Skip to main content
Please wait, loading

Job summary

Main area
Cyber Security
Grade
Band 6
Contract
Permanent: On call rota applies
Hours
Full time - 37.5 hours per week (On call rota applies)
Job ref
225-CORP-6408979
Employer
The Royal Wolverhampton NHS Trust
Employer type
NHS
Site
New Cross Hospital
Town
Wolverhampton
Salary
£35,392 - £42,618 per annum
Salary period
Yearly
Closing
15/07/2024 23:59

Employer heading

The Royal Wolverhampton NHS Trust logo

IT Cyber Security Systems Technician

Band 6

 

 

Job overview

An opportunity has arisen for the key role of  IT Cyber Security Systems Technician within The Royal Wolverhampton NHS Trust (RWT).

This role is key to the operational effectiveness of cyber security measures across the organisation and will play a significant part in contributing to its compliance with national cyber security standards in line with mandated national policy and our internal Governance, Risk and Compliance Framework.

Working as part of the IT Cyber Security Team you will be responsible for leading the technical deployment of software and hardware patch updates across Trust networks ensuring devices and systems are appropriately tested prior to deployment of approved updates.  You will be involved in managing malware, anti-exploit, anti-ransomware, advanced threat protection, web filtering, encryption and mobile control security solutions.

You will have proven technical experience in the field of IT cyber security with particular emphasis in managing patch management, malware, advanced threat protection and be able to demonstrate an in depth knowledge of associated risks. Regular liaison with other IT teams, third parties and users is key to this role and therefore excellent communications skills are required.

This position will operate in an on-call rota and must be able to respond on site within 30 minutes.

Main duties of the job

The IT Cyber Security Systems Technician plays a key role in the provision of technical IT cyber security system management, policy adherence, complex IT security threat data analysis, interpretation of perceived threats to setting achievable balanced remediation plans. 

The post holder will be responsible for the management and configuration of several IT high profile cyber security systems including IT patch management ensuring all Trust computer devices are up-to-date with the latest Microsoft and third party security updates.  This will include the management and configuration of the Trust’s IT patch management system in line with IT Security policy and producing executive reports for senior management to understand the identified issues. 

Working for our organisation

The Royal Wolverhampton NHS Trust is one of the largest NHS trusts in the West Midlands providing primary, acute and community services and we are incredibly proud of the diversity of both our staff and the communities we serve. We are building a workforce that can help us to fulfil our values, improve quality of care for patients, and solve the health care problems of tomorrow. We're passionate about the value that diversity of thinking and lived experience brings in enabling us to become a learning organisation and leader in delivering compassionate care for our patients.

We are delighted that we have been rated as "Good" by CQC. We have achieved numerous awards; The Nursing Times Best Diversity and Inclusion Practice and Best UK Employer of the Year for Nursing Staff in 2020.

The Trust is a supportive working environment committed to creating flexible working arrangements that suit your needs and as such will consider all requests from applicants who wish to work flexibly.

Detailed job description and main responsibilities

1. To be responsible for ensuring Trust computer assets are kept up-to-date and free from known vulnerabilities. This includes responsibility for the Trust IT patch management solution and the updating of 7000+ computer assets. Due to the critical nature of NHS service delivery a major part of this role will be to perform robust testing of software and hardware updates; working closely with the Test Manager and Information Asset Owners to ensure critical systems are tested against updates prior to general release. To monitor Trust wide patch update deployments and take remedial actions where necessary. To produce reports for Trust Senior Management including the Senior Information Risk Officer (SIRO) evidencing compliance for security updates across its networks and devices. To be the subject matter expert for the IT patch management solution and reconfiguring patch configuration/process in accordance with business needs.

2. To be responsible for the management of the NHS Digital Advanced Threat Protection (ATP) security system. To analyse complex IT cyber security threats, interpreting data to recommend appropriate courses of action for remediation, mitigation, risk transference and/or acceptance. To ensure the ATP incident and alert system is updated with agreed risk action plans within expected timescales. To ensure all computer devices are communicating with ATP as expected; to perform fault resolution as required. The management of this and other security systems will result in regular interruptions to your daily workload as security incidents are of an unpredictable nature and will require in many cases immediate attention. 

