Skip to main content

This site is independent of the NHS and the Department of Health.

Please wait, loading

Job summary

Main area
Cyber Security
Grade
NHS AfC: Band 6
Contract
Permanent
Hours
  • Full time
  • Flexible working
  • Compressed hours
37.5 hours per week
Job ref
907-890
Employer
NICE - The National Institute for Health and Care Excellence
Employer type
NHS
Site
3rd Floor, 3 Piccadilly Place
Town
Manchester
Salary
£39,959 - £48,117 per annum
Salary period
Yearly
Closing
05/07/2026 23:59

Employer heading

NICE - The National Institute for Health and Care Excellence logo

Cyber Security Specialist (Governance, Risk & Compliance)

NHS AfC: Band 6

The National Institute for Health and Care Excellence (NICE) is the independent organisation responsible for providing national guidance and advice on promoting high quality health, public health and social care.

As an equal opportunities employer we are committed to creating a inclusive environment and welcome everyone from all backgrounds to apply so we can continue to create a workforce which is representative of the communities we serve.

If you are suitably qualified and have an interest in remote, hybrid, full time or part time working we encourage you to get in touch as we are happy to discuss potential flexible working opportunities.

We have modern offices in Manchester city centre and Stratford, London.  Please take into consideration that you may be required to commute to one of our offices for business purposes if necessary.

Job overview

Do you want to do meaningful work that makes a genuine difference to society? Our main purpose here at The National Institute for Health and Care Excellence (NICE) is to improve health and wellbeing by putting science and evidence at the heart of health and care decision-making.  As an organisation we all collaborate to achieve this goal by empowering our workforce to do great things!  


Please note that this role may not be eligible for sponsorship under the Skilled Worker route. Please refer to the DirectGov website for more information on eligibility. 


We reserve the right to close adverts early should we receive sufficient applications, so please don’t delay your submission. 

Main duties of the job

The Cyber Security Specialist (Governance, Risk & Compliance) plays a key role in protecting NICE’s digital services, information, and systems by strengthening cyber security governance, managing risk, and ensuring compliance with recognised security standards. Working as part of the Infrastructure, Cyber & IT Operations team, you will help embed good security practices across the organisation, support assurance activities, and enable NICE to operate securely while delivering nationally important health and care services.


What you will do / bring to the role
•    Support the development, maintenance, and continuous improvement of cyber security governance frameworks, policies, and standards.

•    Identify, assess, and manage information and cyber security risks, including maintaining risk registers and supporting mitigation activities.
•    Contribute to compliance and assurance activities aligned to recognised frameworks and standards (such as ISO 27001 and NHS security requirements).

•    Work collaboratively with technical and non technical colleagues to provide clear, practical security advice and guidance.

•    Support audits, reviews, and reporting related to cyber security, risk, and compliance.

•    Help promote a strong security aware culture across the organisation through clear communication and engagement.

 

Working for our organisation

The Infrastructure, Cyber & IT Operations team plays a critical role in ensuring NICE’s digital services are secure, resilient, and reliable. The team is responsible for safeguarding systems and information, supporting users across the organisation, and maintaining operational stability with minimal risk or disruption. 


As part of this team, you will help protect nationally important digital services while enabling NICE to deliver trusted guidance and information to health and care users across England.

We are passionate and proud of the work we do and the impact we make. NICE offer:

  • Generous NHS Pension – Secure your future with one of the most rewarding pension schemes in the UK
  • Flexible working – Enjoy a healthy work-life balance with options like remote working, compressed hours and flexible start/finish times
  • Exclusive discounts – Save on shopping, dining and more with a Blue Light Card
    Time to recharge – Start with 27 days’ annual leave plus bank holidays
  • Inclusive staff networks – Join supportive communities like Women in NICE, Race Equality Network, Disability Advocacy and NICE and Proud – we celebrate diversity
  • Tailored development – Grow your career with personalised learning and development opportunities

If you feel this is the type of environment you will enjoy working in, apply today!

Detailed job description and main responsibilities

To be considered for this role, you should be able to particularly demonstrate the person specification criteria in the job advert in your application. However, applicants should be able to demonstrate all essential criteria through the entirety of the recruitment process to be considered for the job. Please see job description attached for full list of responsibilities.

Person specification

Education/Qualifications

Essential criteria
  • Degree level qualification or equivalent professional experience, with specialist knowledge in cyber security governance, risk and compliance gained through practical experience and training.

Experience

Essential criteria
  • Proven experience working in a cyber security or information assurance role with a clear focus on governance, risk management, compliance, and assurance activities.

Experience

Essential criteria
  • Practical experience conducting security risk assessments, business impact analyses, and reviewing the effectiveness of security controls to support informed risk decisions.

Skills/Knowledge

Essential criteria
  • Strong familiarity with key cyber security standards, frameworks, and regulatory requirements such as CAF, Cyber Essentials, DSPT, ISO 27001, and GDPR.

Skills/Knowledge

Essential criteria
  • Excellent written and verbal communication skills, with the ability to explain complex security risks clearly to both technical and non technical stakeholders and influence decision making.

Skills/Knowledge

Desirable criteria
  • Good understanding of core IT concepts including operating systems, networking, and cloud technologies (such as Azure or AWS), enabling robust and well informed risk assessment.

Employer certification / accreditation badges

Disability confident employerTime to changeHappy to Talk Flexible Working

Documents to download

Apply online now

Further details / informal visits contact

Name
Mark Perrett
Job title
AD, Infrastructure, Cyber & IT Operations
Email address
[email protected]
Apply online nowAlert me to similar vacancies