Job summary
Looking to challenge and develop yourself and give back to the NHS and UK society?
To meet the demands of HM Government Cyber Security strategy 2022, we are looking for a security architect to assist prioritisation of security 1st across our extensive transformation, modernisation, and delivery portfolio.
You will, working collaboratively with business areas, be able to understand, develop, shape, and provide benefit to our applications, services, and systems to reduce costs. Whilst enabling open, modern secure digital services and protecting in the constantly changing risk profile of the interconnected world and bring improvements to Citizens and NHS consumers.
NHS Business Services Authority (https://www.nhsbsa.nhs.uk) is the provider of at scale business services to the NHS, running a portfolio of services managing over £35 billion on behalf of the NHS. It has an excellent reputation with clients and its growing service portfolio.
What do we offer?
o 27 days leave (increasing with length of service) plus 8 bank holidays
o Flexible working (we are happy to discuss options such as compressed hours)
o Hybrid working model (we are currently working largely remotely)
o Career development
o Active wellbeing and inclusion networks
o Excellent pension
o NHS Car lease scheme
o Access to a wide range of benefits and high street discounts!
Main duties of the job
- Working within the Cyber Security Architecture & Operations Team. Getting involved and working across the organisation and especially with teams within the Digital, Data and Technology directorate such as Infrastructure, Platform and Software developers, as well as other major stakeholders such as Information Security & Governance teams and Managed Service Providers.
- Actively reviewing and developing processes to ensure the security of NHS BSA network infrastructure and information systems, as well as, maintaining a solid knowledge of NHS BSA information security principles and practices to ensure timely technical support, advice, guidance and consultancy is provided to satisfy business needs.
- Assisting with maintaining the organisations Cyber Security Risk Register, Security Improvement Program and implementing NHS BSA Cyber security strategy to continuously improve the organisations security position.
- Working under general direction and within a clear framework of accountability you will exercise substantial personal responsibility and autonomy to plan own workloads to meet objectives and delivery timeframes.
About us
At the NHS Business Services Authority (NHSBSA) we deliver a range of essential national services to NHS organisations and contractors, patients and the public.
You may already be using some of our services. Do you have a prescription pre-payment certificate? Perhaps you found this vacancy through NHS Jobs? We're behind these, and much, much more.
Being one of the UK's Best Big Companies to work for, our values are to be Collaborative, Adventurous, Reliable and Energetic. We CARE about what we do and support each other in achieving our objectives.
Our people are the heart of our organisation. We strive to ensure they feel trusted, valued and empowered. We're passionate about nurturing and developing people. When you join us, we want you to grow, and we offer many opportunities for you to do that.
We welcome applications from people of all backgrounds. With wellbeing and inclusion central to our ethos, our BAME, Disability and Neurodiversity, LGBTQ+, Armed Forces and Women's networks help our colleagues to be their authentic selves at work.
At the NHSBSA we value and respect the diversity of our colleagues and are committed to being a flexible employer. We are proud to offer flexible working opportunities. Whether you're interested in hybrid working, working from home, flexible hours or job sharing, apply today and we can discuss available options with you at the interview stage.
We are the NHS delivering for the NHS.
Visit www.nhsbsa.nhs.uk/work-with-us and start your career.
Job description
Job responsibilities
The security architect is a key role within the NHSBSA ICT Security Operations team with accountability for the definition of the security solutions and Security architecture for applications, information, and infrastructure as NHSBSA transforms the underlying IT supporting the business.
The role is responsible for security architecture, and security posture providing advice, guidance and consultancy input into new and existing IT solutions fully exploiting the opportunities of emerging technologies as the NHSBSA transforms the way it provides services.
You will engage and collaborate with a wide range of stakeholders, including senior stakeholders, across all departments and communities. Integrating with external and internal providers, including customers, peers, and other organisations, to build effective relationships to enablingmodern secure and open digital services, ensuring customer data and other assets are protected.
