Principal Cyber Security Adviser
Listed on 2026-01-14
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
This role sits within the Joint Cyber Unit (JCU), a collaboration between the Department of Health and Social Care (DHSC) and NHS England (NHSE). The JCU is embedded within the Digital Policy Unit (DPU), a unit comprising both DHSC staff and NHSE staff intended to design, plan and build a digitally enabled, data driven and safe health and social care system with ministers and the NHS.
The purpose of the JCU is to provide strategic leadership in cyber security across the health and care sector, assure the cyber security of the sector, act as system stewards to improve cyber resilience across the health and care system and to provide advice which empowers health and care staff to share information appropriately and securely to deliver care.
The JCU sets, develops, and implements strategy, policy and standards for cyber security across the NHS and Adult Social Care in England. It has responsibility for designing, implementing and the ongoing assurance of the cyber security system risk management and compliance framework in place across the wider health and care system.
The JCU is comprised of two divisions:
- Governance, Risk and Compliance - cyber and information governance, system engagement, system compliance, system supply chain, system risk management and internal JCU business operations.
- Strategy and Policy - development and implementation of national strategy, policy and regulation.
The Principal Cyber Security Adviser post sits within the Governance, Risk and Compliance division in the System Cyber Risk and Assurance function which is responsible for managing cyber risk across the health and care system, ensuring that we operate within the appetite set by both the NHSE and DHSC board.
As a Principal Cyber Security Adviser assigned to lead the cyber risk assessment capability, the post holder will work as part of a dynamic team in delivering an effective service supporting managers and staff across the Joint Cyber Unit to:
- Provide expert level subject matter knowledge in the cyber security area from both a technical and a business perspective to advise on issues across the cyber security domain and all activity across the Joint Cyber Unit.
- Establish and oversee process for assessing cyber risk and advising proportionate national interventions, including funding and regulatory levers, across the system.
- Lead the development of risk assessments into flagged scenarios and make recommendations as to how risk is best managed, articulating recommendation verbally and in writing, potentially to senior audiences.
- Lead on the reporting to the National Chief Information Security Officer on system cyber risk through development and oversight of a system cyber risk scenario library, drawing on support from the cyber risk intelligence and cyber governance teams.
The post holder should have expertise in managing cyber security risks in large and complex environments and should be able to evidence their commitment to continuing professional development. This is a lead role within the risk and assurance function, and the post holder will need line management experience and the ability to deal with competing priorities and tight deadlines.
They should have the ability to build and maintain strong working relationships with other teams and be able to communicate cyber security risk topics to a range of stakeholders (both technical and non‑technical).
The post holder will provide efficient, effective and high quality, professional and well‑co‑ordinated cyber security leadership meeting all statutory, regulatory and NHS requirements ensuring alignment with the activity of the organisation.
- Establishing and leading a capability to assess system cyber risk and recommending proportionate national interventions (e.g. regulatory action, funding decisions, and technical support) to manage it.
- Delivering risk assessments, potentially to extremely tight timescales and with limited information, including recommendations on how to proportionally manage the risk.
- Contributing to Cyber Improvement programme where relevant to areas of responsibility.
- Building relationships across Joint Cyber…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: