Digital Health and Care Wales

Security Specialist Design

The closing date is 17 June 2025

Job summary

The Cyber Security team are looking to recruit a specialist to join the team and work alongside lead roles and team members, in order to assist with the design, development & assurance of new services

What we are looking for

We are seeking candidates with the commitment, experience, skills and knowledge to provide the necessary level of cyber security involvement for services across NHS Wales. Candidates must be capable of managing the robust and consistent design and assurance required to support the delivery new digital services. Experienced in managing the delivery and provision of cyber security services within a large and complex organisation, you will have excellent planning and organization skills, coupled with practical knowledge of risk management methodology. An exceptional communicator, you shall be expected to establish working relationships with staff at all levels within DHCW, including clinicians and the wider user community.

Main duties of the job

As a specialist, you will primarily be responsibility for the workstream within the national assurance group, ensuring that all proposals receive a thorough review to identify all necessary cyber security activities and are fully integrated within the internal risk management process.

This role will also be responsible for ensuring the correct implementation of the cyber security strategies to enhance the protection of critical national infrastructure and clinically critical applications. Working closely with stakeholders at all levels within local Health Boards / Trusts, other public sector organisations in Wales, and security professionals throughout the UK in order to ensure that our systems are positioned to proactively identify, respond, recover and ultimately defend against Cyber related threats.

About us

Digital Health and Care Wales (DHCW) is an expert national body and part of NHS Wales. We work in partnership with NHS Wales colleagues and other key stakeholders to provide national digital and data services which support the delivery of health and social care in Wales. Modern health and care services depend on good digital tools, data and information. DHCW runs or works with more than 100 services and delivers major national digital transformation programmes to support this. In addition, DHCW provides expert advice in relation to cyber security and information governance. We give frontline staff the digital tools which help them provide safer and more efficient care. We are also giving patients and the public digital tools to better manage their own health and wellbeing, empowering people to live healthier lives. We put people at the heart of what we do, working to the highest standards to deliver quality and make digital a force for good in health and care.

Working for DHCW offers lots of employee benefits, including flexible working, a competitive salary, 28 days of annual leave plus Bank Holidays and opportunities for career development. We are committed to recognising and celebrating our staff as the most valuable part of our organisation.

Details

Date posted

03 June 2025

Pay scheme

Agenda for change

Band

Band 7

Salary

£46,840 to £53,602 a year per annum

Contract

Permanent

Working pattern

Full-time, Flexible working

Reference number

025-AC119-0625

Job locations

Hybrid working

Location to be confirmed at interview

CF11 9AD


Job description

Job responsibilities

You will be able to find a full Job description and Person Specification attached within the supporting documents or please click Apply now to view in Trac

We are looking for candidates who can demonstrate proven experience and strong skills in the following areas:

  • A good understand of cyber security design process and have the ability to take a structured approach when reviewing system design.

  • A strong technical background - including networking, computing, software development, systems integration and compliance frameworks.

  • Formal qualifications in cyber security.

  • An understanding of malicious attack processes along with the ability to verify services for vulnerabilities that might allow those attack to be achieved.

  • Good verbal and written communications skills and must understand when to escalate concerns to line manager.

  • The ability to work to very tight deadlines and work proactively under pressure

  • Deliver projects and work packages against individual and team Key Performance Indicators

  • Proven ability to manage large scale Cyber Security projects, and appropriate communications

  • A good understanding of best practice security controls for market leading technologies

  • Must be keen and proactive and able to work on your own initiative.

Job description

Job responsibilities

You will be able to find a full Job description and Person Specification attached within the supporting documents or please click Apply now to view in Trac

We are looking for candidates who can demonstrate proven experience and strong skills in the following areas:

  • A good understand of cyber security design process and have the ability to take a structured approach when reviewing system design.

  • A strong technical background - including networking, computing, software development, systems integration and compliance frameworks.

  • Formal qualifications in cyber security.

  • An understanding of malicious attack processes along with the ability to verify services for vulnerabilities that might allow those attack to be achieved.

  • Good verbal and written communications skills and must understand when to escalate concerns to line manager.

  • The ability to work to very tight deadlines and work proactively under pressure

  • Deliver projects and work packages against individual and team Key Performance Indicators

  • Proven ability to manage large scale Cyber Security projects, and appropriate communications

  • A good understanding of best practice security controls for market leading technologies

  • Must be keen and proactive and able to work on your own initiative.

Person Specification

Qualifications and Knowledge

Essential

  • Educated to degree level (or equivalent qualification / experience) in an associated professional field
  • Technical knowledge of application and network security.

Desirable

  • Registered with a relevant informatics professional body
  • FEDIP Practitioner, or equivalent recognised Intermediate level Professional qualification.

Experience

Essential

  • Experience of conducing Cyber reviews of IT systems.
  • Experience of producing risk reports to a hight level and delivering them to project teams.

Desirable

  • A clear understanding and appreciation of NHS Wales' national infrastructure and organisational structures.
  • Experience of working in an NHS/Healthcare or Public Sector environment

Skills and Attributes

Essential

  • Excellent communication and interpersonal skills when dealing with highly technical and complex information to a wide range of stakeholders across organisational boundaries.
  • Confident in dealing with and resolving scenarios where people's opinions may conflict.

Desirable

  • Welsh language skills at level 1, or above
Person Specification

Qualifications and Knowledge

Essential

  • Educated to degree level (or equivalent qualification / experience) in an associated professional field
  • Technical knowledge of application and network security.

Desirable

  • Registered with a relevant informatics professional body
  • FEDIP Practitioner, or equivalent recognised Intermediate level Professional qualification.

Experience

Essential

  • Experience of conducing Cyber reviews of IT systems.
  • Experience of producing risk reports to a hight level and delivering them to project teams.

Desirable

  • A clear understanding and appreciation of NHS Wales' national infrastructure and organisational structures.
  • Experience of working in an NHS/Healthcare or Public Sector environment

Skills and Attributes

Essential

  • Excellent communication and interpersonal skills when dealing with highly technical and complex information to a wide range of stakeholders across organisational boundaries.
  • Confident in dealing with and resolving scenarios where people's opinions may conflict.

Desirable

  • Welsh language skills at level 1, or above

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).

Additional information

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).

Employer details

Employer name

Digital Health and Care Wales

Address

Hybrid working

Location to be confirmed at interview

CF11 9AD


Employer's website

https://nwis.nhs.wales/ (Opens in a new tab)

Employer details

Employer name

Digital Health and Care Wales

Address

Hybrid working

Location to be confirmed at interview

CF11 9AD


Employer's website

https://nwis.nhs.wales/ (Opens in a new tab)

Employer contact details

For questions about the job, contact:

Cyber Assurance Lead

Andy Shanahan

andy.shanahan@wales.nhs.uk

Details

Date posted

03 June 2025

Pay scheme

Agenda for change

Band

Band 7

Salary

£46,840 to £53,602 a year per annum

Contract

Permanent

Working pattern

Full-time, Flexible working

Reference number

025-AC119-0625

Job locations

Hybrid working

Location to be confirmed at interview

CF11 9AD


Supporting documents

Privacy notice

Digital Health and Care Wales's privacy notice (opens in a new tab)