You will be accountable for the control of the IT Security Blueprints which define the end state architecture, current state and the transition roadmaps for the NHSBSA. This includes supporting the creation and execution of technology and service roadmaps that will drive the NHSBSAs current IT estate towards cloud technology for strategic systems whilst decommissioning legacy systems.
You will be actively involved in creating and maintaining IT security requirements for procuring IT services and the selection of 3rd party providers delivering IT services and working closely with them to provide solutions for the Business.
The post holder may be required to work across the NHSBSAs locations and will therefore be required to undertake a degree of travel across thecountry.
Please see our job description and person specification for full details.
In this role, you are responsible for:
Security Architecture/Operations1. Collaborate to define as-is and to-be architectures to develop full technical solutions designs including preparation of technical artefacts, and blueprints, providing a high quality security proposal for submission into internal and external business cases and assessments.
- Undertake and lead on investigative analysis within multidisciplinary teams, providing technical authority, making credible and practical technical decisions, communicating these with sensitivity and diplomacy to ensure the right technical direction is followed.
- Working across/within different programmes and across different layers of architecture as needed and to translate business security requirements into IT services, solutions, investment and migration roadmap. Taking a major role to identify and share good security practices, participating in relevant communities of practice to drive adoption of design standards, trends and patterns.
- Take ownership of particular areas of the business service, project or programme IT security architecture and ensure consistency with the Enterprise Architecture, HMG Security Strategy, HMG Digital Strategy and DH Digital Strategy and provides input into IT Strategy.
- Monitoring the development of new and emerging tools, technologies and products to assess potential value and identifying opportunities to enhance security capabilities for products and services used within the organisation.
- Responsible for the security blueprint solutions for complex protective and vulnerability security management of both physical and data assets clearly defining the as-is and to-be security architectures and document the transition to the to-be solution and its integration in the overall Enterprise and Security Architecture blueprints.
Staff Management
- Management of staff including all line management responsibilities, performance management, appraisals, disciplinary, and standard HR processes for Security operations.
- Undertake recruitment and selection in line with organisational processes and participate in the implementation and delivery of initiatives to secure suitable resources, increase skills levels and develop talent pools to meet the changing needs of the business landscape.
- Seeking, providing and taking feedback to support and encourage teams and individuals to develop thinking and independently work through issues, to reach solutions-based outcomes. Taking full accountability for the approach and decision-making practices within area, including providing positive challenge to ideas and solutions.
- Responsible for prioritising and planning own whilst contributing to the teams work and providing input to the prioritisation of projects and programmes proposed and/or underway.
Financial Management11. Maintain an awareness of financial and personal implications in the use of a range of resources.
- Responsibility for contributing to budget management processes in accordance with NHSBSAs policies, standing orders, financial regulations and legislative requirements.
- Develop proposals for future investment including both technology refresh and project- based change; preparing necessary estimates, mandates and business cases within the technology department and providing estimates for such led by other departments.
Knowledge Management14. Research of the marketplace and constant awareness of industry trends, threats and innovation using information to inform the ICT security strategy of the NHSBSA and as input to design activities.
- To work with NHSBSA staff and Third Parties to ensure that security policy, standards, governance, and processes are in place for producing and maintaining up to date, comprehensive, comprehensible documentation which will include IT service security blueprints for all systems and services.
Relationship Management16. Identify opportunities, engaging and fostering relationships and partnership working within the organisation, and with third parties, to identify and deliver value to the organisation.
- Working across/within different programmes and across different layers of architecture as needed and to translate business security requirements into IT services and solutions.
- Work with organisations external to the NHSBSA (e.g. the DHSC and GDS) when necessary to assist in clarifying their needs and requirements and be capable of devising options for security solutions, along with full assessment and cost estimation.
Information Management19. Handles sensitive commercial & financial information, ensuring that the security solution architectural designs adhere to relevant legislation and standards including for example, Information Security, NHS Confidentiality and Data Protection legislation.
- Implement, monitor and report on a number of areas including agreed service levels, KPI's and standards within security operations.
