Pay scheme

Agenda for change

Band

Band 8a

Salary

£56,514 to £63,623 a year per annum

Contract

Permanent

Working pattern

Full-time, Flexible working

Reference number

025-AC229-0925

Job locations

Hybrid working

Location to be confirmed at interview

CF11 9AD


Job description

Job responsibilities

Work with NHS Wales organisations and Welsh Government to further improve the auditing process and reporting structure.

Assist development of the CRU Auditing process using the Cyber Assessment Framework to provide a consistent, efficient and professional service.

You will be able to find a full Job description and Person Specification attached within the supporting documents, please click "Apply now" to view in Trac.

The ability to speak Welsh is desirable for this post; English and/or Welsh speakers are equally welcome to apply.

Job description

Job responsibilities

Work with NHS Wales organisations and Welsh Government to further improve the auditing process and reporting structure.

Assist development of the CRU Auditing process using the Cyber Assessment Framework to provide a consistent, efficient and professional service.

You will be able to find a full Job description and Person Specification attached within the supporting documents, please click "Apply now" to view in Trac.

The ability to speak Welsh is desirable for this post; English and/or Welsh speakers are equally welcome to apply.

Person Specification

Qualifications and Knowledge

Essential

  • Educated to master's degree level, within Business or IT (or equivalent qualification / experience).
  • Further evidence of relevant higher-level education (postgraduate) and/or training.
  • Excellent understanding and experience of security compliance auditing processes and best practice, using recognised standards such as ISO 27001, NCSC CAF or Cyber Essentials.
  • Excellent knowledge of the NIS and NIS2 Directives (Cyber Security legislation).

Desirable

  • Theoretical and specialist knowledge, gained with relevant certification in security auditing (e.g. ISCA CISA, ISO 27001 Auditor).
  • Recognised qualification in Management or Leadership.

Experience

Essential

  • Practical experience, working at this level, across the range of work procedures and practices.
  • Proficient in managing and motivating successful technical teams.
  • Expert at delivering concise, accurate, high-quality written reports, providing complex and sensitive data, to tight deadlines.

Desirable

  • Proficient in coaching and mentoring staff; specifically agile and multi-disciplinary teams.
  • A clear understanding and appreciation of the processes supporting clinical care and the approaches required to design and implement the supporting IT Security environment.

Skills and Attributes

Essential

  • Commitment to supporting the organisation's mission to encourage and embrace diversity and inclusion across the NHS
  • A flexible approach to work in a hybrid working environment.
  • Travel throughout Wales between sites, as required by the job

Desirable

  • Welsh language skills are desirable, at level 1 or above, in understanding, speaking, reading and writing in Welsh.
  • Knowledge of NHS Wales or the Health sector.
Person Specification

Qualifications and Knowledge

Essential

  • Educated to master's degree level, within Business or IT (or equivalent qualification / experience).
  • Further evidence of relevant higher-level education (postgraduate) and/or training.
  • Excellent understanding and experience of security compliance auditing processes and best practice, using recognised standards such as ISO 27001, NCSC CAF or Cyber Essentials.
  • Excellent knowledge of the NIS and NIS2 Directives (Cyber Security legislation).

Desirable

  • Theoretical and specialist knowledge, gained with relevant certification in security auditing (e.g. ISCA CISA, ISO 27001 Auditor).
  • Recognised qualification in Management or Leadership.

Experience

Essential

  • Practical experience, working at this level, across the range of work procedures and practices.
  • Proficient in managing and motivating successful technical teams.
  • Expert at delivering concise, accurate, high-quality written reports, providing complex and sensitive data, to tight deadlines.

Desirable

  • Proficient in coaching and mentoring staff; specifically agile and multi-disciplinary teams.
  • A clear understanding and appreciation of the processes supporting clinical care and the approaches required to design and implement the supporting IT Security environment.

Skills and Attributes

Essential

  • Commitment to supporting the organisation's mission to encourage and embrace diversity and inclusion across the NHS
  • A flexible approach to work in a hybrid working environment.
  • Travel throughout Wales between sites, as required by the job

Desirable

  • Welsh language skills are desirable, at level 1 or above, in understanding, speaking, reading and writing in Welsh.
  • Knowledge of NHS Wales or the Health sector.

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).

Additional information

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).

Employer details

Employer name

Digital Health and Care Wales

Address

Hybrid working

Location to be confirmed at interview

CF11 9AD


Employer's website

https://nwis.nhs.wales/ (Opens in a new tab)

Employer details

Employer name

Digital Health and Care Wales

Address

Hybrid working

Location to be confirmed at interview

CF11 9AD


Employer's website

https://nwis.nhs.wales/ (Opens in a new tab)

Employer contact details

For questions about the job, contact:

Cyber Security Compliance Lead

Kevin Seward

kevin.j.seward@wales.nhs.uk

Details

Date posted

29 September 2025

Pay scheme

Agenda for change

Band

Band 8a

Salary

£56,514 to £63,623 a year per annum

Contract

Permanent

Working pattern

Full-time, Flexible working

Reference number

025-AC229-0925

Job locations

Hybrid working

Location to be confirmed at interview

CF11 9AD


Supporting documents

Privacy notice

Digital Health and Care Wales's privacy notice (opens in a new tab)