Job summary NHS England's Chief Information Security Office (CISO) Function's purpose is to enable safe care and build public trust by strengthening the cyber resilience of the NHS. The CISO supports the Transformation Directorate's purpose of delivering the best care and outcomes for patients, and enables faster, safer digital transformation of the NHS. As part of the CISO Function the Senior Cyber Security Advisor sit in the Secure Team who provide expert specialist security consultancy services to NHS England's Critical National Infrastructure and major national services, ensuring these services meet the requirements of Secure by Design Principles. Senior Cyber Security Advisors ensure NHS England's systems operate from a cyber resilient architecture. They provide detailed cyber guidance to project and DevSecOps teams, supporting the management of cyber risk. This is an exciting opportunity to help delivery cyber resilient systems for the NHS. You'll be given the support and autonomy to use your skills, knowledge, and experience, to make a real impact on improving people's lives. The role of Senior Security Advisor has been awarded a Recruitment and Retention Premia (RRP) in response to current labour market conditions. In recognition of this, the role attracts an additional monthly RRP payment equal to 20% per annum.Please be aware that RRP is none contractual and subject to review. Main duties of the job As a Senior Cyber Security Advisor, you will: Conduct security assessments and threat modelling to ensure systems are designed to reduce the risk and impact of compromise. Be focused on the provision of expert cyber security consultative guidance advising on security standards, designs, and patterns, ensuring there is security governance in place. Proactively interact with key stakeholders to gather information, resolve problems and make recommendations for improvements for developing and delivering an integrated information and cyber security strategy. Embed security culture within assigned programmes, enabling teams to build systems securely from the ground up. Implement project level strategies, defining objectives and addressing technology related controls, risks, and issues. Support programmes and projects in the delivery of secure systems.Conduct Risk Assessments against identified risks within assigned programmes. This is a critical role ensuring NHS England's security measures are aligned to government and industry standards, and appropriate measures are in place to mitigate against cyber security risks. The security landscape is constantly evolving, and this is your opportunity to think creatively and contribute to improving the security resilience of NHS Services across England. It's a great time to join NHS England and be part of the journey. About us The NHS England board have set out the top-level purpose for the new organisation to lead the NHS in England to deliver high-quality services for all, which will inform the detailed design work and we will achieve this purpose by: Enabling local systems and providers to improve the health of their people and patients and reduce health inequalities. Making the NHS a great place to work, where our people can make a difference and achieve their potential. Working collaboratively to ensure our healthcare workforce has the right knowledge, skills, values and behaviours to deliver accessible, compassionate care Optimising the use of digital technology, research, and innovation Delivering value for money. If you would like to know more or require further information, please visithttps://www.england.nhs.uk/. Colleagues with a contractual office base are expected to spend, on average, at least 40% of their time working in-person. Staff recruited from outside the NHS will usually be appointed at the bottom of the pay band. NHS England hold a Sponsor Licence; this means that we may be able to sponsor you providing the Home Office requirements are met. To be eligible for sponsorship through the Skilled Worker route you'll usually need to be paid the 'standard' salary rate of at least £38,700 per year, or the 'going rate' for your job, whichever is higher. You can find more information on the Government website. Date posted 06 January 2025 Pay scheme Agenda for change Band Band 8a Salary £64,506 to £72,605 a year Includes a RRP payment of 20%. Contract Permanent Working pattern Full-time Reference number 990-TD-CY-6846944-E Job locations Wellington Place, Leeds / Hexagon House, Exeter Leeds/Exeter LS1 4AP Job description Job responsibilities Please see the attached Job Description and Person Specification for more information about the role and responsibilities. Please ensure your supporting statement includes demonstratable evidence and specific examples on how you meet the criteria for each of the key skills specified. This will be used in both the shortlisting and interview processes Important: Please be aware there are residency requirements you need to meet: All NHS England Cyber Security personnel must hold security clearance SC level as a minimum. To meet National Security Vetting requirements, you must have resided in the UK for a minimum of 3 out of the past 5 years for SC clearance. Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role - will still be considered. Please make sure you meet these requirements before applying for this role. You dont need to have SC already, however, failure to achieve the requirements for SC after offer, will result in the job offer being withdrawn. Job description Job responsibilities Please see the attached Job Description and Person Specification for more information about the role and responsibilities. Please ensure your supporting statement includes demonstratable evidence and specific examples on how you meet the criteria for each of the key skills specified. This will be used in both the shortlisting and interview processes Important: Please be aware there are residency requirements you need to meet: All NHS England Cyber Security personnel must hold security clearance SC level as a minimum. To meet National Security Vetting requirements, you must have resided in the UK for a minimum of 3 out of the past 5 years for SC clearance. Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role - will still be considered. Please make sure you meet these requirements before applying for this role. You dont need to have SC already, however, failure to achieve the requirements for SC after offer, will result in the job offer being withdrawn. Person Specification Knowledge & Experience Essential Working knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organisational network operation and minimise negative effect by cybersecurity risks Extensive knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply this knowledge appropriately to diverse situations. Skills Essential Proven knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organisational data. Proven knowledge of techniques, approaches, and processes of digital threats; ability to detect, monitor, analyse and prevent digital threats. Qualifications Essential Certified Information Systems Security Professional (CISSP) - or equivalent knowledge Certified in Risk and Information Systems Control (CRISC) - or equivalent knowledge Person Specification Knowledge & Experience Essential Working knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organisational network operation and minimise negative effect by cybersecurity risks Extensive knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply this knowledge appropriately to diverse situations. Skills Essential Proven knowledge of the processes, tools and techniques of information security management, ability to deploy and monitor information security systems, as well as detect, resolve and prevent violations of IT security, to protect organisational data. Proven knowledge of techniques, approaches, and processes of digital threats; ability to detect, monitor, analyse and prevent digital threats. Qualifications Essential Certified Information Systems Security Professional (CISSP) - or equivalent knowledge Certified in Risk and Information Systems Control (CRISC) - or equivalent knowledge Disclosure and Barring Service Check This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions. Certificate of Sponsorship Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab). From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab). Additional information Disclosure and Barring Service Check This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions. Certificate of Sponsorship Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab). From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab). Employer details Employer name NHS England Address Wellington Place, Leeds / Hexagon House, Exeter Leeds/Exeter LS1 4AP Employer's website https://www.england.nhs.uk/about/working-for/ (Opens in a new tab)