Job summary
  NHS England's Chief Information Security Office (CISO) Function's purpose is to enable safe care and build public trust by strengthening the cyber resilience of the NHS. The CISO supports the Transformation Directorate's purpose of delivering the best care and outcomes for patients, and enables faster, safer digital transformation of the NHS.
As part of the CISO Function the Senior Cyber Security Advisor sit in the Secure Consulting Team who provide specialist cyber security consultancy services to NHS England's Critical National Infrastructure and major national services, ensuring these services and digital programmes are Secure by Design.
Senior Cyber Security Advisors ensure NHS England's systems operate from a cyber resilient architecture. They provide detailed cyber guidance to programme delivery teams, including architecture, software engineering and infrastructure, supporting the management of cyber risk.
This is an exciting opportunity to help deliver cyber resilient systems for the NHS. You'll be given the support and autonomy to use your skills, knowledge, and experience, to make a real impact on improving people's lives.
The role of Senior Cyber Security Advisors has been awarded a Recruitment and Retention Premia (RRP) in response to current labour market conditions. In recognition of this, the role attracts an additional monthly RRP payment equal to 20% per annum.
Please be aware that RRP is non contractual and subject to review.
  Main duties of the job
  As a Senior Cyber Security Advisor, you will:
   - Conduct security assessments and threat modelling, articulate cyber risk and recommend mitigating controls to ensure systems are designed securely.
- Provide specialist cyber security guidance aligned to NHSE security policy and industry best practice, covering the main technology pillars, including Cloud (hybrid), IAM, software and infrastructure engineering.
- Proactively interact with delivery and service teams to gather information, provide guidance to resolve security issues and make recommendations to technical and non-technical stakeholders.
- Embed security culture within assigned programmes, enabling teams to build systems securely from the ground up.
- Implement project level strategies, defining objectives and addressing technology related controls, risks, and issues.
- Support programmes and projects in the delivery of secure systems.
- Conduct risk assessments within assigned programmes to determine potential impact and recommend mitigation strategies.
This is a critical role ensuring NHS England's security measures are aligned to government and industry standards, and appropriate measures are in place to mitigate against cyber security risks.The security landscape is constantly evolving, and this is your opportunity to think creatively and contribute to improving the security resilience of NHS Services across England. It's a great time to join NHS England and be part of the journey.
  About us
  Our work supports the NHS to deliver high quality services for patients and best value for taxpayers.
Our staff bring expertise across hundreds of specialisms -- including clinical, operational, commissioning, technology, data science, cyber security, software engineering, education, and commercial -- enabling us to design and deliver high-quality NHS services.
We lead the NHS in England by:
- Enabling local systems and providers to improve the health of their people and patients and reduce health inequalities
- Making the NHS a great place to work, where our people can make a difference and achieve their potential
- Working collaboratively to ensure our healthcare workforce has the right knowledge, skills, values and behaviours to deliver accessible, compassionate care
- Optimising the use of digital technology, research, and innovation
- Delivering value for money
Earlier this year, the Government announced that NHS England will gradually merge with the Department of Health and Social Care, leading to full integration. The aim is to create a smaller, more strategic centre that reduces duplication and eliminates waste.
If successful at interview, we will initiate an Inter Authority Transfer (IAT) via the Electronic Staff Record (ESR). This retrieves key data from your current or previous NHS employer to support onboarding, including competency status, Continuous Service Dates (CSD), and annual leave entitlement. You may opt out at any stage of the recruitment process.
.
      
      
  
