Senior Cyber Security Engineer

Job summary

Senior Cyber Security Engineer

Research, Data & Digital Directorate, Cyber Security Department

Closing date: 17th August 2025

Interview: The interview will take place virtually 02 September 2025

Main duties of the job

Are you an experienced Cyber Security engineer who is dedicated to ensuring that our public services are safe and secure? Do you enjoy collaborating and implementing across different functions and divisions? The Senior Cyber Security Engineer is a permanent role at Public Health Wales that will help us deliver our Digital and Data Strategy.

A degree (preferably in Cyber Security) or equivalent work experience and knowledge is essential. You must have held a senior cyber security position, preferably in a healthcare environment. You must also be prepared to work from our Cardiff location when required, including on short notice.

If you'd like to discuss the role further, please contact Dennis Jones, Principal Data Security Specialist: dennis.jones2@wales.nhs.uk

The ability to speak Welsh is desirable for this post; Welsh and/or English speakers are equally welcome to apply.

You will be able to find a full Job description and Person Specification attached within the supporting documents or please click "Apply now" to view on Trac.

About us

We are Public Health Wales - the national public health agency in Wales. Our purpose is 'Working together for a healthier Wales'. We exist to help everyone in Wales live longer, healthier, happier lives. Together with our partners, we work to increase healthy life expectancy, improve health and well-being, and reduce inequalities for everyone in Wales, now and for future generations.

Our teams work to prevent disease, protect health, and provide leadership, specialist services and public health expertise. We are the leading source of public health information, research and innovation in Wales. In a world facing complex health challenges, our work has never been so important.

We are guided by our Values, 'Working together, with trust and respect, to make a difference'. We are committed to building an inclusive workplace that values equality and diversity. We welcome applications which represent the rich diversity of the communities we serve and are supportive of flexible working arrangements, including part time roles and job sharing.

To find out more about working for us and the benefits we offer please visit https://phw.nhs.wales/careers/

For guidance on the application process, please visithttps://phw.nhs.wales/working-for-us/applicant-information-and-guidance/

Job description

Job responsibilities

The Senior Cyber Security Engineer at Public Health Wales is primarily responsible for protecting the organisations digital infrastructure, systems and sensitive data by implementing and enhancing cyber security measures across all IT systems.

This includes designing and documenting secure cyber infrastructure, including network architectures and communication systems, as well as ensuring that all cybersecurity controls align with national standards and best practices.

The role involves proactively identifying and mitigating cyber risks, managing the organisations readiness for cyber threats, and leading responses to security incidents. The postholder will also oversee cyber audits, penetration testing, and incident investigations, often requiring collaboration with staff at all levels.

Monitoring and analysing security events using tools like SIEM is a key duty, ensuring swift detection and response to threats. Additionally, the role includes mentoring cyber security team members, promoting professional development, and fostering a culture of continuous learning.

Strong communication and organisational skills are essential, as the engineer must translate complex technical issues into clear information and deliver robust security policies and infrastructure under pressure.

Qualifications and Knowledge

Essential

  • Educated to degree level (preferably in Cyber Security) or equivalent level of work experience and knowledge.
  • Evidence of continual professional development.
  • Awareness of national and international cyber security regulations, standards and frameworks (e.g. NIS Regulations, ISO 27001, NIST).

Desirable

  • Holds a relevant professional cyber security certification (e.g. CISSP, CISM).
  • Membership of a professional body (e.g. BCS).
  • Knowledge of IT systems within a healthcare environment.
  • CCNP Security or equivalent experience.
  • Understanding of aligning cyber security with organisational strategy.

Experience

Essential

  • Relevant experience in a senior cyber security role, preferably within a healthcare environment.
  • Extensive experience working on IT security-related issues.
  • Management or supervisory experience.
  • Experience in managing and motivating technical teams
  • Ability to understand vulnerability scans and penetration tests and develop remediation plans.
  • Experience developing and implementing cyber security policies, processes, and procedures.
  • Experience managing phishing simulation & training and awareness campaigns.
  • Experience with vulnerability scanning, incident response, and third-party risk management.
  • Experience in monitoring and configuring warning and security systems.

