Cyber Security Vulnerability Manager
Job summary
Are you passionate about cyber security and protecting critical digital services that make a real difference to people's lives? We are looking for a Cyber Vulnerability Manager to lead and develop our vulnerability management function, helping to identify, assess and reduce cyber risks across NHS Wales.
In this highly influential role, you will oversee vulnerability scanning, assessment and remediation activities, ensuring systems and applications remain secure against existing and emerging threats. Working with a wide range of stakeholders, you will provide expert advice, develop improvement initiatives and support the delivery of a strong cyber security culture across the organisation.
As a leader within the Cyber Security team, you will manage and support specialist staff, helping them to develop their skills while creating an inclusive and collaborative environment where everyone can thrive. You will also contribute to strategic cyber security planning, helping shape future security capabilities and continuously improving services for our users.
This is an exciting opportunity for someone with strong technical expertise, excellent leadership skills and a passion for continuous improvement. If you enjoy solving complex challenges, influencing positive change and working in a role where your expertise directly supports vital public services, we would love to hear from you.
Main duties of the job
As Cyber Vulnerability Manager, you will lead the delivery of vulnerability management services across a complex digital environment. You will coordinate vulnerability assessments, analyse security findings and work closely with technical teams, suppliers and service owners to ensure risks are effectively managed and remediated.
You will oversee vulnerability scanning tools, penetration testing activities and associated contracts, ensuring services remain effective, compliant and aligned with organisational objectives. Using data and intelligence from multiple sources, you will assess risk, identify trends and produce reports that support informed decision-making at operational and strategic levels.
A key part of the role will involve developing policies, procedures and standards that strengthen cyber resilience and support continuous improvement. You will lead projects, manage priorities and contribute to cyber security improvement programmes, ensuring outcomes are delivered on time and to a high standard.
The post holder will also build strong relationships across the organisation and wider NHS, providing expert guidance, delivering training and awareness activities, and helping teams understand and manage cyber security risks in a practical and collaborative way.
About us
Digital Health and Care Wales (DHCW) is part of the NHS Wales family and has an important role in changing the way health and care services are delivered through technology and data. The organisation supports frontline staff with modern systems and access to important information about their patients, while empowering the people of Wales to manage their own health through digital NHS Wales services.
Working for DHCW offers lots of employee benefits, including flexible working, a competitive salary, 28 days of annual leave plus Bank Holidays and opportunities for career development. We are committed to recognising and celebrating our staff as the most valuable part of our organisation.
Join our game changing, life-saving team and start making a real difference to health and care services in Wales.
Job description
Job responsibilities
You will be able to find a full Job description and Person Specification attached within the supporting documents or please click "Apply now" to view in Trac.
- Provide professional leadership, coaching and line management to specialist cyber security staff, supporting their development and performance.
- Develop and maintain vulnerability management policies, processes and standards in line with organisational and national requirements.
- Analyse complex security data, vulnerability reports and threat intelligence to identify risks, trends and opportunities for improvement.
- Work collaboratively with technical teams, suppliers and stakeholders to coordinate remediation activity and improve security outcomes.
- Manage cyber security projects and improvement programmes, balancing competing priorities and ensuring successful delivery.
- Produce high-quality reports, dashboards, presentations and recommendations for a range of technical and non-technical audiences.
- Act as a subject matter expert, providing specialist advice on vulnerability management, cyber security best practice and emerging threats.
- Support governance, risk and compliance activities, including audits, security assessments and accreditation requirements.
- Champion an inclusive, supportive and continuous improvement culture where diverse perspectives are valued and everyone is encouraged to contribute their best work.
We welcome applications from candidates of all backgrounds and experiences.
The ability to speak Welsh is desirable for this post; Welsh and/or English speakers are equally welcome to apply.
Person Specification
Qualifications
- Educated to degree (or equivalent qualification / experience) in an associated professional field.
- Educated to degree (or equivalent qualification / experience) in an associated professional field.
- Professional Registration with a relevant informatics professional body.
- FEDIP Practitioner, or equivalent recognised Intermediate level Professional qualification.
Experience
- Experience of leading a team and successfully identifying and managing the risks posed by vulnerabilities in the IT systems and applications within a large complex organisation.
- Experience of conducting penetration tests and vulnerability scans in a corporate environment.
- Proven ability to develop training materials to effectively accommodate participants with differing learning styles.
- Familiar with the IT environment relating to own sphere of work (own organisation and/or closely associated organisations, such as customers, suppliers, partners), in particular own organisation's technical platforms and those that interface to them through the specialism, including those in closely related organisations.
Skills and Attributes
- Technical Adaptability skills to learn and assess new methodologies or technologies quickly, understanding their wider implications and where appropriate implement them.
- Analytical skills to acquire a proper understanding of a problem or situation by breaking it down systematically into its component parts and identifying the relationships between these parts. Selecting the appropriate method/tool to resolve the problem and reflecting critically on the result, so that what is learnt is identified and assimilated.
Disclosure and Barring Service Check
This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.
Certificate of Sponsorship
Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website.
From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants.
Employer details
Employer name
Digital Health and Care Wales
Address
Hybrid working
Location to be confirmed at interview
CF11 9AD
United Kingdom
Employer's website
https://nwis.nhs.wales/