    Job description
    Job responsibilities
    Please see the attached Job Description and Person Specification for more information about the role and responsibilities. Please ensure your supporting statement includes demonstratable evidence and specific examples on how you meet the criteria for each of the key skills specified. This will be used in both the shortlisting and interview processes
 Important: Please be aware there are residency requirements you need to meet:
 All NHS England Cyber Security personnel must hold Security Clearance level as a minimum. To meet National Security Vetting requirements, SC clearances require 5 years continuous UK residency. In certain cases, this can be reduced to three years continuous UK residency, with additional overseas checks for the previous two years. Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role - will still be considered.Please make sure you meet these requirements before applying for this role. You dont need to have SC already, however, failure to achieve the requirements for SC after offer will result in the job offer being withdrawn. For further advice please check https://www.gov.uk/government/publications/united-kingdom-security-vetting-clearance-levels/national-security-vetting-clearance-levels#security-check-sc
 Please be aware that should you be successful in this position, you will be hired to the job title of Senior Security Advisor and this job title is advertised to attract the right skills needed for the role.
 Applicants from within the NHS will be offered on a secondment basis only, agreement should be obtained from their employer prior to submitting the application.
 Please note that the reason for the fixed term of this contract is short term vacancy.
 If you like what you have read and think you have the skills and experience, we need then don't delay, apply today! We get lots of applications for our roles and so we sometimes have to close our posts early. Don't miss out!
  Secondments   
Applicants from within the NHS will be offered on a secondment basis only, agreement should be obtained from their employer prior to submitting the application.
   
  
    
      
        Job description
      
    
    
      Job responsibilities
      Please see the attached Job Description and Person Specification for more information about the role and responsibilities. Please ensure your supporting statement includes demonstratable evidence and specific examples on how you meet the criteria for each of the key skills specified. This will be used in both the shortlisting and interview processes
 Important: Please be aware there are residency requirements you need to meet:
 All NHS England Cyber Security personnel must hold Security Clearance level as a minimum. To meet National Security Vetting requirements, SC clearances require 5 years continuous UK residency. In certain cases, this can be reduced to three years continuous UK residency, with additional overseas checks for the previous two years. Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role - will still be considered.Please make sure you meet these requirements before applying for this role. You dont need to have SC already, however, failure to achieve the requirements for SC after offer will result in the job offer being withdrawn. For further advice please check https://www.gov.uk/government/publications/united-kingdom-security-vetting-clearance-levels/national-security-vetting-clearance-levels#security-check-sc
 Please be aware that should you be successful in this position, you will be hired to the job title of Senior Security Advisor and this job title is advertised to attract the right skills needed for the role.
 Applicants from within the NHS will be offered on a secondment basis only, agreement should be obtained from their employer prior to submitting the application.
 Please note that the reason for the fixed term of this contract is short term vacancy.
 If you like what you have read and think you have the skills and experience, we need then don't delay, apply today! We get lots of applications for our roles and so we sometimes have to close our posts early. Don't miss out!
  Secondments   
Applicants from within the NHS will be offered on a secondment basis only, agreement should be obtained from their employer prior to submitting the application.
     
   
      
  
    Person Specification
    
    
      
        
          Knowledge
        
      
      
      Essential
      
        
        - Working knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organisational network operation and minimise negative effect by cybersecurity risks
- Extensive knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply this knowledge appropriately to diverse situations.
- Demonstrable knowledge of the tools and techniques used for securing cloud and infrastructure environments in complex hybrid environments using Azure and AWS.
        
          Skills and Experience
        
      
      
      Essential
      
        
        - Proven knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organisational data.
- Proven knowledge of techniques, approaches, and processes of digital threats; ability to detect, monitor, analyse and prevent digital threats.
        
          Qualifications
        
      
      
      Essential
      
        
        - Certified Information Systems Security Professional (CISSP) - or equivalent knowledge
 
  
    
      
        Person Specification
      
    
    
      
      
        
          
            Knowledge
          
        
        
        Essential
        
          
          - Working knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organisational network operation and minimise negative effect by cybersecurity risks
- Extensive knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply this knowledge appropriately to diverse situations.
- Demonstrable knowledge of the tools and techniques used for securing cloud and infrastructure environments in complex hybrid environments using Azure and AWS.
          
            Skills and Experience
          
        
        
        Essential
        
          
          - Proven knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organisational data.
- Proven knowledge of techniques, approaches, and processes of digital threats; ability to detect, monitor, analyse and prevent digital threats.
          
            Qualifications
          
        
        
        Essential
        
          
          - Certified Information Systems Security Professional (CISSP) - or equivalent knowledge
 
   
      
  
    Disclosure and Barring Service Check
    This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.