Job summary
NHS England's Cyber Operations team is at the forefront of safeguarding critical national healthcare services and ensuring patient safety through robust cyber resilience. The Cyber Security Lead role is a key part of the Cyber Governance, Risk and Compliance, operating within the Chief Information Security Office (CISO) Function. This team is responsible for providing leadership with accurate information regarding cyber and information security risks in a timely manner, helping to ensure the resiliency of national services and Critical National Infrastructure.
You will play a pivotal role in developing and maintaining an understanding of the security risk exposure across the organisation, working alongside other CISO Functions to maintain a functioning security framework, enabling proactive security risk management.
This role offers unparalleled opportunities to address challenges of national scale, contribute to improving healthcare outcomes, and enhance NHS cyber resilience. As part of a supportive and innovative environment, you will benefit from access to professional development, collaborative initiatives, and impactful work that directly supports patient care.
The post of Security Lead has been awarded a Recruitment and Retention Premia (RRP) in response to current labour market conditions. In recognition of this, the role attracts an additional monthly RRP payment equal to 30% per annum.Please be aware that RRP is non-contractual and subject to review
Main duties of the job
As a Cyber Security Lead, your responsibilities include:
- Deputise for the Head of GRC, leading the GRC team and managing outputs as required.
- Embed and mature an organisational security operating model to support risk-driven, evidence-based decision making.
- Oversee the security policy lifecycle, ensuring policies are harmonised, accessible, and risk-focused.
- Manage and track security risks and issues on behalf of the CISO, working with stakeholders to maintain risk within tolerance.
- Design, implement, and monitor key controls to reduce risk, provide assurance, and meet compliance obligations.
- Provide effective security metrics and reporting to governance boards, senior leaders, and audit functions.
- Conduct research and analysis using diverse data sources to inform security best practices and decisions.
- Promote 'security by design' across directorates, strategies, and business plans.
- Monitor organisational changes and support audits of high-risk activities, assets, and third parties.
- Ensure compliance with statutory, regulatory, and contractual obligations, aligning security activities with business priorities.
- Streamline assessment and audit processes to reduce operational burden.
- Collaborate with product and service teams to identify and remediate compliance gaps and manage associated risks.
About us
The NHS England board have set out the top-level purpose for the new organisation to lead the NHS in England to deliver high-quality services for all, which will inform the detailed design work and we will achieve this purpose by:
- Enabling local systems and providers to improve the health of their people and patients and reduce health inequalities.
- Making the NHS a great place to work, where our people can make a difference and achieve their potential.
- Working collaboratively to ensure our healthcare workforce has the right knowledge, skills, values and behaviours to deliver accessible, compassionate care
- Optimising the use of digital technology, research, and innovation
- Delivering value for money.
If you would like to know more or require further information, please visithttps://www.england.nhs.uk/.
Colleagues with a contractual office base are expected to spend, on average, at least 40% of their time working in-person.
Staff recruited from outside the NHS will usually be appointed at the bottom of the pay band.
NHS England hold a Sponsor Licence; this means that we may be able to sponsor you providing the Home Office requirements are met. To be eligible for sponsorship through the Skilled Worker route you'll usually need to be paid the 'standard' salary rate of at least £38,700 per year, or the 'going rate' for your job, whichever is higher. You can find more information on the Government website.
Job description
Job responsibilities
Please see the attached Job Description and Person Specification for more information about the role and responsibilities. Please ensure your supporting statement includes demonstratable evidence and specific examples on how you meet the criteria for each of the key skills specified. This will be used in both the shortlisting and interview processes
Important: Please be aware there are residency requirements you need to meet:
All NHS England Cyber Security personnel must hold Security Clearance level as a minimum. To meet National Security Vetting requirements, SC clearances require 5 years continuous UK residency. In certain cases, this can be reduced to three years continuous UK residency, with additional overseas checks for the previous two years. Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role - will still be considered.Please make sure you meet these requirements before applying for this role. You dont need to have SC already, however, failure to achieve the requirements for SC after offer will result in the job offer being withdrawn. For further advice please check https://www.gov.uk/government/publications/united-kingdom-security-vetting-clearance-levels/national-security-vetting-clearance-levels#security-check-sc
Please be aware that should you be successful in this position, you will be hired to the job title of Security Lead and this job title is advertised to attract the right skills needed for the role.