3. To provide advanced technical support for Trust antivirus/malicious code prevention systems. To provide incident response management as stated in the IT Security Policy to contain virus or malicious code outbreaks. To provide day to day monitoring of the Trust’s malware protection systems and ensure all Trust devices have active up-to-date anti-virus software. To produce statistics and reports to senior management evidencing performance in managing malicious threats to Trust networks and assets. To perform system hardware and/or software upgrades as and where required.

4. To be responsible for the Trust’s mobile device management system. To configure the mobile device management system balancing the needs of the business and in accordance with IT Security Policy. As the subject matter expert you will to direct the IT Cyber Security Technician in the administration of this system, ensuring all devices are up-to-date with the latest security configurations and operating system/app updates. To design new client configurations as new technologies are incorporated into the 
mobile management system. To perform system hardware and/or software upgrades as and where required.

5. To support the Senior IT Cyber Security Technician in the management of the Trust’s web filtering solution. To update system configurations to resolve user/service based Internet access requests. To ensure the regular backups of web filtering solution configurations and perform system restores to ensure business continuity as required. To perform system hardware and/or software upgrades as and where required.

6. To support the Trust’s encryption solutions on both servers and client devices. To provide day to day monitoring of the Trust’s encryption systems. To provide monitoring and reports to Trust senior management via the Information Governance Action Group on the transfer of data to removable media across Trust devices. To perform system hardware and/or software upgrades as and where required.

7. The IT Cyber Security Team manages the installation and upgrade of Trust high value security tools/hardware and you will be expected to direct and/or partake in these system upgrades/installations. You are required to have the highest ethical standards when managing these systems due to their value and importance to the effective security of Trust networks. 

8. To provide, receive and analyse highly complex security vulnerability assessments. To analyse, understand and be able to interpret complex security threats to IAO’s in a language they clearly understand; providing recommendations for remedial actions and ensuring IAO’s complete these within agreed timescales. To produce executive summary reports for the Trust SIRO of these complex security issues against recognised standards such as the Open Web Application Security Project (OWASP) and as determined by the Data Security and Protection Toolkit (DSPT).

9. To support the IT Cyber Security Manager in assessing systems for security threats or auditing compliance with Trust IT Security Policy. To work with third party security consultants and IAO’s in the security assessment or audit of new or existing Trust systems.

10. To be responsible for performing regular password audits of all user accounts, liaising with users who require assistance to meet good password standards. Taking action where standards are repeatedly not 
met. Producing training and advice material to enable end users to understand the required process and reasons for compliance.

11. To provide NHS authorities and senior IT managers with risk information relevant to mandatory cyber security monitoring of NHS information systems identifying potential risks. Daily analysis and recording of associated IT security system alerts including but not limited to enterprise firewalls and malware. 

12. To receive, analyse and recommend action plans for NHS Digital CareCERT cyber-security alerts directly affecting Trust hardware and/or software. To recommend and agree remedial actions with senior IT Cyber Security staff and monitor the progress of cyber-security remediation actions. To liaise with relevant IAO’s and provide expert IT security advice to ensure the successful completion of recommended actions. To escalate where these actions are not being achieved.

13. To support the IT Cyber Security Manager in IT Security policy creation, update and implementation. To review IT Security policy and suggest amendments to processes in order to meet new or changing 
business needs. To provide advice to Trust users at all levels on Trust IT security policy and technical solutions. To provide resolution for IT security related incidents and service requests and maintain/update the IT Cyber Security Team 3rd line job allocation management system.

14. To be part of a IT cyber security incidence response team and manage and support the investigation of IT security related incidents which may include highly sensitive matters that require strict confidentiality.This may also include exposure to content that is of an offensive or graphic nature.

