Cyber Security Manager – Governance, Risk and Compliance (GRC)

Company: Essex Partnership University NHS Foundation Trust
Apply for the Cyber Security Manager – Governance, Risk and Compliance (GRC)
Location: Grays
Job Description:

Job overview

Cyber Security Manager – Governance, Risk and Compliance (GRC)

Band 7 – £49,387 – £56,515 per annum

37.5 hours per week

Thurrock Community Hospital

Are you ready to lead cyber security at scale in a complex, mission‑driven organisation where your work truly matters?

We are looking for an experienced and passionate Cyber Security Manager – GRC to drive our cyber assurance agenda and strengthen the resilience of critical NHS services. Reporting directly to the Associate Director of Information Security (CISO), you will shape how we manage cyber risk, compliance and governance across the Trust.

Main duties of the job

As Cyber Security Manager – GRC, you will lead a high‑quality governance, risk and compliance function, ensuring strong cyber assurance across the Trust.

What you’ll be doing:

  • Lead Governance & Assurance – Oversee cyber governance services, ensuring alignment with ISO 27001, CAF and DSPT frameworks, manage policies and procedures, and deliver assurance reports and dashboards to senior and board‑level stakeholders.
  • Drive Risk & Compliance – Identify, assess and mitigate cyber risks across the organisation, ensure adherence to legislation and best practice, and coordinate audit evidence and assurance activities.
  • Strengthen Controls & Testing – Lead the penetration testing programme, manage remediation plans, analyse security data, vulnerabilities and incidents, and implement KRIs and control effectiveness.
  • Enhance Incident Preparedness – Develop and lead incident response planning, including tabletop exercises, working closely with operational, technical and information governance teams to improve resilience.
  • Lead & Develop the Team – Provide leadership, coaching and direction, manage resources and priorities, and foster a high‑performing, collaborative culture.
  • Engage Stakeholders – Build strong relationships across teams, communicate complex risks in a clear, accessible way, and influence decision‑making to secure buy‑in for security initiatives.

Working for our organisation

Valuing you. Recognising your dedication. At EPUT, we look after you.

  • Receive supervision and support to help you fulfil your potential.
  • Join an inclusive community and connect with others through engagement events and champion networks.
  • Access mental health and wellbeing services, occupational health advice and counselling.

Benefits

  • 27 days holiday plus bank holidays, rising to 33 days after 10 years’ service.
  • Excellent pension of up to 14.5% of your pensionable pay.
  • Staff discounts including Blue Light Card, NHS discount offers, and staff benefits.
  • £8,000 relocation package if you move to Essex to join us.
  • Season ticket loans are interest‑free to cover travel costs by tram, rail or bus.
  • Job share applications are welcomed.

Detailed job description and main responsibilities

You will be a confident and credible cyber security professional with a strong GRC background and leadership experience in complex environments.

Key skills and experience include

  • Expert knowledge of cyber security, governance, risk and compliance frameworks.
  • Strong experience with ISO 27001, CAF, DSPT, COBIT or similar standards.
  • Proven ability to lead risk management, audits and assurance programmes.
  • Experience managing security incidents, vulnerability management and protective monitoring.
  • Demonstrable success in leading teams, driving change and delivering against demanding timescales.
  • Excellent analytical, problem‑solving and decision‑making skills.
  • Outstanding communication and stakeholder engagement skills, with the ability to influence at senior levels.
  • Experience working in a large, complex organisation (NHS or public sector desirable).
  • Relevant professional certifications (e.g. CISM, CISA, CRISC, CGRC) or equivalent experience.

Personal qualities we value

  • Driven, proactive and resilient under pressure.
  • Collaborative, flexible and adaptable to change.
  • Passionate about cyber security and emerging technologies.
  • Ability to simplify complexity and bring clarity to challenging issues.

Person specification

Education / Qualification

  • Educated to master’s level, or equivalent experience, in Cyber Security or governance/compliance.
  • Evidence of continuing professional development and specialist knowledge or experience that is equivalent to a master’s degree.
  • Actively hold certifications: CGRC, CRISC, CISA, CISM or CGEIT.
  • Professional registration of FEDIP and membership of one of its member bodies.

Desirable criteria

  • ISO 27001:2022 Implementer or Auditor Certification.
  • Subject matter expert in risk management and cyber security.
  • ITIL Service Management.

Additional qualifications

  • Must be a car owner with a full UK driving licence as travel will be required.
  • Passion for new and emerging security related technologies.
  • Willingness to work flexibly to ensure the job is done.

Knowledge

  • In‑depth knowledge of the fundamentals surrounding cyber security.
  • Excellent understanding of the management and transformation of services.
  • Experience and knowledge of the Cyber Assurance Framework (CAF), Data Security Protection Toolkit, and COBIT 2019 implementation.

Skills / Experience

  • Significant experience of protective monitoring and security incident management.
  • Previous experience within a large complex organisation in a related area of activity.
  • Experience producing qualitative work to aggressive timescales.
  • Experience building strong relationships with business partners and multidisciplinary project delivery teams.
  • Full line and team management experience, including leading, developing, motivating, coaching and talent management.
  • Public sector or NHS management experience.
  • Evidence of implementing change in governance‑related activity or area.
  • Experience of working in a planning, project or change management environment.
  • Development of option appraisals, feasibility studies and business cases.
  • Ability to plan, organise and control all aspects of workload, even under extreme pressure.
  • Ability to explain highly complex issues and requirements in a clear, non‑technical language and concise manner.
  • Ability to interface at all levels within the customer environment to develop relationships and manage problems.

Important note: please ensure that as part of your application you include professional references with business contact information covering your last three years of employment history. We are unable to accept personal or character references.

Our Trust is an Equal Opportunities Employer. We particularly welcome applications from people with experience of using mental health services. We also hold the Disability two‑tick symbol and are committed to employing more people with learning disabilities. If you require this application form in another format (e.g. Braille or audio tape), please contact the Recruitment Department on 01375 364513 or email epunft.recruitment.adverts@nhs.net.

#J-18808-Ljbffr…

Posted: July 15th, 2026