- Monitor, report, present or escalate issues as appropriate to the Security Operations Manager
Delivery Management22. Operate as an SME and point of authority on security architecture, making credible, pragmatic and practical security decisions and communicate with sensitivity and diplomacy to ensure the right technical direction is followed and to guide the business to make the best use of its existing IT where appropriate and to make recommendation about what other IT assets it needs to invest in.
- To demonstrate creativity and innovation in applying IT solutions and services to develop and improve services and quality for the benefit of the organization and/or the end user of technology services. This includes devising and managing security initiatives to enable exploitation ofdigital services, capacity, performance, and system availability improvements that ensure business targets are met or exceeded and legacy services decommissioned, whilst ensuring data security and controlled access to data.
- Responsible for providing expert help and guidance across the lifecycle of a security solution implementation, including technical and nontechnical aspects. This includes the migration of services across suppliers and closely with Technical Architects ensuring the solution and service design is successfully translated, built delivered and operated to meet security and business requirements
- Input into workforce planning, ensuring required operational commitments are fully met, business change is estimated, prioritised, and delivered, resourcing issues are identified, mitigated and managed to deliver business value.
- Manage, and input into the development and implementation of approaches, strategies, policies, standards and practices across the team, ensuring and monitoring the timely delivery of business objectives within budget through the management of projects and programmes.
- To identify and interpret DHSC, GDS, local and national security policy changes and directives, and assess the impact on IT Infrastructure and surrounding processes, including influencing policy information within own security specialism.
- Produce and deliver in depth reports and/or presentations to NHSBSA, HMG or DHSC stakeholders staff and external parties, on any aspect of the work delivered.
In addition to the above accountabilities, as post holder you are expected to:Undertake additional duties and responsibilities in line with the overall purpose of your role and as agreed by your line manager.
Demonstrate NHSBSA values and core capabilities in all aspects of your work.
Foster an environment where your own and colleagues safety and well-being is promoted.
Contribute to a culture which values diversity and inclusion.
Comply with NHSBSA policies, procedures, and protocols as they apply to your role.
Have SC clearance or willing to undergo clearance following appointment to post.
Deputise for the Security Operations Manager as required
Job description
Job responsibilities
The security architect is a key role within the NHSBSA ICT Security Operations team with accountability for the definition of the security solutions and Security architecture for applications, information, and infrastructure as NHSBSA transforms the underlying IT supporting the business.
The role is responsible for security architecture, and security posture providing advice, guidance and consultancy input into new and existing IT solutions fully exploiting the opportunities of emerging technologies as the NHSBSA transforms the way it provides services.
You will engage and collaborate with a wide range of stakeholders, including senior stakeholders, across all departments and communities. Integrating with external and internal providers, including customers, peers, and other organisations, to build effective relationships to enablingmodern secure and open digital services, ensuring customer data and other assets are protected.
You will be accountable for the control of the IT Security Blueprints which define the end state architecture, current state and the transition roadmaps for the NHSBSA. This includes supporting the creation and execution of technology and service roadmaps that will drive the NHSBSAs current IT estate towards cloud technology for strategic systems whilst decommissioning legacy systems.
You will be actively involved in creating and maintaining IT security requirements for procuring IT services and the selection of 3rd party providers delivering IT services and working closely with them to provide solutions for the Business.
The post holder may be required to work across the NHSBSAs locations and will therefore be required to undertake a degree of travel across thecountry.
Please see our job description and person specification for full details.
In this role, you are responsible for:
Security Architecture/Operations1. Collaborate to define as-is and to-be architectures to develop full technical solutions designs including preparation of technical artefacts, and blueprints, providing a high quality security proposal for submission into internal and external business cases and assessments.
- Undertake and lead on investigative analysis within multidisciplinary teams, providing technical authority, making credible and practical technical decisions, communicating these with sensitivity and diplomacy to ensure the right technical direction is followed.
- Working across/within different programmes and across different layers of architecture as needed and to translate business security requirements into IT services, solutions, investment and migration roadmap. Taking a major role to identify and share good security practices, participating in relevant communities of practice to drive adoption of design standards, trends and patterns.
