Search
Header navigation
Head of Cyber Security

Head of Cyber Security

remoteOn-Site
ExpiresExpires: Expiring in less than 3 weeks
IT
£88,920 - £98,801 per year

Summary

What you'll do

As the Head of Cyber Security, you will lead NHG Digital's cyber security domain, protecting our digital services, systems, suppliers, data flows and operational environments through clear strategy, standards, controls, monitoring, assurance and incident response.

You will own our cyber security policy, cyber risk position, control assurance and specialist security judgement, making cyber risk visible, understood and managed as a core business risk. You will ensure that security requirements are embedded across product, architecture, engineering, transition, operations, data, supplier and governance activity.

Working with senior leaders and teams across NHG, you will help protect residents, colleagues, services, data and public trust while enabling digital change to be delivered safely and responsibly.

How you'll do it

  • Lead and maintain NHG Digital's cyber security strategy, roadmap, policies, standards and control framework, aligned to our risk appetite, operating model, regulatory context and changing threat environment.
  • Own specialist cyber security assurance across products, platforms, integrations, infrastructure, suppliers, identity and access, privileged access, perimeter controls, vulnerability management, monitoring, incident response and recovery.
  • Embed security requirements early in product discovery, service design, architecture, DevOps delivery, supplier management, service transition and live operations.
  • Work with Digital Operations to ensure agreed controls are sustained across patching, vulnerability response, monitoring, privileged access, backup and recovery, incident response and operational resilience.
  • Lead cyber monitoring, threat awareness, incident preparation and major cyber incident response coordination, including playbooks, escalation routes, evidence capture and recovery expectations.
  • Provide clear and proportionate advice to senior leaders on cyber threats, control gaps, response options and residual risk.
  • Hold suppliers and managed service partners to account for cyber obligations, assurance evidence, access controls, incident notification, vulnerability remediation, penetration testing and ongoing compliance.
  • Build cyber security awareness and capability across NHG Digital, helping technical and non-technical colleagues understand their role in protecting residents, staff, data and services.

The ideal candidate

We believe great service starts with great people, and we are committed to recruiting and developing passionate, enthusiastic, and talented individuals who can add value to our thriving organisation.

Pending confirmation of legislative changes, this role may require a qualification to demonstrate competence. If not already qualified, there may be an expectation to study towards a professional qualification.

Essential:

  • Pending confirmation of legislative changes, this role may require a qualification to demonstrate competence. If not already qualified, there may be an expectation to study towards a professional qualification.
  • Substantial experience leading cyber security, information security, security operations, cyber risk, security assurance or resilience within a complex, regulated or similarly accountable environment.
  • Strong knowledge of cyber security strategy, policy, standards, management, controls, assurance, risk monitoring, vulnerability management, response and recovery. incident.
  • Proven ability to define and maintain proportionate cyber security controls across identity, access, perimeter security, privileged cloud, access, platforms, infrastructure, applications, integrations, suppliers and live operational environments.
  • Experience embedding security requirements into product discovery, architecture, DevOps delivery, supplier management, service transition, change control and live operations.
  • Ability to assess and explain cyber risk, control gaps, residual-risk options and assurance evidence clearly to senior leaders, technical specialists, service owners and non-technical stakeholders.
  • Experience leading or coordinating cyber incident preparation and response, including playbooks, escalation routes, evidence capture, communication principles, recovery expectations and lessons learned.
  • Good understanding of data protection, privacy, records management, business continuity, operational resilience, supplier assurance, responsible AI, auditability and regulatory expectations in a digital service environment.
  • Experience holding suppliers and managed service partners to account for security obligations, assurance evidence, access controls, incident notification, vulnerability remediation, penetration testing, contractual controls and ongoing compliance.
  • Strong communication and influencing skills, with the ability to promote security awareness, advise senior leaders, challenge constructively and translate technical security issues into practical business risk decisions.
  • Visible, values-led leadership style, with the ability to build capability, support teams under pressure, escalate appropriately and create an inclusive, accountable and security-aware culture.

What's in it for you?

Once you join us, you'll find plenty of opportunities to grow within our organisation. You'll also have access to a wide range of learning opportunities to help you achieve and maximise your potential.

Benefits include:

  • Excellent annual leave allowance and flexible working opportunities (qualifying period may apply)
  • Generous pension scheme
  • Enhanced maternity, paternity, and adoption pay in addition to statutory entitlements (qualifying period may apply)
  • Employee assistance - free confidential advice and counselling services provided by independent specialist organisations.
  • Health cash plan
  • Staff discounts - we give our staff access to discounts at hundreds of major retailers, gyms, restaurants, entertainment, days out, insurance, and much more.
  • Interest free loans - season ticket loan, tenancy deposit loan, and training loan
  • Cycle to work scheme.
  • Life Assurance x 4 annual salary

All about us

Notting Hill Genesis is a not-for-profitorganisation providing affordable homes for Londoners and it is now one of thelargest housing associations in London. We are both alandlord and a developer, with more than 65,000 existing homes and we employaround 1,800 employees.

For more information on what we do and what makes us different please visit:https://group.nhg.org.uk/careers/

We welcome applications from everyone. We actively monitor the diversity of our workforce and strive to show equal representation throughout all levels of the organisation. We are a Stonewall Diversity Champion, a Disability Confident employer amongst other diversity commitments.

To find out more about our approach to equality, diversity and inclusion please visit: https://group.nhg.org.uk/careers/diversity-is-our-strength/

Selection Process

Step 1: If you are interested, please send your application now!

Step 2: Successful candidates will be asked to do an assessment  

Step 3: Successful candidates will be invited to interview  

Please apply for this role online. If you are not able to apply online or if you have any reasonable adjustment requirements arising from a disability or medical condition to fully participate in the recruitment process, please discuss this with our hiring team via .  

NHG reserves the right to close this vacancy early if we receive sufficient applications for the role, so we advise you to submit your application at your earliest opportunity.

Salary range

  • £88,920 - £98,801 per year