Job overview
The Christie NHS Foundation Trust, a world-renowned cancer centre, are seeking an experienced and skilled Cyber Security Analyst (Band 6) to work with us.
As a Cyber Security Analyst at The Christie, your main duties will encompass a range of responsibilities crucial to protecting our digital infrastructure, and data. You will play a key role in administering and optimising our cyber security toolset, which includes antivirus solutions, vulnerability scanners, and threat protection services. Your proactive approach will ensure that all cyber security tools are configured according to best practices and compliant with NHS guidelines.
Main duties of the job
Continuous monitoring of the Trust’s cyber and security systems is a fundamental part of your role, where you will detect, analyse, and respond to any cyber security incidents or breaches. This includes managing the incident response process, documenting actions taken, and reporting findings to minimise the impact on our operations. You will also assess and manage the cyber security risks associated with our IT systems, ensuring compliance with legal and regulatory requirements such as GDPR. CAF/DSPT.
In addition to these technical duties, you will maintain the Trust's risk register and prepare comprehensive reports on our cyber security posture. Effective communication with both internal and external stakeholders is essential to raise awareness about cyber security issues and strategies.
You will provide regular updates to senior management and non-technical staff, ensuring they are informed about critical security matters and preventive measures.
Collaboration is key in this role, as you will work closely with various Digital Services teams to design and implement system enhancements that strengthen our cyber security defences. You will also participate in security projects, ensuring they align with our strategic goals and IT infrastructure developments.
Your involvement in internal and external audits related to IT security will help ensure adherence to security policies and procedures.
Detailed job description and main responsibilities
Main Duties and Responsibilities
- Administer and optimise the use of the Trust's cybersecurity toolset, which includes antivirus software, vulnerability scanners, SIEM systems, threat protection services, and patch management solutions.
- Ensure that all cybersecurity tools are configured according to best practices and compliant with NHS guidelines and standards.
- Conduct continuous monitoring of the Trust’s IT systems to detect, analyse, and respond to cybersecurity incidents and breaches.
- Manage the incident response process, including documentation and reporting, to mitigate risks and minimize the impact of security breaches.
- Assess and manage cybersecurity risks associated with IT systems and operations.
- To manage, maintain, and update firewall rules in line with security best practice and ITIL change management.
- Ensure compliance with relevant legal and regulatory requirements, including GDPR and NHS-specific security mandates.
- Maintain the Trust's risk register, updating and evaluating the effectiveness of security measures regularly.
- Prepare comprehensive reports on the state of the Trust’s cybersecurity, detailing vulnerabilities, incidents, and overall security posture for review by senior management.
- Document security breaches and the measures taken to resolve them in a timely and detailed manner.
- Communicate effectively with internal and external stakeholders to raise awareness about cybersecurity issues and strategies.
- Provide regular updates to, senior management, and non-technical staff on critical security matters and preventive measures.
- Collaborate with Digital Services teams to design and implement system enhancements that bolster the Trust’s cybersecurity defences.
- Participate in the planning and execution of security projects, ensuring alignment with strategic goals and IT infrastructure developments.
- Assist in internal and external audits related to IT security to ensure adherence to security policies and procedures.
- Work with audit teams to address any findings and implement recommended changes to security practices and controls.
- Stay abreast of the latest cybersecurity trends, tools, and practices through continuous professional development.
- Facilitate and participate in cybersecurity training sessions for other IT staff and end-users within the Trust to promote security awareness and best practices.
- Ensure that all backup systems are secure, and that data integrity is maintained during backup and recovery processes.
- Maintain flexibility to respond to urgent cybersecurity issues outside of normal working hours as required