- Take ownership of particular areas of the business service, project or programme IT security architecture and ensure consistency with the Enterprise Architecture, HMG Security Strategy, HMG Digital Strategy and DH Digital Strategy and provides input into IT Strategy.
- Monitoring the development of new and emerging tools, technologies and products to assess potential value and identifying opportunities to enhance security capabilities for products and services used within the organisation.
- Responsible for the security blueprint solutions for complex protective and vulnerability security management of both physical and data assets clearly defining the as-is and to-be security architectures and document the transition to the to-be solution and its integration in the overall Enterprise and Security Architecture blueprints.
Staff Management
- Management of staff including all line management responsibilities, performance management, appraisals, disciplinary, and standard HR processes for Security operations.
- Undertake recruitment and selection in line with organisational processes and participate in the implementation and delivery of initiatives to secure suitable resources, increase skills levels and develop talent pools to meet the changing needs of the business landscape.
- Seeking, providing and taking feedback to support and encourage teams and individuals to develop thinking and independently work through issues, to reach solutions-based outcomes. Taking full accountability for the approach and decision-making practices within area, including providing positive challenge to ideas and solutions.
- Responsible for prioritising and planning own whilst contributing to the teams work and providing input to the prioritisation of projects and programmes proposed and/or underway.
Financial Management11. Maintain an awareness of financial and personal implications in the use of a range of resources.
- Responsibility for contributing to budget management processes in accordance with NHSBSAs policies, standing orders, financial regulations and legislative requirements.
- Develop proposals for future investment including both technology refresh and project- based change; preparing necessary estimates, mandates and business cases within the technology department and providing estimates for such led by other departments.
Knowledge Management14. Research of the marketplace and constant awareness of industry trends, threats and innovation using information to inform the ICT security strategy of the NHSBSA and as input to design activities.
- To work with NHSBSA staff and Third Parties to ensure that security policy, standards, governance, and processes are in place for producing and maintaining up to date, comprehensive, comprehensible documentation which will include IT service security blueprints for all systems and services.
Relationship Management16. Identify opportunities, engaging and fostering relationships and partnership working within the organisation, and with third parties, to identify and deliver value to the organisation.
- Working across/within different programmes and across different layers of architecture as needed and to translate business security requirements into IT services and solutions.
- Work with organisations external to the NHSBSA (e.g. the DHSC and GDS) when necessary to assist in clarifying their needs and requirements and be capable of devising options for security solutions, along with full assessment and cost estimation.
Information Management19. Handles sensitive commercial & financial information, ensuring that the security solution architectural designs adhere to relevant legislation and standards including for example, Information Security, NHS Confidentiality and Data Protection legislation.
- Implement, monitor and report on a number of areas including agreed service levels, KPI's and standards within security operations.
- Monitor, report, present or escalate issues as appropriate to the Security Operations Manager
Delivery Management22. Operate as an SME and point of authority on security architecture, making credible, pragmatic and practical security decisions and communicate with sensitivity and diplomacy to ensure the right technical direction is followed and to guide the business to make the best use of its existing IT where appropriate and to make recommendation about what other IT assets it needs to invest in.
- To demonstrate creativity and innovation in applying IT solutions and services to develop and improve services and quality for the benefit of the organization and/or the end user of technology services. This includes devising and managing security initiatives to enable exploitation ofdigital services, capacity, performance, and system availability improvements that ensure business targets are met or exceeded and legacy services decommissioned, whilst ensuring data security and controlled access to data.
- Responsible for providing expert help and guidance across the lifecycle of a security solution implementation, including technical and nontechnical aspects. This includes the migration of services across suppliers and closely with Technical Architects ensuring the solution and service design is successfully translated, built delivered and operated to meet security and business requirements
- Input into workforce planning, ensuring required operational commitments are fully met, business change is estimated, prioritised, and delivered, resourcing issues are identified, mitigated and managed to deliver business value.
