JOB DESCRIPTION PART A: JOB DETAILS JOB TITLE: AFC BAND: T&T Security and Resilience Manager 8a HOURS: 37.5 DIRECTORATE: DEPARTMENT: REPORTING TO: BASE: IM&T Technology and Telecommunications Head of T&T Bedford, Chelmsford or Norwich PART B: JOB SUMMARY This role is central to the continuity of delivery of Technology and Telecoms services across the Trust. A high degree of autonomy is required in this role to deliver a quality service. This role will be responsible for the leadership and effective management of the IT Security agenda across the Trust, ensuring the protection of data held within the Organisation and related third parties. This role will operate as the lead in all matters related to IT Security, IT Disaster Recovery and IT Business Continuity. This role will operate at the lead in all external and internal audits that relate to and/or involve the T&T team. PART C: KEY RELATIONSHIPS Head of T&T CIO T&T team IM&T Directorate
Users at various levels within EEAST PART D: JOB SPECIFIC RESPONSIBILITIES Responsible for the effective management of the IT Security agenda across the Trust. Responsible for all matters related to IT Security, IT Disaster Recovery and IT Business Continuity across the Trust. Responsible all external and internal audits that relate to and/or involve the T&T team, ensuring action plans are written and actions completed within the appropriate timescales. Responsible for the implementation of policies, standards and controls related to IT Security across the Trust ensuring continued compliance with relevant legislation. Responsible for the implementation of policies, standards and controls related to IT Disaster Recovery across the Trust. Ensure compliance with Best Practice guidelines, including ISO27001 compliance. Responsible for the T&T Business Continuity plan, ensuring it is accurate and appropriate at all times. Work with the Trust s Business Continuity and Resilience team to ensure the T&T Business Continuity plan is tested at regular intervals. Work with the Information Governance team to ensure that all users within the Trust are aware of the security policies and their obligation to adhere to them. Work with the Deputy Head of T&T and the Technical Architect to ensure the Trust has in place at all times effective IT security solutions that balance risk and costs. Work with the Deputy Head of T&T to ensure audits and action plans are completed in a timely manner. Ensure that all changes to the IT environment comply with security requirements. Provide horizon scanning to ensure that the department is aware of and follows best practice from within the IT industry. Responsible for addressing information security issues as and when they arise. Investigate suspected security breaches of security policies and procedures. Ensure that security audits are undertaken and the results used to improve the effectiveness of the security controls. Responsible for reporting on all aspects of Information Security and Disaster Recovery.
Work with the Deputy Head of T&T to ensure contracts and suppliers (new and current) meet the appropriate security standards. Ensure input to the technical work-streams from an IT Security perspective to support any Trust initiatives. Work closely with the IM&T Programme Management Office to ensure all technical projects consider appropriate IT Security and business continuity aspects. Assess the impact of change requests within the T&T team to ensure they are fully understood and compatible with the Trust s security policies. Ensure continued support and mentoring is given to the T&T team to enable them to have a full understanding of the IT Security agenda. Ensure compliance with national guidelines and statutory regulations that are applicable to the Trust. Work with the Head of T&T and the T&T management team to agree the strategy plans for each year. Provide regular reports to the Head of T&T and the CIO as requested. Provide regular reports, documentation updates and verbal updates (including presentations) to the IM&T Directorate to ensure knowledge and plans are shared appropriately. Ensure all major issues and risks are escalated to senior management as appropriate using the agreed escalation routes and policies. Produce risk assessments related to the Trust s infrastructure and systems. Work with the wider IM&T directorate to ensure all projects and programmes of work that have a technical angle fit with the Trust s IT Security policies. Communicate effectively with a wide range of stakeholders both within the Trust and outside of the Trust. Present technical and complex areas to stakeholders who do not have technical backgrounds, ensuring they understand the background and impact of changes and planned work. In conjunction with the Deputy Head of T&T and the Technical Architect ensure that an appropriate business continuity regime is designed into all programmes of work. Work with members of the T&T team and the wider Trust in the completion of business cases that have a potential impact on IT Security. PART E: GENERAL RESPONSIBILITIES