Secondments
Applicants from within the NHS will be offered on a secondment basis only, agreement should be obtained from their employer prior to submitting the application.
Please note that the reason for the fixed term of this contract isshort term vacancy
If you like what you have read and think you have the skills and experience, we need then don't delay, apply today! We get lots of applications for our roles and so we sometimes have to close our posts early. Don't miss out!
Job description
Job responsibilities
Please see the attached Job Description and Person Specification for more information about the role and responsibilities. Please ensure your supporting statement includes demonstratable evidence and specific examples on how you meet the criteria for each of the key skills specified. This will be used in both the shortlisting and interview processes
Important: Please be aware there are residency requirements you need to meet:
All NHS England Cyber Security personnel must hold Security Clearance level as a minimum. To meet National Security Vetting requirements, SC clearances require 5 years continuous UK residency. In certain cases, this can be reduced to three years continuous UK residency, with additional overseas checks for the previous two years. Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role - will still be considered.Please make sure you meet these requirements before applying for this role. You dont need to have SC already, however, failure to achieve the requirements for SC after offer will result in the job offer being withdrawn. For further advice please check https://www.gov.uk/government/publications/united-kingdom-security-vetting-clearance-levels/national-security-vetting-clearance-levels#security-check-sc
Please be aware that should you be successful in this position, you will be hired to the job title of Security Lead and this job title is advertised to attract the right skills needed for the role.
Secondments
Applicants from within the NHS will be offered on a secondment basis only, agreement should be obtained from their employer prior to submitting the application.
Please note that the reason for the fixed term of this contract isshort term vacancy
If you like what you have read and think you have the skills and experience, we need then don't delay, apply today! We get lots of applications for our roles and so we sometimes have to close our posts early. Don't miss out!
Person Specification
Knowledge
Essential
- Detailed knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organisational data.
- Detailed knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organisational network operation and minimise negative effect by cybersecurity risks.
Desirable
- Extensive knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply this knowledge appropriately to diverse situations.
- Extensive knowledge of vulnerability assessment tools, techniques, models, and systems; ability to utilise the knowledge to identify vulnerabilities on networks, operating systems, mobile applications, etc
Skills and Experience
Essential
- Specialist knowledge of and the ability to protect information and systems while ensuring confidentiality, integrity and availability.
Desirable
- Specialist knowledge of and the ability to utilise tools and techniques for assessing the effectiveness of information security measures, identifying potential risk exposures, and protecting the availability, confidentiality and audit trails of information from destruction or manipulation.
Qualifications
Essential
- Master's level degree or equivalent level of experience.
Desirable
- Certified Information Systems Security Professional (CISSP) and/or Certified Information Security Manager (CISM)
Person Specification
Knowledge
Essential
- Detailed knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organisational data.
- Detailed knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organisational network operation and minimise negative effect by cybersecurity risks.
Desirable
- Extensive knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply this knowledge appropriately to diverse situations.
- Extensive knowledge of vulnerability assessment tools, techniques, models, and systems; ability to utilise the knowledge to identify vulnerabilities on networks, operating systems, mobile applications, etc
Skills and Experience
Essential
- Specialist knowledge of and the ability to protect information and systems while ensuring confidentiality, integrity and availability.
Desirable
- Specialist knowledge of and the ability to utilise tools and techniques for assessing the effectiveness of information security measures, identifying potential risk exposures, and protecting the availability, confidentiality and audit trails of information from destruction or manipulation.
Qualifications
Essential
- Master's level degree or equivalent level of experience.
Desirable
- Certified Information Systems Security Professional (CISSP) and/or Certified Information Security Manager (CISM)
Disclosure and Barring Service Check
This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.