
Job overview
The Joint Cyber Unit (JCU) is a collaboration between the Department of Health and Social Care (DHSC) and NHS England (NHSE). The JCU is embedded within the Digital Policy Unit (DPU), a unit comprising both DHSC staff and NHSE staff intended to design, plan and build a digitally enabled, data driven and safe health and social care system with ministers and the NHS.
The DPU is a sub-directorate of the Transformation Directorate, which enables the delivery of the best care and outcomes for the NHS and the people it serves by improving population health and patient pathways, rapidly adopting effective technologies, building on insights from data and edge-cutting research, and by transforming the way that care is delivered.
Purpose of the JCU
The JCU sets develops and implements strategy, policy and standards for cyber security across the NHS and Adult Social Care in England. It has responsibility for designing, implementing and the ongoing assurance of the cyber security system risk management and compliance framework in place across the wider health and care system, as well as simplifying and transforming information governance.
Main duties of the job
As a Deputy Director the post holder will work across the Joint Cyber Unit, which leads on cyber security across the health and care sector (including for NHS organisations, NHS England Regions, Integrated Care Systems, Adult Social Care Providers, and major suppliers of IT products and software to the sector) and increasing compliance with mandated cyber security standards.
The role requires a strong understanding of cyber security or significant technical knowledge and will lead on:
- Leadership and development of teams across JCU
- Governance, Risk and Compliance
- Strategy and Policy
- Stakeholder management and engagement
It is expected that the postholder, will as be required, play a leading role in supporting the management of any NHS or wider health and care system cyber incidents and will oversee the High Severity Alert Process. This can mean being expected to work out of hours and at weekends.
Detailed job description and main responsibilities
Candidate Essential requirements
- Educated to Masters level or equivalent level or equivalent experience of working at a senior level in specialist area.
- Experience of project and programme management techniques and tools such as Prince 2 or Managing Successful Projects.
- A willingness to train to gain or hold appropriate cyber qualifications. (ISACA: Certified Information Security Manager (CISM)
- Strong understanding of cyber security or significant technical knowledge.
- Experience leading and creating large scale, complex engagement strategies.
- Demonstrated expertise in a Healthcare environment
- Significant management experience at senior level in the NHS or other public healthcare related industry
- Extensive experience of delivering presentations to large groups of stakeholders in often pressured and politically sensitive environments
- Strong external communications skills in a politically sensitive environment with knowledge of and experience in handling media relations
- Ability to prepare and produce concise yet insightful communications for dissemination to senior stakeholders and a broad range of stakeholders as required
- Ability to analyse highly complex issues where material is conflicting and drawn from multiple sources (verbal, written and numerical).
Candidate Desirable requirements
- Proven Board level experience of leading and delivering complex change and strategy development programmes in a politically sensitive and complex environment.
Important: Please be aware there are residency requirements you need to meet:
All NHS England Cyber Security personnel must hold security clearance SC level as a minimum.
To meet National Security Vetting requirements, SC clearances require 5 years continuous UK residency. In certain cases, this can be reduced to three years continuous UK residency, with additional overseas checks for the previous two years.
Candidates who were posted abroad for service with HM Government, Armed Forces or within a UK government role - will still be considered.
Please make sure you meet these requirements before applying for this role.
You don’t need to have SC already, however, failure to achieve the requirements for SC after offer, will result in the job offer being withdrawn.
For further advice please check https://www.gov.uk/government/publications/united-kingdom-security-vetting-clearance-levels/national-security-vetting-clearance-levels#security-check-sc or contact england.securityvetting@nhs.net.
Applicant requirements
This post will require a submission for Disclosure to be made to check for any unspent criminal convictions.
Person specification
Qualifications
Essential
- Educated to Masters level or equivalent level or equivalent experience of working at a senior level in specialist area.
- A willingness to train to gain or hold appropriate cyber qualifications. (ISACA: Certified Information Security Manager (CISM)
- Experience of project and programme management techniques and tools such as Prince 2 or Managing Successful Projects.
Knowledge and experience
Essential
- Significant management experience at senior level in the NHS or other public healthcare related industry
- Demonstrated expertise in a Healthcare environment
- Extensive experience of delivering presentations to large groups of stakeholders in often pressured and politically sensitive environments
- Strong understanding of cyber security or significant technical knowledge.
- Experience leading and creating large scale, complex engagement strategies.
Desirable
- Proven Board level experience of leading and delivering complex change and strategy development programmes in a politically sensitive and complex environment.
Skills Capabilities & Attributes
Essential
- Strong external communications skills in a politically sensitive environment with knowledge of and experience in handling media relations
- Ability to prepare and produce concise yet insightful communications for dissemination to senior stakeholders and a broad range of stakeholders as required
- Ability to analyse highly complex issues where material is conflicting and drawn from multiple sources (verbal, written and numerical).
WhatsApp job alerts
Get instant WhatsApp alerts for Band 9 Manager and Corporate roles in London/Leeds
Create your Job Clerk account first. We'll collect your alert preferences during onboarding and help you turn on WhatsApp notifications for matching healthcare roles.
Applying for this NHS job
This advert is for Deputy Director Cyber Security Engagement and Compliance with NHS England in Wellington House (London) / Wellington Place (Leeds). It is listed as a Band 9 Manager and corporate role. The advertised salary is £112,782 - £129,783 per annum (exclusive of London Weighting). The contract type is Permanent. The application deadline is 08 Sep 2026.
Before you apply, compare the job description with the person specification and mirror the employer's essential criteria in your supporting information. Use the vacancy title, employer, location, salary, contract type, closing date and posted date (25 Aug 2026) to decide whether this role fits your current NHS job search. If the employer can close applications early, prepare the application before the stated deadline rather than waiting for the final day.
For more context, review related Job Clerk pages for the same profession, band or location where they exist, then use the application-support guides to tailor your statement and prepare for interview.
