NHS Jobs • Reading RG1 5UZ
About this role
PRINCIPAL RESPONSIBILITIESSupport the CISO in developing, implementing and monitoring a strategic, comprehensive cyber, enterprise information security, resilience, information governance and IT risk management strategy and plan.Provide expert cyber security advice to senior stakeholders and technical teams across the organisation.Work directly with key stakeholders to facilitate risk assessment and risk management processes. Collaborate with all departments within the Trust (and ICS) where necessary to identify and disseminate high-quality information that facilitates effective cyber and information security management and improvement. Use advanced analytic tools to determine emerging threat patterns and vulnerabilities. Scoping and delivery of penetration tests and ensure actions from vulnerability assessments are resolvedLead on audit and audit preparation relating to IT security Maintaining compliance with various standards in place e.g. Data Security and Protection Toolkit, CareCERT, Cyber Essentials+, Network and Information Systems Regulations etc. Act as the Trusts advisor on cyber security protection, detection, response and recovery.Analyse complex data and oversee the production of detailed informationWork closely with the Emergency Preparedness, Resilience and Response teams to ensure that preparations include events relating to cyber security. Evaluate options and be able to persuade and influence others to ensure that risks in relation to cyber, resilience and information integrity and security are addressed appropriately.isk and benefit. Ensure that all local information and cyber security strategies and activities align with the national Plan. To assist with the development of disaster recovery and business continuity strategies for Trust digital services, wider stakeholders and partner organisations. To perform security reviews, audits and risk assessment All activities will be conducted within the context of professional standards, including, but not limited to, PRINCE II and ITIL.This post requires continual upgrading of skills to reflect rapid changes in technology, the Trusts environment and the needs of the Trust. This is achieved through formal training; informal skills transfer and self-tuition.Business Change and Transformation