Job summary
- Main area
- Digital
- Grade
- Band 8b
- Contract
- Permanent: The postholder will be required to travel across MIAA footprint and will be expected to work from client/office sites as and when required to meet the service needs of the organisation.
- Hours
- Full time
- Flexible working
- Job ref
- 287-MIAA-6-26
- Employer
- Liverpool University Hospitals NHS Foundation Trust
- Employer type
- NHS
- Site
- MIAA Regatta Place
- Town
- Liverpool
- Salary
- £66,582 - £77,368 per annum
- Salary period
- Yearly
- Closing
- 10/07/2026 23:59
Employer heading
Principal Digital Risk Consultant (Risk and Governance)
Band 8b
Job overview
We are looking for enthusiastic Digital Risk professionals to join our successful teams to work across all MIAA regions. We want driven people who think creatively about their work, embrace challenges and can resolve complex problems.
As a Principal Digital Risk Consultant you will be earning up to £77,368. You will take lead responsibility for the management and delivery of a broad and challenging portfolio of audit and/or advisory assignments including the personal conduct of highly complex assignments.
To conclude upon the quality of all audit opinions produced for allocated clients, contribute to the Head of Internal Audit Opinion, and assist in the drafting of the Annual Governance Statement as required and/or to deliver and coordinate highly complex advisory assignments.
To direct and supervise staff to deliver the allocated portfolio/assignments on time, to budget and to quality standards.
To report to relevant client committees and boards on a regular basis.
To respond to a broad range of sensitive and complex queries from clients and staff.
Focus on providing detailed Cyber Security, Data Protection and Information Governance assurance, advice, guidance, and services to clients, supporting improvement in the monitoring, reporting and remediation of risk.
Must have the ability to travel to a range of sites and work in a range of environments. A driving licence and own transport is essential.
Main duties of the job
We are looking for a dedicated individuals who have significant experience in:-
Produces, agrees, and oversees delivery of highly complex risk-based digital assurance plans with allocated clients that are designed to produce sufficient assurances to fulfil the requirements of the Head of Internal Audit Opinion on the effectiveness of internal control.
Actively identifies, defines, and delivers/oversees the highly complex advisory assignments and services specific to the needs of clients with a view to increasing and securing income from such activities.
Manages the planning, conduct, output and opinions for highly complex assurance and advisory work and services for allocated clients within agreed deadlines, budgets, and quality standards.
Operates as budget holder for allocated plans, advisory assignments, and services to ensure income is recovered, costs contained, and outputs delivered. Often these budgeted plans need to be adjusted on an ongoing basis for reporting to Audit Committees as priorities shift.
Manages and develops the key relationships with allocated clients, particularly at the Chief Information/Digital Officer, Chief Clinical Information Officer, Chief Nursing Information Officer, Senior Information Risk Owner, Data Protection Officer as well as other senior digital staff.
Provides the highly complex advice to clients on technology/digital risk, either current or emerging, in the context of care, service and business activities.
Working for our organisation
MIAA is an NHS Shared service, hosted by Liverpool University Hospitals NHS Foundation Trust. MIAA is the predominant provider of assurance and solutions services to over 60+ NHS and wider public and third sector, including local government, police & fire, charities and housing organisations.
MIAA offer clients a number of services including internal audit, consultancy, anti-fraud services, technology risk, clinical coding audit and training, and, specific to this role, information governance and data protection services. MIAA’s budgeted turnover is £16m million, which is demonstrative of the organisation’s ambitious and strategic goals.
We are committed to equality, diversity and inclusion, welcoming applications from people of all backgrounds, identities and lived experiences.
Staff benefit from flexible/hybrid working, a generous pension scheme, protected learning time and opportunities for development and career progression
We promote a respectful, supportive and flexible working environment and operate zero tolerance to bullying, harassment and discrimination.
We particularly welcome applications from Black, Asian and minority ethnic communities, LGBTQ+ individuals, disabled people, carers, returners and other under‑represented groups.
Applicants with a disability who meet the essential criteria will be offered an interview, and reasonable adjustments will be made throughout recruitment and employment.
Detailed job description and main responsibilities
The agency operates in a unique competitive trading environment always requiring a professional customer-focus and a range of commercial skills of the postholder. This trading environment creates a business model that requires income to be secured in open competition against multinational consulting and accountancy firms. Income needs to be secured on a regional and national basis to maintain operational and strategic viability.
There is the requirement to have responsibility across the function, and the wider MIAA, for aspects of the design and adaptation of information systems. Also, this responsibility extends to other NHS bodes through audit related consultancy and opinions.
A substantial element of the job involves utilising a number of office based and client computer systems, as well as technical interrogation, testing and monitoring tools to evaluate system and produce the audit outputs.
Communication and the establishment of personal credibility as a subject matter expert at Board level with the clients are central to the job. This is built upon the provision and receipt of highly complex, highly contentious, highly technical and highly sensitive information of a confidential nature and the demonstration of highly specialist knowledge and practical experience. This will require developed negotiation, tact, and persuasion skills as well as a deep appreciation and understanding of complex client risks, NHS systems and existing guidance.
Discussions with senior and non-digital staff from a substantial element of the job often concerning contentious and complicated risk, control, and governance issues at a corporate level. Communication will involve negotiating with, and influencing, external agencies. The job involves significant involvement in persuading and negotiating the reasoning behind highly complex recommendations with senior staff, up to and including Board level, across a range of disciplines to arrive at an agreed position. Communication of findings and advice will be personally and principally delivered through attendance at Audit Committee and other high level presentations, often to large groups of staff.
Work is managed rather than supervised, with the jobholder working within set procedures and broad guidelines as defined by the Quality System and corporate policies, but having substantial freedom to act with autonomy and to interpret policies, standards, and legislation to meet the strategic and operational requirements of MIAA and clients..
The nature of the work necessitates a thorough and concentrated focus on technologies, systems, and processes to deliver consistent and robust opinions whilst balancing competing priorities. The work pattern is often unpredictable but there is routinely a need to actively participate and lead Board level discussions and workshops requiring high levels of sustained concentration. Meeting competing deadlines is a routine element of the job.
For further information please read the Job description and person specification in full.
Person specification
Qualifications
Essential criteria
- Level 7 Qualification in an Informatics or Cyber Security subject/equivalent e.g. Masters degree or equivalent
- Qualification in Computer Audit (QiCA) or Certified Information System Auditor (CISA) or Demonstrable, significant experience in the field of IT/IS Audit
Desirable criteria
- Certified Information Security Manager
- Certified Data Protection Officer
- Prince 2 project management or Managing Successful Programmes
- CREST Penetration Tester
- CHECK Team Member
- CHECK Team Leader
Experience
Essential criteria
- Must have senior experience of working in audit and consultancy or within a senior role in digital delivery
- Must have significant demonstrable PQE plus self-certified CPD
- Experience of operating at board level, presenting to an audit committee and influencing Exec and Non Exec Directors
- Demonstrable understanding of the role of audit and consultancy and relevant techniques for delivery
- Must have significant experience of recruiting, developing, managing and supervising staff
- Must have experience of working in the NHS or other public sector organisation resulting in a developed understanding of digital systems, risks and processes. Alternative experience in an equivalent organisation may be acceptable
Knowledge
Essential criteria
- Full and mature understanding of NHS and public sector structures, policy, functions, and digital systems together with the aptitude to build on that knowledge
- Full understanding of the digital risk agenda, corporate governance, risk management and assurance principles and practice
- Full and mature understanding of audit and IM&T principles and practice together with the aptitude to build on that knowledge
- Must understand corporate governance, risk management and assurance principles and practiceq
- Demonstrate a full understanding of audit and financial principles and practice together with the aptitude to build on that knowledge
- Specific technical knowledge including: processes, tools and techniques of information security management, protection of information and information systems, application security, data loss, prevention and access control, vulnerability assessment tools, endpoint security configuration, IT security and data protection, network monitoring and analysis, methods and tools of forensics investigations for IT security violations, tools and techniques of cyber security management, vulnerability assessment tools, tools and techniques for assessing the effectiveness of information security measures
Skills
Essential criteria
- Excellent written and verbal communication skills, including presentational, negotiation and influencing skills
- Excellent analytical skills
- Strong supervision, team building, staff management, coaching, mentoring and staff development skills
- Ability to negotiate, persuade and influence, sometimes in a setting that is unresponsive or hostile to audit findings
- High levels of numeracy and keyboard skills
- Ability to make judgements and recommendations in the context of complex systems and materiality of findings
- Good time management skills and the ability to work to tight deadlines and manage competing priorities
- Ability to contribute to strategic corporate direction
Applicant requirements
You must have appropriate UK professional registration.
Documents to download
Further details / informal visits contact
- Name
- Paula Fagan
- Job title
- Deputy Digital Director
- Email address
- [email protected]
- Telephone number
- 07825592866
If you have problems applying, contact
- Address
-
L9 7AL
- Telephone
- 0151 706 4666
List jobs with Liverpool University Hospitals NHS Foundation Trust in Administrative Services or all sectors









