Cyber Operations purpose is to support safe care and build public trust by building NHS England's cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate's purpose of delivering the best care and outcomes for the NHS.
The Cyber Operations sub-directorate consists of four operational areas:
The Senior Security Advisor (CISO) for Insider Risk sits within the CISO Security Assurance team, supporting NHS England to manage cyber and information security risk through assurance, monitoring and risk-led security activity.
The role will help develop our insider risk capability, using security telemetry, behavioural indicators and investigative tooling to identify, assess and respond to potential misuse, compromise or inappropriate access to NHS England systems and data.
Working with Cyber Operations, CSOC, governance, data protection, investigations, policy and personnel security teams, the post holder will support proportionate, evidence-led approaches to insider risk and personnel security.
Main duties include acting as a specialist escalation point for insider risk matters, providing technical advice, case support and judgement across complex or sensitive activity.
The role will use threat hunting, KQL and detection engineering to identify indicators of misuse, compromise, inappropriate access or unusual activity requiring review.
The post holder will analyse Microsoft Defender for Endpoint, Microsoft Purview, Azure AD sign‑in and other telemetry; support investigations; advise on monitoring, cloud controls, DLP, eDiscovery and tooling; improve workflows, playbooks and reporting; and identify control or response gaps.
The successful candidate will be an experienced cyber security professional with strong analytical, investigative and stakeholder engagement skills, able to apply technical expertise in a sensitive, proportionate and evidence‑led way.
They will understand insider risk across technology, people, process and trust, and bring the judgement, discretion, curiosity and resilience needed to handle sensitive matters in a complex national organisation.
This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.
All NHS England Cyber Security personnel must hold Security Clearance level as a minimum. To meet National Security Vetting requirements, SC clearances require 5 years continuous UK residency. In certain cases, this can be reduced to three years continuous UK residency, with additional overseas checks for the previous two years. Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role will still be considered.
The post of Senior Security Advisor (CISO) has been awarded a Recruitment and Retention Premia (RRP) in response to current labour market conditions. In recognition of this, the role attracts an additional monthly RRP payment equal to 20% per annum. RRP is non‑contractual and subject to review.
We cannot offer visa sponsorship for any vacancies.
NHS England
Wellington Place, Leeds / Hexagon House, Exeter / Wellington House, London
£69,033.60 to £77,700 a year (this includes an RRP payment of 20%) exclusive of HCAS.
Permanent
Full‑time
990‑TDD‑CY‑EC2599‑E
Wellington Place, Leeds / Hexagon House, Exeter / Wellington House, London