Desirable

  • Cloud Security experience (e.g. Azure, AWS, GCP).
  • Experience with firewalls, intrusion detection/prevention systems, and network design.
  • Experience with Microsoft Windows Server and IP networking.
  • Experience of working within ITIL-based change management processes.
  • Ability to evaluate and select from a range of security tools and controls.

Skills and Attributes

Essential

  • Excellent problem-solving and analytical skills.
  • Excellent verbal and written communication skills.
  • Ability to communicate clearly with non-technical staff and end users.
  • Pragmatic approach to balancing security and usability.
  • Ability to work independently and organise own and team workload.
  • Strong planning, prioritisation, and organisational skills.
  • Ability to handle sensitive information appropriately.
  • Ability to make judgements involving highly complex information.
  • Ability to manage IT and cyber security projects and technical implementations.

Desirable

Welsh Language Skills

Other

Ability to travel between sites in a timely manner to meet the needs of the service.

Ability to travel and work away from base.

Able to periodically work out of hours or at weekends when required.

Able to participate in on-call rota.

Person Specification

Qualifications and Knowledge

Essential
  • oEducated to degree level (preferably in Cyber Security) or equivalent level of work experience and knowledge.
  • oEvidence of continual professional development.
  • oAwareness of national and international cyber security regulations, standards and frameworks (e.g. NIS Regulations, ISO 27001, NIST).
Desirable
  • oHolds a relevant professional cyber security certification (e.g. CISSP, CISM)
  • oMembership of a professional body (e.g. BCS).
  • oKnowledge of IT systems within a healthcare environment
  • . oCCNP Security or equivalent experience.
  • .oUnderstanding of aligning cyber security with organisational strategy.

Experience

Essential
  • oRelevant experience in a senior cyber security role, preferably within a healthcare environment.
  • oExtensive experience working on IT security-related issues.
  • oManagement or supervisory experience.
  • oExperience in managing and motivating technical teams
  • oAbility to understand vulnerability scans and penetration tests and develop remediation plans.
  • oExperience developing and implementing cyber security policies, processes, and procedures.
  • oExperience managing phishing simulation & training and awareness campaigns.
  • oExperience with vulnerability scanning, incident response, and third-party risk management.
  • oExperience in monitoring and configuring warning and security systems.
Desirable
  • oCloud Security experience (e.g Azure, AWS, GCP)
  • oExperience with firewalls, intrusion detection/prevention systems, and network design.
  • oExperience with Microsoft Windows Server and IP networking.
  • oExperience of working within ITIL-based change management processes.
  • oAbility to evaluate and select from a range of security tools and controls.

Skills and Attributes

Essential
  • oExcellent problem-solving and analytical skills
  • oExcellent verbal and written communication skills.
  • . oAbility to communicate clearly with non-technical staff and end users.
  • oPragmatic approach to balancing security and usability.
  • oAbility to work independently and organise own and team workload.
  • oStrong planning, prioritisation, and organisational skills.
  • oAbility to handle sensitive information appropriately.
  • oAbility to make judgements involving highly complex information.
  • oAbility to manage IT and cyber security projects and technical implementations.
Desirable
  • oWelsh Language Skills

Other

Essential
  • oAbility to travel between sites in a timely manner to meet the needs of the service
  • oAbility to travel and work away from base.
  • oAble to periodically work out of hours or at weekends when required.
  • oAble to participate in on-call rota.

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website.

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants.

Employer details

Employer name

Public Health Wales

Address

Capital Quarter 2

Tyndall Street

Cardiff

CF10 4BZ


Employer's website

https://phw.nhs.wales/

Company
Public Health Wales
Location
Cardiff, United Kingdom CF10 4BZ
Employment Type
Permanent
Salary
£48527.00 - £55532.00 a year
Posted
Company
Public Health Wales
Location
Cardiff, United Kingdom CF10 4BZ
Employment Type
Permanent
Salary
£48527.00 - £55532.00 a year
Posted