Cyber Security Manager

Alder Hey Children’s NHS Foundation Trust

  • Location: Liverpool
  • Salary: £50,952 – £57,349 Per Annum

Alder Hey Children’s NHS Foundation Trust is a provider of specialist health care to over 275,000 children and young people each year.  Alder Hey has a presence in community outreach sites and, in collaboration with other providers, our clinicians help deliver care closer to patients’ homes by holding local clinics at locations from Cumbria to Shropshire, in Wales and the Isle of Man. The Trust also provides inpatient care for children with complex mental health needs at our Sunflower House building newly relocated, and opened on the hospital site.

We currently have more than 4,000 staff working across our community and hospital sites. We’re also a teaching and training hospital providing education and training to around 540 medical and over 500 nursing and allied health professional students each year.

As black and minority ethnic (BME) employees are currently under-represented in this area, we particularly welcome applications from members of our BME communities. All appointments will be made on merit.

You can expect a warm welcome at Alder Hey Childrens NHS Foundation Trust, our staff are friendly and welcoming. We listen to each other and work together to embed our Trusts values and behaviours. At Alder Hey we appreciate our staff and reward them with an outstanding benefits package including:

  • Great flexible working opportunities
  • Lease car scheme and Home Electronics Scheme
  • Generous annual leave and pension scheme
  • Extensive staff health and well-being programmes

Job overview

We have an exciting opportunity for an experienced cyber security specialist to join our team as our Cyber Security Manager to lead on Cyber Security over two NHS Foundation Trust’s:

  • Alder Hey Children’s Hospital
  • Liverpool Heart and Chest Hospital. 

The Cyber Security Manager role will act as our expert on cyber security protection, detection, response, and recovery. The Cyber Security Manager will be responsible for the strategic approach to cyber threat management and will lead the strategic planning of current and future IT security solutions, researching and reviewing industry best practice and upcoming changes to technology and provide assurance against the security architecture of new and existing systems.

The role form part of the wider leadership across the iDigital division, enabling successful cross-function partnerships in relation to ensuring cyber security best practice.

If you’d like to discuss the role further please get in touch!

Main duties of the job

As a natural collaborator and the senior subject matter expert for cyber security, you will define and lead the planning and implementation of cyber security initiatives and policies across the digital estate. You will be overseeing and delivering the Cyber Improvement Plan and align with the organisational strategies and Digital Strategies respectively for each Trust. Working with cyber security, technical IT engineers and information governance professionals, you will support their work to implement secure by design from discovery to production. 

Knowledgeable  around the requirements relating to protecting critical infrastructure, regulatory compliance within the NHS and knowledge of GDPR/NIS2 requirements. An understanding of the CAF (Cyber Assessment Framework) would be an advantage as you will be leading on ensuring we have governance, processes and technology in place to meet CAF objectives and outcomes. 

The Cyber Security Manager will be key in the completion of the Data Security Assessment Toolkit, owning our journey to achieving Cyber Essentials Plus certification and maintaining it along with other cyber compliance and assurance requirements. The role will include working collaboratively with cyber leads across the Cheshire and Merseyside ICS as we work collectively towards defending as one as outlined in the the national Cyber security strategy for health and social care.

Working for our organisation

Alder Hey Children’s NHS Foundation Trust is a provider of specialist health care to over 275,000 children and young people each year.  Alder Hey has a presence in community outreach sites and, in collaboration with other providers, our clinicians help deliver care closer to patients’ homes by holding local clinics at locations from Cumbria to Shropshire, in Wales and the Isle of Man. The Trust also provides inpatient care for children with complex mental health needs at our Sunflower House building newly relocated, and opened on the hospital site.

We currently have more than 4,000 staff working across our community and hospital sites. We’re also a teaching and training hospital providing education and training to around 540 medical and over 500 nursing and allied health professional students each year.

As black and minority ethnic (BME) employees are currently under-represented in this area, we particularly welcome applications from members of our BME communities. All appointments will be made on merit.

You can expect a warm welcome at Alder Hey Childrens NHS Foundation Trust, our staff are friendly and welcoming. We listen to each other and work together to embed our Trusts values and behaviours. At Alder Hey we appreciate our staff and reward them with an outstanding benefits package including:

  • Great flexible working opportunities
  • Lease car scheme and Home Electronics Scheme
  • Generous annual leave and pension scheme
  • Extensive staff health and well-being programmes

Detailed job description and main responsibilities

To lead on Cyber Security for Alder Hey, working closely with MIAA and peers within Cheshire and Merseyside.

Develop Cyber Security policies and processes providing a significant level of assurance.

