IT Cyber Specialist

Job summary

The IT Cyber Specialist is responsible for supporting the delivery, monitoring, and continual improvement of cyber security operations across the Integrated Care Board (ICB) and GP IT estate. The post holder helps protect critical clinical and corporate systems by strengthening defences, supporting incident response, managing vulnerabilities, patching, and ensuring adherence to NHS cyber, DSPT CAF and other information security standards. Working under the direction of the Head of IT Infrastructure & Cyber Operations, the IT Cyber Specialist provides expert hands on cyber security capability, maintains tooling and monitoring platforms, and contributes to organisation wide cyber resilience. The role supports safe patient care by helping prevent, detect, and mitigate cyber threats.

Main duties of the job

This role is responsible for supporting the day-to-day cyber security operations across the Integrated Care Board (ICB) & GP IT estate, helping to protect clinical & corporate systems from cyber threats. The post holder will monitor & manage security tools, investigate & respond to security alerts & incidents, conduct vulnerability assessments, & support patching & remediation activities. The role works closely with internal IT teams, NHS partners, suppliers & national cyber services to strengthen the organisation's security posture. Key duties include maintaining cyber security records & compliance evidence, producing technical reports, supporting security audits, responding to national cyber alerts, & providing specialist advice on cyber risks & secure working practices. The post holder will contribute to cyber improvement programmes, security hardening initiatives, resilience testing, disaster recovery exercises & phishing simulations. They will also support identity & access management processes, help develop secure technical standards, & assist with the implementation of new cyber security tools & controls. The successful candidate will act as a subject matter expert for cyber security, helping to improve organisational resilience, supporting compliance with NHS & regulatory requirements, & promoting a strong culture of cyber awareness across the organisation. Occasional participation in out-of-hours support for major incidents & essential maintenance may be required.

About us

Under the Model ICB Blueprint and the 10 Year Health Plan, ICBs will adopt a more strategic commissioning role, focusing on population needs, reducing inequalities, and delivering the three shifts as defined in the 10-year health plan, all while operating within strict financial limits.

The new organisation will operate on a larger scale with a revised vision and purpose, managing a commissioning budget of around £8 billion. Our role as a strategic commissioner is to transform our local NHS through exceptional commissioning and build an innovative health system fit for the 21st century that truly meets our communities needs. Informed by high quality data and insights, we will radically re-imagine how we operate, making sure that every pound in our system delivers the best possible value for everyone we serve.

We will encourage and support our people to grow and develop new skills and embrace new agile ways of working. Everyone is encouraged to contribute ideas, seek feedback, and take part in creating a listening and learning culture where insight leads to improvement.

We will work as a team of teams, collaborating across services and professions to deliver the best outcomes for our communities. You will be encouraged, and expected to model inclusive behaviours, valuing diverse perspectives and helping to create a workplace where everyone feels respected, supported, and able to thrive.

Job description

Job responsibilities

For detailed information on this IT Cyber Specialist job, please refer to the attached Job Description.

Person Specification

Experience

Essential
  • Please also refer to the detailed Person Specification attached.
  • Strong technical understanding of cyber security principles, secure configuration, threat detection and vulnerability management
  • Experience working with security monitoring and protective tooling such as:
  • Microsoft MDE
  • Vulnerability scanning tools
  • Identity security and multi-factor authentication
  • Working knowledge of Microsoft 365 security in nhs.net connect
  • Understanding of network security concepts (e.g., firewalls, segmentation, IDS/IPS, DNS filtering).
  • Knowledge of patching methodologies, operating system hardening, and baseline compliance
  • Awareness of national NHS cyber policies, cyber alerts, and regulatory expectations e.g. NIS and DSPT CAF
  • Hands-on technical experience supporting cyber security operations in a complex IT environment
  • Experience analysing security alerts, investigating incidents, correlating events, and contributing to incident response
  • Experience conducting vulnerability assessments, patch compliance checks and remediation tracking
  • Experience working with IT teams to improve security posture across endpoints, servers, networks, and cloud environments
  • Experience documenting incidents, maintaining risk registers, and producing security reports
  • Ability to communicate technical cyber risks clearly and appropriately to both technical and non-technical colleagues
  • Ownership of issues
  • Demonstrated capabilities to manage own workload and make informed decisions in the absence of required information, working to tight and often changing timescales
  • The promotion of equality of opportunity and good working relations (providing practical leadership)
  • Self-motivated
  • Demonstrates honesty and integrity and promotes organisational values
  • Embrace change, viewing it as an opportunity to learn and develop

Qualifications

Essential
  • Please also refer to the detailed Person Specification attached.
  • Educated to degree level in a relevant IT, cyber security, or computer science discipline, or able to demonstrate equivalent specialist experience at an advanced technical level. Professional cyber security qualification(s) desirable, such as:
  • CompTIA Security+
  • CompTIA CySA+
  • EC-Council CEH (Desirable) CISSP / CCSP / CISM (or working toward)
  • Evidence of ongoing professional development in cyber security, threat detection, security monitoring, and vulnerability management
  • Knowledge of NHS cyber frameworks (DSPT, Cyber Assessment Framework, NIS/NIS2) acquired through formal training or relevant experience
  • Training or certification in security tooling (MDE, vulnerability management, identity protection) advantageous

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website.

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants.

Employer details

Employer name

NHS Dorset

Address

NHS Dorset Integrated Care Board

NHS Dorset - County Hall

Colliton Park

Dorchester

Dorset

DT1 1XJ

United Kingdom

Employer's website

https://nhsdorset.nhs.uk/



Job Details

Company
NHS Dorset
Location
Dorchester, DT1 1XJ, Chippenham, SN15 1GG, Yeovil, BA22 8HR, United Kingdom
Salary
£49387.00 to £56515.00
Posted