- Manage, and input into the development and implementation of approaches, strategies, policies, standards and practices across the team, ensuring and monitoring the timely delivery of business objectives within budget through the management of projects and programmes.
- To identify and interpret DHSC, GDS, local and national security policy changes and directives, and assess the impact on IT Infrastructure and surrounding processes, including influencing policy information within own security specialism.
- Produce and deliver in depth reports and/or presentations to NHSBSA, HMG or DHSC stakeholders staff and external parties, on any aspect of the work delivered.
In addition to the above accountabilities, as post holder you are expected to:Undertake additional duties and responsibilities in line with the overall purpose of your role and as agreed by your line manager.
Demonstrate NHSBSA values and core capabilities in all aspects of your work.
Foster an environment where your own and colleagues safety and well-being is promoted.
Contribute to a culture which values diversity and inclusion.
Comply with NHSBSA policies, procedures, and protocols as they apply to your role.
Have SC clearance or willing to undergo clearance following appointment to post.
Deputise for the Security Operations Manager as required
Person Specification
Qualifications
Essential
- An IT related degree or equivalent Industry Recognised Qualifications e.g. CISSP, CISMP, CCP, ISO 27001 implementer.
- plus significant demonstrable experience in two of the of the following: o IT Security Architecture o Working in a number of complementary security roles o System and Service Architecture Design OR Significant demonstrable experience over a number of years in at least three of the following: o IT Security Architecture o HMG Information Standards and best practice o Working in a number of complementary security roles o System and Service Architecture Design o Management of a significant demonstrable experience over a number of years in at least three of the following: o IT Security Architecture o HMG Information Standards and best practice o Working in a number of complementary security roles o System and Service Architecture Design o Management of a s significant ICT implementation
Desirable
- TOGAF/SABSA Certification or equivalent, or willing to work towards this certification CESG Certified Professional (CCP) Senior IA Architect Experience of working in an agile environment and experience with agile methodologies such as Scrum, Kanban ITIL Certification ISO27001 Implementer/ Auditor
Personal Qualities, Knowledge and Skills
Essential
- Business change, rationalisation and transformation and implementation of strategic approaches, plans, activities and solutions.
- Evaluation, interpretation, translation and communication of complex data/information from multiple sources and requirements to inform decision making.
- Design of cost effective and scalable enterprise solutions, from development through to implementation in a multi-supplier environment.
- Proven experience in developing and implementing security solution and enterprise architecture and design strategies in a multi supplier environment.
- Proven ability to undertake detailed security analysis of technical designs and provide the business with security assurance of supplier designs and proposals
- Broad technical knowledge covering web applications and services, information, infrastructure, cloud and managed service architectures. Knowledge of GDS Principles, NCSC guidance and familiarity with the requirements of the Government Security Classifications and NHS DSPT. Knowledge, and ideally experience, of emerging security technologies to mainstream business, such as: o Vulnerability management o Secure Baseline configuration o Logging o Incident response o Security Analytics o Identity access management Experience of effective stakeholder management
Desirable
- Enterprise architecture components and frameworks experience such as TOGAF, SABSA. Recent and demonstrable Team and Line Management experience
- A variety of approaches to hosted solutions and data centres including co-Location (and integration into Service Management models) Working to GDS Principles and/or having participated in GDS assessments
Experience
Essential
- Knowledge & experience of the following : Engaging and building relationships with a range of stakeholders to support delivery of business outcomes Creatively interpreting strategy and translate emerging trends and technologies to design innovative security solutions and controls which benefit the organisation, reducing risk and enable opportunity. Complex system, information and security solution design.
- Knowledge & experience of the following :Developing and implementing security solution and enterprise architecture and design strategies in a multi supplier environment Comprehensive and recent experience in architecting security solutions in high-volume digital services Demonstrate detailed understanding of the security implications and appropriate security controls of hosting sensitive information in large scale UK Cloud based cloud infrastructure environments
- Knowledge & experience of the following :Ability to demonstrate a deep knowledge of security and privacy risks and threats along with a strong understanding of key considerations such as confidentiality, availability, integrity, non-repudiation and privacy. HMG cyber security policy, such as, NCSC guidance, Technology codes of practice and minimum security standards
Desirable
- Transition of legacy services into digital cloud-based solutions Team and Line Management, including staff development
- Open source and cloud technologies and their sourcing. Experience of migrating services across different Data Centre locations and legacy application consolidation Solution and service design and delivery within an Agile development environment.
