The Assistant Director of Cyber Security, Governance, Compliance & Risk provides senior leadership and strategic direction for the organisation’s cyber security function. The post holder is accountable for developing, implementing, and continuously improving a comprehensive, outcome-focused cyber security programme that protects the confidentiality, integrity, availability, safety, privacy, and recoverability of all information assets across the organisation and wider GM system.
As the lead expert and highest point of escalation, you will own the end-to-end cyber governance, risk management, and compliance agenda. This includes formulating and maintaining the overarching cyber strategy, policies, standards, and control frameworks (aligned to short-, medium-, and long-term organisational objectives), while ensuring consistent application organisation-wide. Key responsibilities encompass leading threat intelligence and assessment activities, conducting complex risk assessments, maintaining risk registers, devising and prioritising mitigations, and integrating cyber risk into the wider organisational risk management process.
This senior leadership role demands exceptional strategic vision, expert technical knowledge, advanced stakeholder management, and the ability to navigate highly complex, multi-faceted information in a large-scale environment to drive cyber resilience and support the organisation’s mission.
Be the lead expert in your field, providing expert advice, leadership and being the highest point of escalation for the team.
Be responsible for all aspects of cyber governance, risk and compliance.
You will implement and monitor a strategic, comprehensive information security cyber program to ensure appropriate levels of confidentiality, integrity, availability, safety, privacy and recovery of information assets owned, controlled or/and processed.
Have responsibility for ensuring adherence to mandated requirements around DSPT toolkit and ensuring the organisation is compliant with UK Regulations.
Hold overall responsibility for the compliance of organisational wide information security systems.
Be responsible for the overall cyber strategy, formulating, adjusting and ensuring the delivery of plans as necessary, across the short, medium and long term.
Be responsible for and lead on threat intelligence and threat assessment for the organisation.
Be responsible for and ensure compliance with Cyber Essentials/Cyber Essentials plus and with the ISO 27000 series of standards.
Lead the cyber function, holding overall responsibility for all aspects of people management.
NHS GM plans and delivers joined-up services to improve the health and wellbeing of the population residing in Greater Manchester. Its’s goals include improving population health and healthcare outcomes, tackling inequalities, enhancing productivity and value for money, and supporting broader social and economic development.
This will be achieved at various levels, including neighbourhood, place, combinations of places, and the Greater Manchester system.
Matrix working is key to delivering our organisation's and system priorities. You will actively enable collaboration through service planning, programme delivery, stakeholder engagement, and team leadership. This includes considering the wider impact of decisions, driving improvement, and supporting inclusive ways of working where different perspectives are valued.
KEY DUTIES AND RESPONSIBILITIES
- Be the lead expert in your field, providing expert advice, leadership and being the highest point of escalation for the team.
- Be responsible for all aspects of cyber governance, risk and compliance. You will implement and monitor a strategic, comprehensive information security cyber program to ensure appropriate levels of confidentiality, integrity, availability, safety, privacy and recovery of information assets owned, controlled or/and processed.
COMMUNICATION
- Presents highly complex, sensitive or technical information about projects, initiatives and services to a wide range of stakeholders in a formal setting.
- Required to explain highly complex technical issues in a simple, non-technical manner for customers
INFORMATION RESOURCES, ANALYSIS AND DECISION MAKING
The post holder is responsible for the development, maintenance, and interpretation of highly complex cyber security information resources, including strategic risk registers, threat intelligence reports, maturity assessments, metrics dashboards, control assurance evidence, and compliance documentation (e.g., DSPT toolkit submissions, Cyber Essentials assessments, ISO 27001-aligned frameworks).