Skip to main content

Cyber Security Manager - Governance, Risk and Compliance (GRC)

This job is brought to you by Jobs/Redefined, the UK's leading over-50s age inclusive jobs board.

Please be aware that, due to current allocation constraints, Certificates of Sponsorship (CoS) are being prioritised for registered roles at this time.

Our Trust cares for more than 100,000 patients at any one time across our community health, mental health and learning disability services across Essex and parts of Bedfordshire and Suffolk.

We want you to be part of our journey of transformation, where our patients and their families are at the heart of everything we do and to achieve our vision to be the leading health and wellbeing service in the provision of mental health and community care.

You'll be part of a Trust where you will be supported to be your authentic self and be the best you can be, where we will help you to grow, develop and thrive.

The Trust is recognised by the University of Essex and is a top provider of apprenticeships for people looking to be an assistant practitioner, senior health care support worker (CAP). Our trailblazing CAP apprenticeship won a national HSJ Award.

We are also recognised as a Veteran Aware Trust and holder of gold accreditation from the Ministry of Defence Employment Recognition Scheme. Our services are highlighted as an exemplar of good practice, producing the best care for more than 3.500 armed forces veterans in the past seven years.

We have been shortlisted and won national awards. We are an inclusive organisation and Level 3 Disability Confident Leader Trust.

We are constantly innovating and looking for new ways to deliver care, such as using technology to enhance patient care and working with partners to launch new services such as the Basildon Mental Health Urgent Care Department, virtual hospitals and falls response cars.

Join us and you'll do the best work of your life - and make a difference to other people's lives. What we do together, matters.

Job overview

Cyber Security Manager - Governance, Risk and Compliance (GRC)
Band 7 - £49,387 - £56,515 per annum
37.5 hours per week
Thurrock Community Hospital

Are you ready to lead cyber security at scale in a complex, mission-driven organisation where your work truly matters?

We're looking for an experienced and passionate Cyber Security Manager - Governance, Risk & Compliance (GRC) to drive our cyber assurance agenda and strengthen the resilience of critical NHS services. Reporting directly to the Associate Director of Information Security (CISO), you will play a pivotal leadership role, shaping how we manage cyber risk, compliance, and governance across the Trust.

This is more than a management role - it's an opportunity to influence strategic decision-making, protect vital services, and lead meaningful change in an evolving cyber landscape. You'll work at the heart of the organisation, collaborating with senior stakeholders, technical teams, and external partners to ensure we meet the highest standards of cyber security and regulatory compliance.

We're looking for someone who combines deep technical expertise with strong leadership, who thrives in a fast-paced environment, and who can translate complex cyber risks into clear, actionable insights.

In return, you'll join a supportive, forward-thinking team where innovation is encouraged, professional growth is supported, and your impact will be visible across the organisation.

If you're shortlisted, your interview will take place on 16 June 2026

Main duties of the job

As Cyber Security Manager - GRC, you will lead a high-quality governance, risk and compliance function, ensuring strong cyber assurance across the Trust.
What you'll be doing:

Lead Governance & Assurance
Oversee cyber governance services, ensuring alignment with frameworks such as ISO 27001, CAF and DSPT. Manage the full lifecycle of policies and procedures, and deliver clear assurance reports and dashboards to senior and board-level stakeholders.

Drive Risk & Compliance
Identify, assess and mitigate cyber risks across the organisation. Ensure adherence to legislation, standards and best practice, and coordinate audit evidence and assurance activities.

Strengthen Controls & Testing
Lead the penetration testing programme, managing remediation plans and analysing security data, vulnerabilities and incidents to drive continuous improvement. Implement and monitor KRIs and control effectiveness.

Enhance Incident Preparedness
Develop and lead incident response planning, including tabletop exercises, working closely with operational, technical and information governance teams to improve resilience.

Lead & Develop the Team
Provide leadership, coaching and direction, managing resources and priorities while fostering a high-performing, collaborative culture.

Engage Stakeholders
Build strong relationships across teams, communicate complex risks in a clear, accessible way, and influence decision-making to secure buy-in for security initiatives.

Working for our organisation

Valuing you. Recognising your dedication. At EPUT, we look after you.

  • Receive supervision and support to help you fulfil your potential.
  • Join an inclusive EPUT community and connect with others through engagement events and equality or champion networks.
  • If you need help, we provide mental health and wellbeing services, occupational health advice and counselling.

Benefits

  • 27 days holiday, plus bank holidays, rising to 33 days after 10 years' service.
  • Excellent pension of up to 14.5% of your pensionable pay.
  • Staff discounts include Blue Light Card, NHS discount offers, and staff benefits.
  • £8K relocation package if you move to Essex to join us
  • Season ticket loans are interest-free to cover the cost of travelling to and from work via tram, rail, or bus.

Work that wraps around your needs

  • Job share: Applications for job shares are welcomed.

Detailed job description and main responsibilities
What we're looking for:

You'll be a confident and credible cyber security professional with a strong GRC background and leadership experience in complex environments.

