Royal Berkshire NHS Foundation Trust logo

Information Security Analyst

This job is closed to applications

Location
Reading, England
Salary
£57,528 - £64,750 Per Annum
Profession
Administrative and IT
Grade
Band 8
Deadline
25 Jun 2026
Contract Type
Permanent
Posted Date
12 Jun 2026
Medical Protection — indemnity for locally employed doctors from £79

Job overview

We are seeking a highly skilled and motivated Information Security Analyst to join our Digital Data & Technology (DDaT) team. This is a pivotal role supporting the Head of Information and Cyber Security  (CISO) in delivering cyber security services across the Trust and wider health and care system.

The role will support the CISO in delivering digital safety, security and overall improvement, adhering to the Target Operating Model. The Information Security Analyst will manage the delivery of all cyber security related services. This will include cyber risk management, Data Security Protection Toolkit (DSPT) compliance against cyber related assertions, policy and procedure lifecycle management, and ensuring the Trust's information compliance adheres to the Cyber Assurance Framework (CAF) and ISO27001.

Main duties of the job

Provide expert guidance on the selection, design, justification, implementation and operation of Cyber Security strategies, technologies, processes, procedures and standards. Support the development of controls and management approaches to maintain the safety, confidentiality, integrity, availability and security of the Trust’s digital infrastructure and systems; including the protection of Trust and patient data and information stored and processed by infrastructure or systems managed by, or under the control of the Trust

As the Information Security Analyst, you will ensure that technology, infrastructure, systems and supporting processes possess adequate and cost-effective protection against cyber threats and all identified Cyber Security risks.

As the Cyber Security Analyst, you will provide expert advice on, and management of, the Trust’s defence against cyber threats, data breaches and Cyber Security technologies.

Support the development of controls and management approaches to maintain the safety, confidentiality, integrity, availability and security of the Trust’s digital infrastructure and systems; including the protection of Trust Information Security Analyst and patient data and information stored and processed by infrastructure or systems managed by, or under the control of the Trust.

Detailed job description and main responsibilities

PRINCIPAL RESPONSIBILITIES • Support the CISO in developing, implementing and monitoring a strategic, comprehensive cyber, enterprise information security, resilience, information governance and IT risk management strategy and plan. • Provide expert cyber security advice to senior stakeholders and technical teams across the organisation. • Work directly with key stakeholders to facilitate risk assessment and risk management processes. • Collaborate with all departments within the Trust (and ICS) where necessary to identify and disseminate high-quality information that facilitates effective cyber and information security management and improvement. • Use advanced analytic tools (artificial intelligence) to determine emerging threat patterns and vulnerabilities. Scoping and delivery of penetration tests and ensure actions from vulnerability assessments are resolved • Lead on audit and audit preparation relating to IT security • Maintaining compliance with various standards in place e.g. Data Security and Protection Toolkit, CareCERT, Cyber Essentials+, Network and Information Systems Regulations etc.

  • Act as the Trusts advisor on cyber security protection, detection, response and recovery. • Analyse complex data and oversee the production of detailed information • Work closely with the Emergency Preparedness, Resilience and Response teams to ensure that preparations include events relating to cyber security. • Evaluate options and be able to persuade and influence others to ensure that risks in relation to cyber, resilience and information integrity and security are addressed appropriately. • Develop business cases and propose funding allocations based around intelligence on the areas of greatest risk and benefit. • Develop and implement a cyber, resilience and information integrity and security strategy, ensuring all partners endorse the strategy. • Ensure that all local information and cyber security strategies and activities align with the national Plan. • To assist with the development of disaster recovery and business continuity strategies for Trust digital services, wider stakeholders and partner organisations. Adherence to Professional Standards • All activities will be conducted within the context of professional standards, including, but not limited to, PRINCE II and ITIL. • This post requires continual upgrading of skills to reflect rapid changes in technology, the Trusts’ environment and the needs of the Trust. This is achieved through formal training; informal skills transfer and self-tuition. Business Change and Transformation • Work closely and collaboratively with, the Trust Improvement Programme Board to ensure synergy for business transformation. • Ensure the teams with area of responsibility develop their knowledge and ability to drive successful technology-based change management and to deliver successful training across a wide range of staff within the Trust.

Person specification

Experience

Essential

  • Extensive experience of developing and delivering an Information Security service to a large complex organisation using confidential and/or sensitive information

Desirable

  • IT experience gained in both and Acute and Community setting

Qualifications

Essential

  • ITIL v3 Service Management Qualification
  • Educated to degree level or equivalent
  • Formal certification (ISACA: Certified Information Security Manager (CISM). CISSP, or CRISC) and/or formal training in information security standards and best practice (e.g.: ISO 27001/2, COBIT), or equivalent work experience demonstrating understanding of the same.

WhatsApp job alerts

Get instant WhatsApp alerts for Band 8 Medical Secretary roles in Reading

Create your Job Clerk account first. We'll collect your alert preferences during onboarding and help you turn on WhatsApp notifications for matching healthcare roles.

Sign up for WhatsApp alerts

Applying for this NHS job

This advert is for Information Security Analyst with Royal Berkshire NHS Foundation Trust in Reading, South East, England. It is listed as a Band 8 Administrative and IT role. The advertised salary is £57,528 - £64,750 Per Annum. The contract type is Permanent. The application deadline is 25 Jun 2026.

Before you apply, compare the job description with the person specification and mirror the employer's essential criteria in your supporting information. Use the vacancy title, employer, location, salary, contract type, closing date and posted date (12 Jun 2026) to decide whether this role fits your current NHS job search. If the employer can close applications early, prepare the application before the stated deadline rather than waiting for the final day.

For more context, review related Job Clerk pages for the same profession, band or location where they exist, then use the application-support guides to tailor your statement and prepare for interview.