Cyber Assurance Officer
2 days ago
Norwich
The post holder will work in our busy team, delivering an outcome-focused, professional and high-quality service at all times. Using their sound knowledge of cyber security processes, they will triage and handle cyber security alerts and tickets, as well as being the first escalation point for more junior members of the team. They will participate in larger pieces of security work, including the checking of security controls and being proactive in team projects. They will produce cyber risk assessments, monitoring controls, audits, and advising projects on cyber risk factors. They may be required to supervise more junior members of the team and also deputise for more senior members of the team from time to time. To support the delivery of a high quality, safe and compassionate healthcare service, all staff are expected to act as a role model to others in all aspects of their work and consistently demonstrate NNUH's 'PRIDE' values of People focused, Respect, Integrity, Dedication and Excellence. Overview of Essential Responsibilities: As part of our team, you will: 1. Provide professional advice on cyber security including phishing, computer security and cyber-crime., 2. Prioritisation of tickets based on severity, knowing when and how to escalate as necessary and offering advice to junior team members around prioritisation., 3. Triage alerts, from National and Local systems and prioritising accordingly., 4. Ensure completion of the Data Security Assessment Toolkit., 5. Maintain compliance with various standards in place eg, Data Security and Protection Toolkit, CareCERT, Cyber Essentials, Network, and Information Systems Regulations etc., 6. Undertake scoping and delivery of penetration tests and ensure actions from vulnerability assessments are resolved., 7. Identify potential security risks and develop strategies to mitigate these. This involves (receiving complex and sensitive information, to enable) conducting risk assessments, analysing security threats, and developing risk treatment plans., 8. Lead on specialised workstreams and projects such as undertaking cyber risk assessments. (complex in their nature), 9. Contribute to the provision of a pro-active, cost-effective, risk controlled, robust and responsive service. This includes being responsible for the safe use of your own equipment and also that used by others., 10. Provide supervision, guidance and training as required and may assist in managing the time of other members of the team., 11. Work within departmental policies, reviewing and inputting into Trust Data Security, Acceptable Use and local cyber or digital policies and procedures as requested, taking into account wider staff concerns and adhering to any KPI's in place. (these policies will impact throughout the organisation), 12. Be responsible for advising and guiding stakeholders with the interpretation of relevant cyber policy to enable compliance with organisational standards., 13. Resolve and deliver cyber security incidents, problems and service requests, working with other members of the cyber security team. (these are both complex and sensitive in nature), 14. Deploy, maintain, monitor and troubleshoot multiple systems (operating or applications) and hardware in use by the organisation, such as email, O365, SharePoint, online platforms, multiple security tools and national security systems., 15. Maintain and monitor Firewalls and anti-virus systems., 16. Ensure the ongoing management, maintenance and use of cyber security standard operating Procedures (SOPs)., 17. Provide specialist advice on, lead on, and perform day-to-day operation of defences against cyber threats., 18. Using analysis of technical details and logs, investigate potential security breaches and other computer crime., 19. Plan, prioritise and manage conflicting agendas and priorities in order to meet challenging deadlines., 20. Provide specialist assistance to IT Services on technical security issues including hands on technical configuration and day-to-day operation of devices and software., 21. Analyse computer, server and network logs including vulnerabilities and known attacks and cross reference on the MIRTE framework and known TTPs.(this will involve analysing complex digital information which is multifaceted where there may be a number of potential outcomes), 22. Assist with the interpretation and communication of developments in national cyber security legislation, policy and best practice.(this will involve analysing complex digital information which is multifaceted where there may be a number of potential outcomes), 23. Ensure that all security and vulnerability releases are being deployed to all on premise and hosted Servers and end point devices safely and effectively, using your judgement to mitigate any service impacting issues., 24. Support in the selection of controls and engage in risk assessments and controls gap analysis., 25. Deal with incidents as they occur, contributing to dealing with them and mitigating any risk to return the business to a working state as quickly as possible; for example, reporting incidents to ICO/NHS CSOC and recovery/lessons learned., 26. Keep up to date with threat actors, TTPs and current vulnerabilities. LA International is a HMG approved ICT Recruitment and Project Solutions Consultancy, operating globally from the largest single site in the UK as an IT Consultancy or as an Employment Business & Agency depending upon the precise nature of the work, for security cleared jobs or non-clearance vacancies, LA International welcome applications from all sections of the community and from people with diverse experience and backgrounds. Award Winning LA International, winner of the Recruiter Awards for Excellence, Best IT Recruitment Company, Best Public Sector Recruitment Company and overall Gold Award winner, has now secured the most prestigious business award that any business can receive, The Queens Award for Enterprise: International Trade, for the second consecutive period.