Information Security Manager

Information Governance Manager

Location: Kent

Contract: 6 Month FTC

An excellent opportunity has arisen for an experienced Information Governance Manager to join an established organisation operating within the healthcare sector.

Reporting to the Group Data Protection Officer, you will play a key role in ensuring compliance with data protection legislation, strengthening the organisation's information governance framework and promoting a positive data protection culture.

A major focus of the position will be supporting a data protection modernisation programme, including transferring Records of Processing Activities (RoPA), DPIAs and LIAs onto the OneTrust platform.

The Role

As Information Governance Manager, you will:

  • Lead the modernisation of the RoPA process, transferring it onto the OneTrust platform.
  • Implement streamlined DPIA and LIA processes, supporting assessments and advising on appropriate mitigation strategies.
  • Develop, review and update information governance and data protection procedures and guidance.
  • Ensure projects embed data protection by design and by default.
  • Provide training and guidance on data protection and information governance matters.
  • Work closely with stakeholders to ensure data handling processes comply with relevant legal and regulatory requirements.
  • Support third-party supplier security and compliance assessments and help identify areas for security improvement.
  • Provide advice and challenge around data protection legislation and cyber security.
  • Support the Group DPO with audits to assess compliance with information governance policies and procedures.

About You

Ideally, you will have:

  • Extensive experience within an Information Governance role within the healthcare environment
  • A deep understanding of NHS Information Governance and Caldicott principles.
  • Strong knowledge of GDPR, ISO 27001 and PCI DSS requirements.
  • Experience supporting information governance programmes, including risk management activities.
  • Experience of third-party audit and compliance management.
  • A Data Protection qualification such as GDPR Practitioner Certification would be desirable.
  • Strong stakeholder management and communication skills, with the ability to communicate effectively with both technical and non-technical audiences.
  • A methodical, thorough and highly organised approach.
  • The ability to work calmly and collaboratively in a fast-paced environment.

Job Details

Company
MERJE
Location
Kent, England, United Kingdom
Posted