To be responsible for the leadership and effective management of the information security management for Alder Hey, ensuring the protection of all data held within the organisation

The post holder will ensure that processes related to the implementation and support for IT security is carried out in accordance with industry and NHS best practice.

The post holder will ensure the processes are documented and they are managed in order to effectively deliver the performance required within an IT security setting.

Main areas of responsibility

  • Support Information Governance and Data protection functions for the Trust to achieve the highest standards of information security, emphasising data protection issues.
  • Manage the Trust’s Electronic Information Asset Register to include auditing of all information systems, providing a significant level of assurance.
  • Maintain, improve and disseminate knowledge of Data Protection relating to Information Security issues throughout the Trust.
  • Provide evidence for the achievement of Information Governance Toolkit standards in relation to Data Protection, Confidentiality, Information Security and NCSC which informs the ‘Standards for Better Health’
  • Responsible for the ongoing management of security alerts and vulnerabilities in line with NHS CareCert toolkit and NHS Digital good practice guidelines
  • To have an in-depth understanding, and adhere to all IM&T and Trust polices.
  • To ensure robust systems are in place for monitoring data protection and information security incidents.
  • To take a lead on Cyber Security and represent the Trust in Cheshire and Merseyside leadership forums
  • Provide expert advice to the Trust on Cyber security.
  • Act as the subject matter expert in all matters relating to Information Security for Alder Hey, working with departmental representatives to achieve and maintain the Information Security Framework.
  • Conduct Information Security risk assessments on sometimes highly intricate business decisions and systems.
  • The post holder will have a broad understanding of IM&T technologies and specialist knowledge in a number of key technologies such as firewalls, email filters, anti-virus and intrusion detection
  • To develop information security plans that will feed into the wider Trust and IM&T strategies.
  • Responsible for the formulation and development of information security plans and strategies to enable the successful completion and implementation of new systems.
  • Design, and maintain Alder Hey Information Security Framework, Policies, Procedures and Standards based upon the requirements of the law, DSPT Toolkit, NHS and industry best practice (e.g. ISO/IEC 27000 series standards.).
  • Perform full audits on all new information systems prior to installation. Research and recommend alternative technical solutions where risks are present.
  • Develop information security strategies, roadmaps, business cases and remediation plans.
  • As technology develops the post holder will need to regularly investigate developments assessing them for any potential security risks.
  • Create and maintain specialist Cyber Security Awareness training for use by the Trust.
  • Undertake Privacy Impact Assessment (PIA) process to assess the privacy and data protection impact of new projects and/or third party services.
  • Co-ordinate the necessary response and resolution activities following a suspected or actual security incident or breach. Keeping the information risk lead (SIRO) and information asset owners (IAO’s) informed of security incidents, impacts and causes, resulting actions and learning outcomes.
  • Ensure that all work undertaken for Alder Hey, in-house or by Third Parties, adheres to the established Security standards.
  • Provide regular assurance reports to the Senior Information Risk Owner and Information Governance lead on all information security matters as part of evidence for the IG Toolkit.
  • Investigate information security incidents, where required, or provide subject matter expertise on Information security incidents investigations.
  • Co-ordinate and manage the implementation of security controls to a sufficient quality required to achieve compliance with relevant information security standards (e.g. DSPT Toolkit, ISO 27001 / 2002) as well as wider industry best practice.
  • Manage and commission annual penetration tests for the Trust Providing management responses for testing reports.
  • Design, develop and maintain Business Continuity plans and carryout desktop exercises to prove the efficiency and accuracy of the plan.
  • Test and provide assurance reports on disaster recovery plans for the IT infrastructure.
  • Provide assistance in developing responses to Freedom of Information requests.
  • To develop Information Governance / DSPT Toolkit Action plans for the Trust. This involves the assessment of Trust systems, processes and policies against the toolkit standards, and liaison with staff.
  • To ensure Information Governance /DSPT toolkits are populated with supporting evidence in order to demonstrate agreed achievement of specific standards.
  • Provide assessment of information processes to maintain the Trusts annual Data Protection
  • To ensure that all information security incidents are recorded, and where necessary; to liaise with the Risk Manager and IG Manager within the Trust.
  • Investigate IT security incidents as required, this may involve audit trails, manually checking individual accounts, interviews, producing system reports regarding activity. Formally track evidence in chain of custody.
  • To regularly report on information security incidents to Trusts Information Governance Groups.
  • To compose and ensure that Information Governance Policies in relation to information security are implemented, enforced and monitored and ensure all Trusts embraces a culture of confidentiality.
  • To plan and implement a system of full data protection audit within Trusts. This will involve liaison with staff within Trust and assessing systems and processes against regulations.
  • To report on the results of the data protection audit making recommendations for improvements. This will involve liaison with senior staff within Trusts.
  • Ensure that data protection and information security training for each Trust is up-to-date, and incorporates current Trust policies and practices.
  • Ensure that data protection and information security training is monitored for quality and understanding. This is usually achieved by post training questionnaires and interviews.
  • To keep abreast of IT Security developments and ensure the Trust is adhering to national cyber security initiatives and maintain awareness of cyber threat trends.
  • Through a matrix management approach, ensure all staff with the IT Operations function are leading on developments to support MIAA recommendations and are managing CareCerts alerts.

