Job summary
- Main area
- IT
- Grade
- Band 7
- Contract
- Permanent
- Hours
- Full time
- Flexible working
- Job ref
- 025-AC067-0826
- Employer
- Digital Health and Care Wales
- Employer type
- NHS
- Site
- Hybrid working
- Town
- Location to be confirmed at interview
- Salary
- £50,129 - £57,365 per annum
- Salary period
- Yearly
- Closing
- 24/08/2026 23:59
Employer heading
Cyber Security Vulnerability Manager
Band 7
Digital Health and Care Wales is an ambitious organisation created by Welsh Government to lead on the digital transformation of health and care. It builds on the digital architecture and national services put in place by the NHS Wales Informatics Service over the past decade.
The organisation will lead on large-scale developments that make a significant difference to the people of Wales as well as to health and care professionals, such as expansion of the digital patient record and the creation of a National Data Resource. It will improve the way data is collected, shared and used. Please check your email account regularly. Successful applicants will receive all recruitment related correspondence via the email account registered on the application form.
All applicants are invited to apply in Welsh, any application submitted in Welsh will not be treated less favourably than an application made in English.
The salary scale for a Band 3 has been adjusted as part of the NHS Agenda for Change pay award for 2026/2027 and will be implemented in August 2026 backdated to 01 April 2026 where applicable.
Job overview
Are you passionate about cyber security and protecting critical digital services that make a real difference to people's lives? We are looking for a Cyber Vulnerability Manager to lead and develop our vulnerability management function, helping to identify, assess and reduce cyber risks across NHS Wales.
In this highly influential role, you will oversee vulnerability scanning, assessment and remediation activities, ensuring systems and applications remain secure against existing and emerging threats. Working with a wide range of stakeholders, you will provide expert advice, develop improvement initiatives and support the delivery of a strong cyber security culture across the organisation.
As a leader within the Cyber Security team, you will manage and support specialist staff, helping them to develop their skills while creating an inclusive and collaborative environment where everyone can thrive. You will also contribute to strategic cyber security planning, helping shape future security capabilities and continuously improving services for our users.
This is an exciting opportunity for someone with strong technical expertise, excellent leadership skills and a passion for continuous improvement. If you enjoy solving complex challenges, influencing positive change and working in a role where your expertise directly supports vital public services, we would love to hear from you.
Main duties of the job
As Cyber Vulnerability Manager, you will lead the delivery of vulnerability management services across a complex digital environment. You will coordinate vulnerability assessments, analyse security findings and work closely with technical teams, suppliers and service owners to ensure risks are effectively managed and remediated.
You will oversee vulnerability scanning tools, penetration testing activities and associated contracts, ensuring services remain effective, compliant and aligned with organisational objectives. Using data and intelligence from multiple sources, you will assess risk, identify trends and produce reports that support informed decision-making at operational and strategic levels.
A key part of the role will involve developing policies, procedures and standards that strengthen cyber resilience and support continuous improvement. You will lead projects, manage priorities and contribute to cyber security improvement programmes, ensuring outcomes are delivered on time and to a high standard.
The post holder will also build strong relationships across the organisation and wider NHS, providing expert guidance, delivering training and awareness activities, and helping teams understand and manage cyber security risks in a practical and collaborative way.
Working for our organisation
Digital Health and Care Wales (DHCW) is part of the NHS Wales family and has an important role in changing the way health and care services are delivered through technology and data. The organisation supports frontline staff with modern systems and access to important information about their patients, while empowering the people of Wales to manage their own health through digital NHS Wales services.
Working for DHCW offers lots of employee benefits, including flexible working, a competitive salary, 28 days of annual leave plus Bank Holidays and opportunities for career development. We are committed to recognising and celebrating our staff as the most valuable part of our organisation.
Join our game changing, life-saving team and start making a real difference to health and care services in Wales.
Detailed job description and main responsibilities
You will be able to find a full Job description and Person Specification attached within the supporting documents or please click "Apply now" to view in Trac.
- Provide professional leadership, coaching and line management to specialist cyber security staff, supporting their development and performance.
- Develop and maintain vulnerability management policies, processes and standards in line with organisational and national requirements.
- Analyse complex security data, vulnerability reports and threat intelligence to identify risks, trends and opportunities for improvement.
- Work collaboratively with technical teams, suppliers and stakeholders to coordinate remediation activity and improve security outcomes.
- Manage cyber security projects and improvement programmes, balancing competing priorities and ensuring successful delivery.
- Produce high-quality reports, dashboards, presentations and recommendations for a range of technical and non-technical audiences.
- Act as a subject matter expert, providing specialist advice on vulnerability management, cyber security best practice and emerging threats.
- Support governance, risk and compliance activities, including audits, security assessments and accreditation requirements.
- Champion an inclusive, supportive and continuous improvement culture where diverse perspectives are valued and everyone is encouraged to contribute their best work.
We welcome applications from candidates of all backgrounds and experiences.
The ability to speak Welsh is desirable for this post; Welsh and/or English speakers are equally welcome to apply.
Person specification
Qualifications
Essential criteria
- Educated to degree (or equivalent qualification / experience) in an associated professional field.
- Educated to degree (or equivalent qualification / experience) in an associated professional field.
Desirable criteria
- Professional Registration with a relevant informatics professional body.
- FEDIP Practitioner, or equivalent recognised Intermediate level Professional qualification.
Experience
Essential criteria
- Experience of leading a team and successfully identifying and managing the risks posed by vulnerabilities in the IT systems and applications within a large complex organisation.
- Experience of conducting penetration tests and vulnerability scans in a corporate environment.
- Proven ability to develop training materials to effectively accommodate participants with differing learning styles.
- Familiar with the IT environment relating to own sphere of work (own organisation and/or closely associated organisations, such as customers, suppliers, partners), in particular own organisation’s technical platforms and those that interface to them through the specialism, including those in closely related organisations.
Skills and Attributes
Essential criteria
- Technical Adaptability skills to learn and assess new methodologies or technologies quickly, understanding their wider implications and where appropriate implement them.
- Analytical skills to acquire a proper understanding of a problem or situation by breaking it down systematically into its component parts and identifying the relationships between these parts. Selecting the appropriate method/tool to resolve the problem and reflecting critically on the result, so that what is learnt is identified and assimilated.
Applicant requirements
Welsh language skills are desirable
Documents to download
Further details / informal visits contact
- Name
- Julian Jones
- Job title
- Head of Cyber Security
- Email address
- [email protected]
List jobs with Digital Health and Care Wales in Administrative Services or all sectors
