15. To create IT cyber security user guidance documents and maintain the Team’s intranet presence.

16. Day-to-day supervision of the IT Cyber Security Technician.

17. To ensure in conjunction with the Senior Cyber Security Technician that there is adequate office cover for the management of IT security technical systems.

18. To manage and maintain the Team’s test bed of IT hardware and software.

19. To provide training to Trust users on IT security related technologies as directed.

20. To attend meetings where technical IT security requires representation including the Information Governance Action Group, Change Management and Desktop Management meetings.

21. To attend relevant training when required.

Any other duties commensurate with the grading of this pos

Person specification

Education

Essential criteria
  • Good standard of education [Math, English]
Desirable criteria
  • Working towards or certified as SSCP or equivalent
  • IT qualifications relevant to the post e.g., ITIL, cyber security

Experience/Skills

Essential criteria
  • Experience of working within an ICT support environment preferably within technical IT Security
  • Experience of resolving complex technical IT security related faults/risks.
  • To demonstrate a good understanding of risk management and be able to competently report identified IT risk events.
  • Excellent analytical skills requiring significant concentration ability in relation to analysis of considerable sized in-depth IT system security/activity logs in order to identify IT security risk.
  • Experience of supporting IT security systems on various operating systems such as web filtering, anti-virus, encryption, mobile device management, advanced threat protection, patch management.
  • Knowledge of malware such as virus, Trojan or ransomware behaviour and remedial actions, containment strategies.
  • Ability to operate effectively in a pressurised, quick changing environment and prioritise workloads to meet targets.
  • To understand the relevant Trust IT Security and Information Governance policies in order to ensure technical compliance of systems and solutions with these Policies. Ability to provide IT security advice to users for technical IT security solutions and Trust IT Security policy.
  • Experience of using Excel desirably to an advanced level.
Desirable criteria
  • Experience of providing technical risk analysis of potential or actual IT security threats including the provision of threat analysis and recommendations for remediation, mitigation, transference and/or risk acceptance.
  • Experience of configuring and using security vulnerability assessment tools and /or report analysis in a language understood by the target audience.
  • Experience of analysing information systems ideally in relation to new/existing systems including changes and/or fault identification identifying potential risk(s).
  • Experience of writing scripts and SQL queries is desirable.

Communication Skills

Essential criteria
  • Excellent telephone manner – good customer contact skills.
  • Good communication skills both written and oral especially in provision of reports to senior management.
  • Must be able to work as part of a team.
  • Ability to work unsupervised on pre-defined tasks.
  • Able to communicate highly technical information to varying levels of user, using non-technical language in a manner that promotes confidence.
Desirable criteria
  • Ability to produce training materials and deliver IT security related training to users either one-to-one or as a group.

Flexibility

Essential criteria
  • To be part of an on-call rota providing out of hours support for cyber related incidents including attendance at any Trust location within 30 minutes.
  • The post holder will normally be expected to work flexibly between the hours of 7am to 6pm. Hours of work within this daily time period will be agreed in advance with the IT Cyber Security Manager to enable business processes to be completed as required.
  • In the absence of the Senior IT Cyber Security Technician the post holder will be expected to provide office cover for the management of technical IT security systems.

Other

Essential criteria
  • Ability to work in a busy / fast moving IT environment.
  • A good understanding of health and safety.
  • A good understanding of manual handling.
  • A high level of confidentiality is required of the post holder when assisting with breaches of security and confidentiality.
  • Advanced computer skills including keyboard together with extensive use of a VDU.
Desirable criteria
  • Due to nature of cyber security incidents, you will be required to change activity quickly.
  • May be required to carry IT equipment for IT cyber security related systems/tasks.

Employer certification / accreditation badges

Apprenticeships logoNo smoking policyAge positiveCare quality commission - GoodArmed Forces Covenant Gold AwardDisability confident employerNursing Times Workforce Summit & Awards WinnerStep into health

Documents to download

Apply online now

Further details / informal visits contact

Name
Jo Watts
Job title
Head of Cyber Security
Email address
[email protected]
Telephone number
01902 481523
Apply online nowAlert me to similar vacancies