Skip to main content
Please wait, loading

Job summary

Main area
IT
Grade
Band 7
Contract
Permanent
Hours
  • Full time
  • Flexible working
37.5 hours per week
Job ref
025-AC067-0826
Employer
Digital Health and Care Wales
Employer type
NHS
Site
Hybrid working
Town
Location to be confirmed at interview
Salary
£50,129 - £57,365 per annum
Salary period
Yearly
Closing
24/08/2026 23:59

Employer heading

Digital Health and Care Wales logo

Cyber Security Vulnerability Manager

Band 7

Digital Health and Care Wales is an ambitious organisation created by Welsh Government to lead on the digital transformation of health and care. It builds on the digital architecture and national services put in place by the NHS Wales Informatics Service over the past decade.

The organisation will lead on large-scale developments that make a significant difference to the people of Wales as well as to health and care professionals, such as expansion of the digital patient record and the creation of a National Data Resource. It will improve the way data is collected, shared and used. Please check your email account regularly. Successful applicants will receive all recruitment related correspondence via the email account registered on the application form.

All applicants are invited to apply in Welsh, any application submitted in Welsh will not be treated less favourably than an application made in English.

The salary scale for a Band 3 has been adjusted as part of the NHS Agenda for Change pay award for 2026/2027 and will be implemented in August 2026 backdated to 01 April 2026 where applicable.

Job overview

Are you passionate about cyber security and protecting critical digital services that make a real difference to people's lives? We are looking for a Cyber Vulnerability Manager to lead and develop our vulnerability management function, helping to identify, assess and reduce cyber risks across NHS Wales.

In this highly influential role, you will oversee vulnerability scanning, assessment and remediation activities, ensuring systems and applications remain secure against existing and emerging threats. Working with a wide range of stakeholders, you will provide expert advice, develop improvement initiatives and support the delivery of a strong cyber security culture across the organisation.

As a leader within the Cyber Security team, you will manage and support specialist staff, helping them to develop their skills while creating an inclusive and collaborative environment where everyone can thrive. You will also contribute to strategic cyber security planning, helping shape future security capabilities and continuously improving services for our users.

This is an exciting opportunity for someone with strong technical expertise, excellent leadership skills and a passion for continuous improvement. If you enjoy solving complex challenges, influencing positive change and working in a role where your expertise directly supports vital public services, we would love to hear from you.

Main duties of the job

As Cyber Vulnerability Manager, you will lead the delivery of vulnerability management services across a complex digital environment. You will coordinate vulnerability assessments, analyse security findings and work closely with technical teams, suppliers and service owners to ensure risks are effectively managed and remediated.

You will oversee vulnerability scanning tools, penetration testing activities and associated contracts, ensuring services remain effective, compliant and aligned with organisational objectives. Using data and intelligence from multiple sources, you will assess risk, identify trends and produce reports that support informed decision-making at operational and strategic levels.

A key part of the role will involve developing policies, procedures and standards that strengthen cyber resilience and support continuous improvement. You will lead projects, manage priorities and contribute to cyber security improvement programmes, ensuring outcomes are delivered on time and to a high standard.

The post holder will also build strong relationships across the organisation and wider NHS, providing expert guidance, delivering training and awareness activities, and helping teams understand and manage cyber security risks in a practical and collaborative way.

Working for our organisation

Digital Health and Care Wales (DHCW) is part of the NHS Wales family and has an important role in changing the way health and care services are delivered through technology and data. The organisation supports frontline staff with modern systems and access to important information about their patients, while empowering the people of Wales to manage their own health through digital NHS Wales services.

 

Working for DHCW offers lots of employee benefits, including flexible working, a competitive salary, 28 days of annual leave plus Bank Holidays and opportunities for career development. We are committed to recognising and celebrating our staff as the most valuable part of our organisation.

 

Join our game changing, life-saving team and start making a real difference to health and care services in Wales.

Detailed job description and main responsibilities

You will be able to find a full Job description and Person Specification attached within the supporting documents or please click "Apply now" to view in Trac.

 

  • Provide professional leadership, coaching and line management to specialist cyber security staff, supporting their development and performance.
  • Develop and maintain vulnerability management policies, processes and standards in line with organisational and national requirements.
  • Analyse complex security data, vulnerability reports and threat intelligence to identify risks, trends and opportunities for improvement.
  • Work collaboratively with technical teams, suppliers and stakeholders to coordinate remediation activity and improve security outcomes.
  • Manage cyber security projects and improvement programmes, balancing competing priorities and ensuring successful delivery.
  • Produce high-quality reports, dashboards, presentations and recommendations for a range of technical and non-technical audiences.
  • Act as a subject matter expert, providing specialist advice on vulnerability management, cyber security best practice and emerging threats.
  • Support governance, risk and compliance activities, including audits, security assessments and accreditation requirements.
  • Champion an inclusive, supportive and continuous improvement culture where diverse perspectives are valued and everyone is encouraged to contribute their best work.

We welcome applications from candidates of all backgrounds and experiences.

The ability to speak Welsh is desirable for this post; Welsh and/or English speakers are equally welcome to apply.

Person specification

Qualifications

Essential criteria
  • Educated to degree (or equivalent qualification / experience) in an associated professional field.
  • Educated to degree (or equivalent qualification / experience) in an associated professional field.
Desirable criteria
  • Professional Registration with a relevant informatics professional body.
  • FEDIP Practitioner, or equivalent recognised Intermediate level Professional qualification.

Experience

Essential criteria
  • Experience of leading a team and successfully identifying and managing the risks posed by vulnerabilities in the IT systems and applications within a large complex organisation.
  • Experience of conducting penetration tests and vulnerability scans in a corporate environment.
  • Proven ability to develop training materials to effectively accommodate participants with differing learning styles.
  • Familiar with the IT environment relating to own sphere of work (own organisation and/or closely associated organisations, such as customers, suppliers, partners), in particular own organisation’s technical platforms and those that interface to them through the specialism, including those in closely related organisations.

Skills and Attributes

Essential criteria
  • Technical Adaptability skills to learn and assess new methodologies or technologies quickly, understanding their wider implications and where appropriate implement them.
  • Analytical skills to acquire a proper understanding of a problem or situation by breaking it down systematically into its component parts and identifying the relationships between these parts. Selecting the appropriate method/tool to resolve the problem and reflecting critically on the result, so that what is learnt is identified and assimilated.

Employer certification / accreditation badges

Apprenticeships logoAge positiveWork With Me - A commitment to becoming a more inclusive business for disabled peopleGold Award for Corporate Health StrategyImproving working livesStop Smoking Wales is the NHS Smoking Cessation Service in WalesGood Recruitment CollectiveStonewall Hyrwyddwr Amrywiaeth Diversity ChampionMindful employer.  Being positive about mental health.CTP The Ministry of Defence partnering with Right ManagementDisability confident employerRemploy CymruThe University of Wales Trinity Saint David - Prifysgol Cymru Y Drindod Dewi SantThe Poppy FactoryDying to Work CharterThe Chartered Institute for IT - Reward the professionalism of your team, define and accelerate career paths, and recognise your organisation’s commitment to advancing technology.Federation for Informatics Professionals - A collaboration between the leading professional bodies in health and care informatics supporting the development of the informatics profession.Armed Forces CovenantEmployer pledge demonstrating a commitment to change how we think and act about mental healthCore principles

Applicant requirements

Welsh language skills are desirable

Documents to download

Apply online now

Further details / informal visits contact

Name
Julian Jones
Job title
Head of Cyber Security
Email address
[email protected]
Apply online nowAlert me to similar vacancies