IT Cyber Specialist: Sponsorship Available

NHS Dorset

Job summary

The
IT Cyber Specialist is responsible for supporting the delivery, monitoring, and
continual improvement of cyber security operations across the Integrated Care
Board (ICB) and GP IT estate. The post holder helps protect critical clinical
and corporate systems by strengthening defences, supporting incident response,
managing vulnerabilities, patching, and ensuring adherence to NHS cyber, DSPT
CAF and other information security standards.
Working under the direction of the Head of IT Infrastructure & Cyber
Operations, the IT Cyber Specialist provides expert hands on cyber security
capability, maintains tooling and monitoring platforms, and contributes to
organisation wide cyber resilience. The role supports safe patient care by
helping prevent, detect, and mitigate cyber threats.

Main duties of the job

This role is responsible for supporting the day-to-day cyber
security operations across the Integrated Care Board (ICB) & GP IT estate,
helping to protect clinical & corporate systems from cyber threats. The post
holder will monitor & manage security tools, investigate & respond to
security alerts & incidents, conduct vulnerability assessments, & support
patching & remediation activities.
The role works closely with internal IT teams, NHS partners, suppliers & national cyber services to strengthen the organisation’s security posture. Key
duties include maintaining cyber security records & compliance evidence,
producing technical reports, supporting security audits, responding to national
cyber alerts, & providing specialist advice on cyber risks & secure working
practices.
The post holder will contribute to cyber improvement programmes, security
hardening initiatives, resilience testing, disaster recovery exercises & phishing simulations. They will also support identity & access management
processes, help develop secure technical standards, & assist with the
implementation of new cyber security tools & controls.
The successful candidate will act as a subject matter expert for cyber
security, helping to improve organisational resilience, supporting compliance
with NHS & regulatory requirements, & promoting a strong culture of cyber
awareness across the organisation. Occasional participation in out-of-hours
support for major incidents & essential maintenance may be required.

Person Specification

Experience

Essential

  • Please also refer to the detailed Person Specification attached.
  • Strong technical understanding of cyber security principles, secure configuration, threat detection and vulnerability management
  • Experience working with security monitoring and protective tooling such as:
  • Microsoft MDE
  • Vulnerability scanning tools
  • Identity security and multi-factor authentication
  • Working knowledge of Microsoft 365 security in nhs.net connect
  • Understanding of network security concepts (e.g., firewalls, segmentation, IDS/IPS, DNS filtering).
  • Knowledge of patching methodologies, operating system hardening, and baseline compliance
  • Awareness of national NHS cyber policies, cyber alerts, and regulatory expectations e.g. NIS and DSPT CAF
  • Hands-on technical experience supporting cyber security operations in a complex IT environment
  • Experience analysing security alerts, investigating incidents, correlating events, and contributing to incident response
  • Experience conducting vulnerability assessments, patch compliance checks and remediation tracking
  • Experience working with IT teams to improve security posture across endpoints, servers, networks, and cloud environments
  • Experience documenting incidents, maintaining risk registers, and producing security reports
  • Ability to communicate technical cyber risks clearly and appropriately to both technical and non-technical colleagues
  • Ownership of issues
  • Demonstrated capabilities to manage own workload and make informed decisions in the absence of required information, working to tight and often changing timescales
  • The promotion of equality of opportunity and good working relations (providing practical leadership)
  • Self-motivated
  • Demonstrates honesty and integrity and promotes organisational values
  • Embrace change, viewing it as an opportunity to learn and develop

Qualifications

Essential

  • Please also refer to the detailed Person Specification attached.
  • Educated to degree level in a relevant IT, cyber security, or computer science discipline, or able to demonstrate equivalent specialist experience at an advanced technical level. Professional cyber security qualification(s) desirable, such as:
  • CompTIA Security+
  • CompTIA CySA+
  • EC-Council CEH (Desirable) CISSP / CCSP / CISM (or working toward)
  • Evidence of ongoing professional development in cyber security, threat detection, security monitoring, and vulnerability management
  • Knowledge of NHS cyber frameworks (DSPT, Cyber Assessment Framework, NIS/NIS2) acquired through formal training or relevant experience
  • Training or certification in security tooling (MDE, vulnerability management, identity protection) advantageous

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).

Closing Date: 26 August 2026

To apply for this job please visit www.jobs.nhs.uk.