
Senior Cyber Security Advisor
- Leeds Exeter
- £66,828-75,218 per year
- Contract
- Full-time
- Conduct security assessments and threat modelling, articulate cyber risk and recommend mitigating controls to ensure systems are designed securely.
- Provide specialist cyber security guidance aligned to NHSE security policy and industry best practice, covering the main technology pillars, including Cloud (hybrid), IAM, software and infrastructure engineering.
- Proactively interact with delivery and service teams to gather information, provide guidance to resolve security issues and make recommendations to technical and non-technical stakeholders.
- Embed security culture within assigned programmes, enabling teams to build systems securely from the ground up.
- Implement project level strategies, defining objectives and addressing technology related controls, risks, and issues.
- Support programmes and projects in the delivery of secure systems.
- Conduct risk assessments within assigned programmes to determine potential impact and recommend mitigation strategies.
- Enabling local systems and providers to improve the health of their people and patients and reduce health inequalities.
- Making the NHS a great place to work, where our people can make a difference and achieve their potential.
- Working collaboratively to ensure our healthcare workforce has the right knowledge, skills, values and behaviours to deliver accessible, compassionate care
- Optimising the use of digital technology, research, and innovation
- Delivering value for money.
- Working knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organisational network operation and minimise negative effect by cybersecurity risks
- Extensive knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply this knowledge appropriately to diverse situations.
- Demonstrable knowledge of the tools and techniques used for securing cloud and infrastructure environments in complex hybrid environments using Azure and AWS.
- Proven knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organisational data.
- Proven knowledge of techniques, approaches, and processes of digital threats; ability to detect, monitor, analyse and prevent digital threats.
- Certified Information Systems Security Professional (CISSP) - or equivalent knowledge
- Working knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organisational network operation and minimise negative effect by cybersecurity risks
- Extensive knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply this knowledge appropriately to diverse situations.
- Demonstrable knowledge of the tools and techniques used for securing cloud and infrastructure environments in complex hybrid environments using Azure and AWS.
- Proven knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organisational data.
- Proven knowledge of techniques, approaches, and processes of digital threats; ability to detect, monitor, analyse and prevent digital threats.
- Certified Information Systems Security Professional (CISSP) - or equivalent knowledge