- Hosted solutions, services and data centres including co-Location (and integration into SIAM Service Management models)
Person Specification
Qualifications
Essential
- An IT related degree or equivalent Industry Recognised Qualifications e.g. CISSP, CISMP, CCP, ISO 27001 implementer.
- plus significant demonstrable experience in two of the of the following: o IT Security Architecture o Working in a number of complementary security roles o System and Service Architecture Design OR Significant demonstrable experience over a number of years in at least three of the following: o IT Security Architecture o HMG Information Standards and best practice o Working in a number of complementary security roles o System and Service Architecture Design o Management of a significant demonstrable experience over a number of years in at least three of the following: o IT Security Architecture o HMG Information Standards and best practice o Working in a number of complementary security roles o System and Service Architecture Design o Management of a s significant ICT implementation
Desirable
- TOGAF/SABSA Certification or equivalent, or willing to work towards this certification CESG Certified Professional (CCP) Senior IA Architect Experience of working in an agile environment and experience with agile methodologies such as Scrum, Kanban ITIL Certification ISO27001 Implementer/ Auditor
Personal Qualities, Knowledge and Skills
Essential
- Business change, rationalisation and transformation and implementation of strategic approaches, plans, activities and solutions.
- Evaluation, interpretation, translation and communication of complex data/information from multiple sources and requirements to inform decision making.
- Design of cost effective and scalable enterprise solutions, from development through to implementation in a multi-supplier environment.
- Proven experience in developing and implementing security solution and enterprise architecture and design strategies in a multi supplier environment.
- Proven ability to undertake detailed security analysis of technical designs and provide the business with security assurance of supplier designs and proposals
- Broad technical knowledge covering web applications and services, information, infrastructure, cloud and managed service architectures. Knowledge of GDS Principles, NCSC guidance and familiarity with the requirements of the Government Security Classifications and NHS DSPT. Knowledge, and ideally experience, of emerging security technologies to mainstream business, such as: o Vulnerability management o Secure Baseline configuration o Logging o Incident response o Security Analytics o Identity access management Experience of effective stakeholder management
Desirable
- Enterprise architecture components and frameworks experience such as TOGAF, SABSA. Recent and demonstrable Team and Line Management experience
- A variety of approaches to hosted solutions and data centres including co-Location (and integration into Service Management models) Working to GDS Principles and/or having participated in GDS assessments
Experience
Essential
- Knowledge & experience of the following : Engaging and building relationships with a range of stakeholders to support delivery of business outcomes Creatively interpreting strategy and translate emerging trends and technologies to design innovative security solutions and controls which benefit the organisation, reducing risk and enable opportunity. Complex system, information and security solution design.
- Knowledge & experience of the following :Developing and implementing security solution and enterprise architecture and design strategies in a multi supplier environment Comprehensive and recent experience in architecting security solutions in high-volume digital services Demonstrate detailed understanding of the security implications and appropriate security controls of hosting sensitive information in large scale UK Cloud based cloud infrastructure environments
- Knowledge & experience of the following :Ability to demonstrate a deep knowledge of security and privacy risks and threats along with a strong understanding of key considerations such as confidentiality, availability, integrity, non-repudiation and privacy. HMG cyber security policy, such as, NCSC guidance, Technology codes of practice and minimum security standards
Desirable
- Transition of legacy services into digital cloud-based solutions Team and Line Management, including staff development
- Open source and cloud technologies and their sourcing. Experience of migrating services across different Data Centre locations and legacy application consolidation Solution and service design and delivery within an Agile development environment.
- Hosted solutions, services and data centres including co-Location (and integration into SIAM Service Management models)
Additional information
Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).
From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).