Cyber Security Manager – Governance, Risk and Compliance (GRC)

Job summary

Cyber Security Manager - Governance, Risk and Compliance (GRC) Band 7 - £49,387 - £56,515 per annum Thurrock Community Hospital

Are you ready to lead cyber security at scale in a complex, mission-driven organisation where your work truly matters?

We're looking for an experienced and passionate Cyber Security Manager - Governance, Risk & Compliance (GRC) to drive our cyber assurance agenda and strengthen the resilience of critical NHS services. Reporting directly to the Associate Director of Information Security (CISO), you will play a pivotal leadership role, shaping how we manage cyber risk, compliance, and governance across the Trust.

This is more than a management role -- it's an opportunity to influence strategic decision-making, protect vital services, and lead meaningful change in an evolving cyber landscape. You'll work at the heart of the organisation, collaborating with senior stakeholders, technical teams, and external partners to ensure we meet the highest standards of cyber security and regulatory compliance.

We're looking for someone who combines deep technical expertise with strong leadership, who thrives in a fast-paced environment, and who can translate complex cyber risks into clear, actionable insights.

In return, you'll join a supportive, forward-thinking team where innovation is encouraged, professional growth is supported, and your impact will be visible across the organisation.

If you're shortlisted, your interview will take place in October 2026

Main duties of the job

As Cyber Security Manager - GRC, you will lead a high-quality governance, risk and compliance function, ensuring strong cyber assurance across the Trust.

What you'll be doing:

Lead Governance & Assurance Oversee cyber governance services, ensuring alignment with frameworks such as ISO 27001, CAF and DSPT. Manage the full lifecycle of policies and procedures, and deliver clear assurance reports and dashboards to senior and board-level stakeholders.

Drive Risk & Compliance Identify, assess and mitigate cyber risks across the organisation. Ensure adherence to legislation, standards and best practice, and coordinate audit evidence and assurance activities.

Strengthen Controls & Testing Lead the penetration testing programme, managing remediation plans and analysing security data, vulnerabilities and incidents to drive continuous improvement. Implement and monitor KRIs and control effectiveness.

Enhance Incident Preparedness Develop and lead incident response planning, including tabletop exercises, working closely with operational, technical and information governance teams to improve resilience.

Lead & Develop the Team Provide leadership, coaching and direction, managing resources and priorities while fostering a high-performing, collaborative culture.

Engage Stakeholders Build strong relationships across teams, communicate complex risks in a clear, accessible way, and influence decision-making to secure buy-in for security initiatives.

About us

Valuing you. Recognising your dedication. At EPUT, we look after you.

  • Receive supervision and support to help you fulfil your potential.
  • Join an inclusive EPUT community and connect with others through engagement events and equality or champion networks.
  • If you need help, we provide mental health and wellbeing services, occupational health advice and counselling.

Benefits

  • 27 days holiday, plus bank holidays, rising to 33 days after 10 years' service.
  • Excellent pension of up to 14.5% of your pensionable pay.
  • Staff discounts include Blue Light Card, NHS discount offers, and staff benefits.
  • £8K relocation package if you move to Essex to join us
  • Season ticket loans are interest-free to cover the cost of travelling to and from work via tram, rail, or bus.

Work that wraps around your needs

  • Job share: Applications for job shares are welcomed.

Job description

Job responsibilities

What were looking for:

Youll be a confident and credible cyber security professional with a strong GRC background and leadership experience in complex environments.

Key skills and experience include:

  • Expert knowledge of cyber security, governance, risk, and compliance frameworks
  • Strong experience with ISO 27001, CAF, DSPT, COBIT or similar standards
  • Proven ability to lead risk management, audits, and assurance programmes
  • Experience managing security incidents, vulnerability management, and protective monitoring
  • Demonstrable success in leading teams, driving change, and delivering against demanding timescales
  • Excellent analytical, problem-solving, and decision-making skills
  • Outstanding communication and stakeholder engagement skills, with the ability to influence at senior levels
  • Experience working in a large, complex organisation (NHS or public sector desirable)
  • Relevant professional certifications (e.g., CISM, CISA, CRISC, CGRC) or equivalent experience

Personal qualities we value:

  • Driven, proactive, and resilient under pressure
  • Collaborative, flexible, and adaptable to change
  • Passionate about cyber security and emerging technologies
  • Able to simplify complexity and bring clarity to challenging issues

This is a unique opportunity to shape cyber security governance at scale, influence senior leadership, and make a tangible difference to patient services and organisational resilience.

If youre ready to lead, innovate, and make an impact wed love to hear from you.

Person Specification

Education/Qualification

Essential
  • Educated to master's level, or equivalent experience, in Cyber Security or governance/compliance
  • Evidence of continuing professional development and specialist knowledge or experience which can be demonstrated to be equitable to a master's degree
  • Actively hold certifications; CGRC, CRISC, CISA, CISM or CGEIT
  • Professional Registration of FEDIP and Professional Member of one of its member bodies
Desirable
  • ISO 27001:2022 Implementer or Auditor Certification
  • Subject matter expert in risk management and cyber security
  • ITIL Service Management

Additional Qualities

Essential
  • Must be a car owner with full UK driving licence as travel will be required
  • Passion for new and emerging security related technologies
  • Willing to work flexibly to ensure 'job is done'

Knowledge

Essential
  • In-depth knowledge of the fundamentals surrounding cyber security
  • Excellent understanding of the management and transformation of services
  • Excellent understanding of the management and transformation of services
Desirable
  • Experience and knowledge of the Cyber Assurance Framework (CAF)
  • Experience and knowledge of the Data Security Protection Toolkit
  • Understanding and implementation experience COBIT 2019

Skills/Experience

Essential
  • Significant experience of protective monitoring and security incident management
  • Previous experience within large complex organisation in related area of activity
  • Demonstrable experience of producing qualitative work to aggressive timescales
  • Demonstrable experience of building strong relationships with business partners and multi-discipline project delivery teams
  • Full line and team management experience including leading, developing, motivating, coaching, talent management
  • Public Sector or NHS Management experience
  • Evidence of implementing change in governance related activity/ area
Desirable
  • Experience of working in a planning, project or change management environment
  • Development of option appraisals, feasibility studies and business cases

Personal Qualities

Essential
  • Ability to plan, organise and control all aspects of workload, whilst working under extreme pressure
  • Can explain highly complex issues and requirements in a clear, non-technical language and concise manner
  • Ability to interface at all levels within the customer environment to develop relationships and opportunities and manage problems

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website.

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants.

UK Registration

Applicants must have current UK professional registration. For further information please see NHS Careers website.

Employer details

Employer name

Essex Partnership University NHS Foundation Trust

Address

Thurrock Community Hospital

Long Lane

Grays

RM16 2PX

United Kingdom

Employer's website

https://eput.nhs.uk/

Job Details

Company
Essex Partnership University NHS Foundation Trust
Location
Grays, RM16 2PX, United Kingdom
Salary
£51657.00 to £58785.00
Posted