Person specification

Qualifications

Essential criteria
  • Certified Information Systems Security Professional (CISSP) qualification (or working towards), or an equivalent level of system security experience.
  • Masters degree or equivalent experience in an IT technical environment
Desirable criteria
  • Certified Information Security Manager (CISM)
  • Project Management Qualification
  • ITIL foundation

Experience

Essential criteria
  • Evidence of the ability to demonstrate strong leadership and management skills that positively supports the overall vision and objectives of the Trust and Department and is an excellent leadership role model for their staff.
  • An understanding of the benefits that new technology can deliver to the NHS.
  • Ability to make judgments on multi-stranded or complex information security problems, which may have no precedent or where there are conflicting opinions
  • Ability to manage numerous conflicting priorities and effective time management.
  • Ability to frequently concentrate for prolonged periods of time managing interruptions as appropriate
  • Ability to travel within the Cheshire and Merseyside Community.
  • Relevant NHS management experience including line-managing staff.
  • Significant experience in a technical Information security position including implementation and maintenance of complex security policies
  • Specialist knowledge and expertise of IT systems and infrastructure. This should include knowledge and expertise in design, systems implementation, IT security, IT standards and best practice.
  • Experience of completing and complying with requirements in the CareCERT
  • Wide ranging knowledge and experience of software packages related to the entire range of IT systems provision.
  • Experience of successful collaborative and partnership working and ability to encourage others likewise
  • Understanding of risk management, business continuity management, procurement, corporate governance and corporate performance reporting principles.
  • Working knowledge of internet security devices such as firewalls, web proxies, email filters and intrusion detection devices

Skills

Essential criteria
  • Ability to communicate effectively with customers and external suppliers and to understand and interpret multi stranded complex policies and problems.
  • Ability to persuade senior managers and frontline staff of the importance of IM&T and the need for change.
  • Excellent written and verbal communicator with ability to express views and ideas that may be highly complex and describing technical solutions to customers in clear and non IM&T language.
  • Able to produce and present reports for audiences of varied technical competence
  • Proven skills and ability to understand a range of complex issues and identify potential solutions
  • Ability to express complex issues in an easily understandable manner for a range of audiences X
  • Ability to influence and persuade
  • Able to translate national requirements into local plans

Knowledge

Essential criteria
  • Indepth understading of the NHS CareCert toolkit and NHS Digital/England good practice Guidelines
  • Advanced knowledge of security technologies including; firewalls, anti-malware, IDS/IPS, web filtering, email filtering, SIEM, patch management, MDM, DLP, PKI and cryptography, IAM (Identity and access management) including MFA (multi-factor authentication)
  • Advanced knowledge of ICT infrastructure including; networking and associated protocols, remote access, virtualisation (compute and networking) and SANs
  • Understanding of virtualization, load balancing, clustering,
  • Extensive knowledge of ISO27001, and implementation
  • A good understanding of the of the Cyber Essentials Plus
  • A good understanding of GDPR/NIS2 and its implications
Desirable criteria
  • Knowledge of NHS England, NHS Digital and Department of Health strategies, policies and guidance
  • Knowledge of Information Security Assurance in the Information Governance / DSPT Toolkit

Personal Qualities

Essential criteria
  • Self-motivated and able to enthuse others at all levels
  • Strong leadership and team building skills
  • Conscientious with good attention to detail
  • Ability to make decisions autonomously on difficult issues, working to tight and often challenging timescales
  • Ability to work to deadlines under pressure and manage and prioritise workloads effectively
  • Able to successfully negotiate solutions, resources and timescales at a senior level in the organisation using tact, diplomacy and persuasion
  • Ability to introduce new methods of working despite potential resistance
  • Ability to absorb new technical information quickly
  • Ability to demonstrate a strong desire to improve performance and make a difference

Closing date: 12/02/2024

For more information about the role and to apply, visit:
https://www.healthjobsuk.com/job/UK/Merseyside/Liverpool/Alder_Hey_Childrens_NHS_Foundation_Trust/Digital_Assurance_Delivery/Digital_Assurance_Delivery-v5962635?_ts=2828