Key skills and experience include:

  • Expert knowledge of cyber security, governance, risk, and compliance frameworks
  • Strong experience with ISO 27001, CAF, DSPT, COBIT or similar standards
  • Proven ability to lead risk management, audits, and assurance programmes
  • Experience managing security incidents, vulnerability management, and protective monitoring
  • Demonstrable success in leading teams, driving change, and delivering against demanding timescales
  • Excellent analytical, problem-solving, and decision-making skills
  • Outstanding communication and stakeholder engagement skills, with the ability to influence at senior levels
  • Experience working in a large, complex organisation (NHS or public sector desirable)
  • Relevant professional certifications (e.g., CISM, CISA, CRISC, CGRC) or equivalent experience

Personal qualities we value:

  • Driven, proactive, and resilient under pressure
  • Collaborative, flexible, and adaptable to change
  • Passionate about cyber security and emerging technologies
  • Able to simplify complexity and bring clarity to challenging issues

This is a unique opportunity to shape cyber security governance at scale, influence senior leadership, and make a tangible difference to patient services and organisational resilience.

If you're ready to lead, innovate, and make an impact - we'd love to hear from you.

Person specification

Education/Qualification

Essential criteria

  • Educated to master's level, or equivalent experience, in Cyber Security or governance/compliance
  • Evidence of continuing professional development and specialist knowledge or experience which can be demonstrated to be equitable to a master's degree
  • Actively hold certifications; CGRC, CRISC, CISA, CISM or CGEIT
  • Professional Registration of FEDIP and Professional Member of one of its member bodies

Desirable criteria

  • ISO 27001:2022 Implementer or Auditor Certification
  • Subject matter expert in risk management and cyber security
  • ITIL Service Management

Additional Qualities

Essential criteria

  • Must be a car owner with full UK driving licence as travel will be required
  • Passion for new and emerging security related technologies
  • Willing to work flexibly to ensure 'job is done'

Knowledge

Essential criteria

  • In-depth knowledge of the fundamentals surrounding cyber security
  • Excellent understanding of the management and transformation of services
  • Excellent understanding of the management and transformation of services

Desirable criteria

  • Experience and knowledge of the Cyber Assurance Framework (CAF)
  • Experience and knowledge of the Data Security Protection Toolkit
  • Understanding and implementation experience COBIT 2019

Skills/Experience

Essential criteria

  • Significant experience of protective monitoring and security incident management
  • Previous experience within large complex organisation in related area of activity
  • Demonstrable experience of producing qualitative work to aggressive timescales
  • Demonstrable experience of building strong relationships with business partners and multi-discipline project delivery teams
  • Full line and team management experience including leading, developing, motivating, coaching, talent management
  • Public Sector or NHS Management experience
  • Evidence of implementing change in governance related activity/ area

Desirable criteria

  • Experience of working in a planning, project or change management environment
  • Development of option appraisals, feasibility studies and business cases

Personal Qualities

Essential criteria

  • Ability to plan, organise and control all aspects of workload, whilst working under extreme pressure
  • Can explain highly complex issues and requirements in a clear, non-technical language and concise manner
  • Ability to interface at all levels within the customer environment to develop relationships and opportunities and manage problems

Please be aware that, due to current allocation constraints, Certificates of Sponsorship (CoS) are being prioritised for registered roles at this time.

Important note: please ensure that as part of your application, you include professional references with business contact information covering your last three years of employment history. We are unable to accept personal or character references.

As a newly appointed employee, you are responsible for incurring the cost of your initial DBS check relevant to your post; the amount will be deducted from your first salary with the Trust.

Our Trust is an Equal Opportunities Employer. We particularly welcome applications from people with experience of using mental health services. We also hold the Disability two tick symbol and have made the pledge to commit to employing more people with learning disabilities, we encourage people with a disability to apply. If you require this application form in another format i.e. Braille or audio tape etc, please contact the Recruitment Department on 01375 364513 or email epunft.recruitment.adverts@nhs.net and we can arrange for this to be dispatched to you.

The Trust has the right to expire vacancies prior to the closing date if they so wish. The Trust makes every attempt to contact all applicants and we strongly advise that you check the email account which is registered with NHS Jobs regularly, we would advise however due to the high number of applications we receive that if you have not heard from us within three weeks of the closing date your application has been unsuccessful on this occasion.

We are committed to safeguarding and promoting the welfare of children, young people and vulnerable adults, and expect all staff to undertake this commitment. Applicants will be subject to robust safer recruitment processes.

Important Notice: Recently the Health and Social Care Act 2008 (Regulated Activities) (Amendment) (Coronavirus) Regulations 2021 (the Regulations) which amended on 22 July 2021 and come into force on 11 November 2021 that anyone directly employed to work in a Care Home or who are required as part of their role to be deployed to a CQC registered care home are required to have had both their COVID vaccinations, unless they are exempt. This is therefore a requirement of this role and will form part of our pre-employment checks.

Please note - staff who are formally at risk within the organisation will be given priority in securing alternative employment. Should it come to light that a post being advertised by the Trust is considered 'suitable alternative employment' to an individual who is at risk, the recruiting manager will be advised and the post will be withdrawn from NHS Jobs.

Use of Artificial Intelligence (AI)

Applications for this role should be written by the applicant. If artificial intelligence (AI) programmes are used then the application may be rejected due to this document being an important part of the assessment process. This does not prevent applicants seeking appropriate support with applications should they need to for the purposes of any declared disability.

Employer certification / accreditation badges

Cyber Security Manager - Governance, Risk and Compliance (GRC)

Essex Partnership University NHS Foundation Trust
Grays, UK
Full-Time

Published on 15/05/2026

Share this job now