Job Summary
Making sure you fit the guidelines as an applicant for this role is essential, please read the below carefully.
The Cyber Operations purpose is to support safe care and build public trust by building NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS.
The Cyber Operations sub-directorate consists of 4 operational areas:
1. Cyber Security Operations Unit (CSOU) - SIO
2. Cyber Delivery Unit (CDU)
3. Cyber Improvement Programme
4. Chief Information Security Office Function (CISO)
The Senior Incident Manager role is a great opportunity to work within the CSOU leading on the management of serious and complex cyber security investigations. You should have great communication skills and not be averse to public speaking and be able to communicate concepts and ideas across a range of stakeholders. You will lead on process improvement work within the Incident Management team and act as a Cyber Security subject matter expert. Flexibility is required as during an incident there may be extended hours of work. You must be able to prepare reports to a standard that would withstand robust scrutiny. An understanding of the computer misuse act and the data protection act is required. You should be able to understand the cyber threat landscape, the volatility of data, the importance of continuity of evidence, and digital forensics.
Main Duties of the Job
* Manage Serious and Complex Cyber Security Investigations.
* Write and develop documentation such as playbooks and user guides.
* Write detailed investigation reports.
* Gather and manage large volumes of information from a variety of sources during an investigation.
* Support Incident Managers and Junior Incident Managers with their investigations.
* Act as a second-tier escalation point for analysts within the CSOU.
* Manage and resolve more complex enquiries.
* Manage Cyber Incident Response teams that are deployed during a cyber security incident.
* Create strategies for digital forensics investigators.
* Run and chair blended calls during a Cyber Security Incident, ensuring they are structured and effective.
* Ensure standards by reviewing security tickets created by analysts and Incident Managers within the CSOU.
* Deliver cyber security and Incident Management presentations to a diverse audience.
* Write articles and share information that can help educate the wider systems on current and emerging cyber security threats.
* Gather key performance indicators and deliver reports.
* Use tooling such as Sentinel, Microsoft Defender for Endpoint, and Splunk during cyber security investigations.
* Work across teams to develop and advance cyber security investigations by bringing together a variety of skill sets and knowledge to achieve successful outcomes.
* Act as a cyber security Subject Matter Expert for projects and improvements across the transformation directorate.
About Us
The NHS England board has set out the top-level purpose for the new organisation to lead the NHS in England to deliver high-quality services for all, which will inform the detailed design work and we will achieve this purpose by:
1. Enabling local systems and providers to improve the health of their people and patients and reduce health inequalities.
2. Making the NHS a great place to work, where our people can make a difference and achieve their potential.
3. Working collaboratively to ensure our healthcare workforce has the right knowledge, skills, values, and behaviours to deliver accessible, compassionate care.
4. Optimising the use of digital technology, research, and innovation.
5. Delivering value for money.
If you would like to know more or require further information, please visit NHS England.
Colleagues with a contractual office base are expected to spend, on average, at least 40% of their time working in-person.
Important: Please be aware there are residency requirements you need to meet:
All NHS England Cyber Security personnel must hold security clearance SC level as a minimum. To meet National Security Vetting requirements, you must have resided in the UK for a minimum of 3 out of the past 5 years for SC clearance. Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role will still be considered.
Please make sure you meet these requirements before applying for this role.
You don't need to have SC already; however, failure to achieve the requirements for SC after offer will result in the job offer being withdrawn.
Person Specification
Qualifications
Essential
* Post-graduate degree or equivalent level of experience (3 years' cyber security experience)
Knowledge
Essential
* Expert knowledge of the processes, tools, and techniques of information security management.
* Demonstrable knowledge of technologies and technology-based solutions dealing with information security issues.
Desirable
* Expert knowledge of concept, procedures, and processes of Security Information and Event Management (SIEM).
Skills and Experience
Essential
* Demonstrable knowledge of and ability to utilize a variety of specific tools for collecting, analysing, and presenting digital-related evidence.
Desirable
* Proven knowledge of tools, techniques, approaches, and processes of cybersecurity risk management.
Disclosure and Barring Service Check
This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.
Certificate of Sponsorship
Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications.
Employer Details
Employer Name
NHS England
Address
7-8 Wellington Place, Leeds / Hexagon House, Exeter
Leeds or Exeter
LS1 4AP
Employer's Website
#J-18808-Ljbffr