Assistant Director of Cyber Security, Governance, Compliance & Risk
Job summary
The Assistant Director of Cyber Security, Governance, Compliance & Risk provides senior leadership and strategic direction for the organisation's cyber security function. The post holder is accountable for developing, implementing, and continuously improving a comprehensive, outcome-focused cyber security programme that protects the confidentiality, integrity, availability, safety, privacy, and recoverability of all information assets across the organisation and wider GM system.
As the lead expert and highest point of escalation, you will own the end-to-end cyber governance, risk management, and compliance agenda. This includes formulating and maintaining the overarching cyber strategy, policies, standards, and control frameworks (aligned to short-, medium-, and long-term organisational objectives), while ensuring consistent application organisation-wide. Key responsibilities encompass leading threat intelligence and assessment activities, conducting complex risk assessments, maintaining risk registers, devising and prioritising mitigations, and integrating cyber risk into the wider organisational risk management process.
This senior leadership role demands exceptional strategic vision, expert technical knowledge, advanced stakeholder management, and the ability to navigate highly complex, multi-faceted information in a large-scale environment to drive cyber resilience and support the organisation's mission.
Main duties of the job
- Be the lead expert in your field, providing expert advice, leadership and being the highest point of escalation for the team.
- Be responsible for all aspects of cyber governance, risk and compliance.
- You will implement and monitor a strategic, comprehensive information security cyber program to ensure appropriate levels of confidentiality, integrity, availability, safety, privacy and recovery of information assets owned, controlled or/and processed.
- Have responsibility for ensuring adherence to mandated requirements around DSPT toolkit and ensuring the organisation is compliant with UK Regulations.
- Hold overall responsibility for the compliance of organisational wide information security systems.
- Be responsible for the overall cyber strategy, formulating, adjusting and ensuring the delivery of plans as necessary, across the short, medium and long term.
- Be responsible for and lead on threat intelligence and threat assessment for the organisation.
- Be responsible for and ensure compliance with Cyber Essentials/Cyber Essentials plus and with the ISO 27000 series of standards.
- Lead the cyber function, holding overall responsibility for all aspects of people management.
About us
NHS GM plans and delivers joined-up services to improve the health and wellbeing of the population residing in Greater Manchester. Its's goals include improving population health and healthcare outcomes, tackling inequalities, enhancing productivity and value for money, and supporting broader social and economic development.
This will be achieved at various levels, including neighbourhood, place, combinations of places, and the Greater Manchester system.
Matrix working is key to delivering our organisation's and system priorities. You will actively enable collaboration through service planning, programme delivery, stakeholder engagement, and team leadership. This includes considering the wider impact of decisions, driving improvement, and supporting inclusive ways of working where different perspectives are valued.
Job description
Job responsibilities
KEY DUTIES AND RESPONSIBILITIES
Be the lead expert in your field, providing expert advice, leadership and being the highest point of escalation for the team.
Be responsible for all aspects of cyber governance, risk and compliance. You will implement and monitor a strategic, comprehensive information security cyber program to ensure appropriate levels of confidentiality, integrity, availability, safety, privacy and recovery of information assets owned, controlled or/and processed.
COMMUNICATION
Presents highly complex, sensitive or technical information about projects, initiatives and services to a wide range of stakeholders in a formal setting.
Required to explain highly complex technical issues in a simple, non-technical manner for customers
INFORMATION RESOURCES, ANALYSIS AND DECISION MAKING
- The post holder is responsible for the development, maintenance, and interpretation of highly complex cyber security information resources, including strategic risk registers, threat intelligence reports, maturity assessments, metrics dashboards, control assurance evidence, and compliance documentation (e.g., DSPT toolkit submissions, Cyber Essentials assessments, ISO 27001-aligned frameworks).
Person Specification
Qualifications
- Minimum of a Masters degree level qualification relevant to the role or demonstrable equivalent level of experience.
- Specialist cyber related qualification.
Professional Registration
- Registered member of professional informatics body such as UKCHIP, BCS, Assist etc.
Experience
- Extensive experience of both imputing into and formulating short, medium and long term strategic plans and policies.
- Extensive experience of project and change management skills and/or techniques.
- Extensive experience of all aspects of people management, from recruitment to dealing with disciplinary matters.
- Substantial experience of working to tight KPI's/targets with the ability to work well under pressure to achieve these.
- Experience of working in a large and complex multi-tiered environment.
- Highly developed specialist knowledge, underpinned by theory and experience.
- Previous experience of strategy planning and development for IT architectures.
- Extensive experience of cyber/architectural analysis, design, development, procurement and deployment.
- Extensive knowledge of IT infrastructures, systems and management processes acquired through post graduate diploma or equivalent experience or training plus further specialist knowledge or experience to master's level or equivalent.
- Evidence of post qualifying and continuing professional development.
- Broad and detailed knowledge of IT infrastructure, architecture, software and systems.
- A firm understanding of design, optimisation, deployment and management processes of network and hardware infrastructures.
- Knowledge and experience of development architecture life cycles and governance processes.
- Must understand the background to and aims of current healthcare and appreciate the implications of this on engagement
- Should have an appreciation of the relationship between NHS England, commissioning, provider and support organisations.
- Good concentration skills, required to concentrate for prolonged periods to analyse highly complex IT information and meet multiple demands on an ongoing and daily basis
- Ability to work out-side normal office hours and participate on an on-call rota.
- Previous experience of working in digital in the NHS or a healthcare setting.
- Previous experience of managing a function comprising of multiple teams.
Knowledge
- Highly developed and expert knowledge of digital best practice and procedures.
- Excellent understanding of information security and information governance.
- Extensive working knowledge of current practices and issues in the cyber field.
- Strong communication skills and the ability to negotiate, influence and facilitate effective interaction with key stakeholders and suppliers.
- Developed communication skills for delivering key messages to a range of stakeholders both internal and external (including outside the NHS) to the organisation, some at very senior level.
- Good presentation skills for conveying complex concepts.
- Ability to use informed persuasion to influence others.
- Able to communication complex technical information to not technical people using simple, explanatory language that is understandable.
Competencies
- Excellent analytical and problem-solving skills.
- Exceptional communication skills in order to convey highly complex and highly sensitive digital / cyber issues to a non-digital / cyber audience
- Good judgement necessary to choose the best solution from complex architectures with a range of options.
- Ability to identify risks, anticipate issues and create solutions and to resolve problems in relation to project or service delivery.
- Ability to understand a broad range of complex information quickly and making decisions where opinions differ/no obvious solution.
- Acknowledged as an expert in cyber security.
Other
- Evidence of planning and delivering programmes and projects and services on time.
- Team working skills.
- Ability to move between details and the bigger picture.
- Previously responsible for a budget, involved in budget setting and working knowledge of financial processes.
- Demonstrates honesty and integrity and promotes organisational values.
- Embrace change, viewing it as an opportunity to learn and develop.
- Ability to work without supervision, providing specialist advice to the organisation, working to tight and often changing timescales.
- Interpreting national policy for implementation.
Employer details
Employer name
NHS Greater Manchester Integrated Care
Address
Tootal Buildings
Manchester
M1 6ED
United Kingdom
Employer's website
https://www.gmsharedservices.nhs.uk/