Flexibility: The postholder may be required to work at any of the Trust s sites in line with service needs. Infection Prevention and Control: All Trust employees have duties under the Health and safety at Work etc. Act 1974 which have a bearing on the prevention and control of infection in particular: Staff are expected to understand their responsibilities as outlined in the infection prevention and control policy and related guidelines, comply with all stated systems and maintain their knowledge of infection prevention and control relative to their role. Confidentiality, Data Protection, Freedom of Information and Computer Misuse: All staff must ensure confidentiality and security of information dealt with in the course of performing their duties. They must comply with and keep up to date with Trust policies and legislation on confidentiality, data protection, freedom of information and computer misuse. Communication: All staff should be able to communicate effectively with people who use services and other staff, to ensure that the care, treatment and support of people who use services is not compromised. Health, Safety, Security and risk management: All staff are required to adhere to and act consistently with all relevant health and safety legislation and Trust policies and procedures in order to ensure that their own and the health, safety and security of others is maintained. This will include identifying and reporting all risks to health and safety, security of equipment and property, use of necessary safety devices and protective clothing and the achievement of the Trust s objectives in accordance with the Trust s risk management strategy and policies. Major Incident: In the event of a major incident or civil unrest or other potential large scale service disruptions (e.g. Pandemic) all East of England Ambulance Service NHS Trust employees will be expected to report for duty on notification. All employees are also expected to play an active part in preparation for a major incident, civil unrest or other potential large scale service disruptions (e.g. Pandemic) and to undertake training as necessary. Equality and Diversity: Actively promote the Trust s commitment to equality and diversity by treating all patients, colleagues and visitors with dignity and respect and comply with related policies including Equal Opportunities Policy, Dignity at Work Policy, Recruitment and Selection Policy etc. Mandatory, job related training and CPD: Take a proactive approach to own personal development in order to ensure that skills set is aligned to the demands of the role as it evolves and develops to meet the organisation s changing needs. This will include full participation in KSF and appraisal. Safeguarding children and vulnerable adults: All employees have a responsibility for protecting, safeguarding and promoting the welfare of children and vulnerable adults. Further information about the Trust commitment to this and your responsibilities can be sought from the Trust s Child Protection Leads. No Smoking Policy: East of England Ambulance Service NHS Trust is a no smoking Trust and all staff must comply with the Trust s no smoking policy. Data Quality: It is the responsibility of all employees to ensure data is of a high quality standard, in order to support the Trust in providing a quality service. Data
must be accurate, valid, reliable, timely, relevant and complete. For further information on the Trust s commitment to this, please refer to the Trust s Data Quality Policy.
PART F: STRUCTURE CHART
PART G: PERSON SPECIFICATION Factors Essential Desirable Education / Qualifications Degree, other tertiary qualification or evidence of relevant on-job qualification. Relevant IT Security qualification, or evidence of meeting required standard Relevant post-graduate degree or relevant on-job training. Full UK Driving Licence. Recognised qualification in the field of IT, computing, Business Systems or similar. For example MCSE. ITIL qualification PRINCE2 project management qualification, or other project management qualification Evidence of on-going continuous professional development. Skills and Competencies Ability to think strategically and work methodically towards achieving solutions. Ability to maintain and build good professional relationships with colleagues from a variety of care backgrounds Ability to organise and prioritise tasks and deliver to timetables. Able to interpret the working practices of others and manage the introduction of new ways of working resolving issues as they arise Ability to understand, amend and work with complex documentation. Structured approach to documentation. Wide ranging IT appreciation. Good communication skills including the ability to communicate complex information in an understandable manner to non-technical staff members. Ability to communicate
effectively (verbal, written and presentations) to all levels of clinical and nonclinical staff and management. Good problem solving skills, including imaginative in finding solutions using different mechanisms. Ability to analyse and investigate complex technical issues. Ability to generate and analyse business cases and budgets in relation to Trust needs and priorities. Knowledge and Experience Experience of at least 10 years of working in IT. Experience of managing large IT teams. Experience of mentoring staff. Substantial experience of the IT Security agenda within the public sector. Extensive knowledge of ICT security disciplines, products, standards, policies and terminology Experience in the development and monitoring of disaster recovery plans and contingency planning arrangements Experience of at least 5 years working in an IT team in an Ambulance Service. external/internal audit and the associated action plans. delivery to time, and on budget, major IT projects. formulating technical strategies. Ability to demonstrate an indepth knowledge of ICT developments, including national developments. Experience of at least 15 years of working in IT support, including a minimum 5 years dealing with IT Security. Experience of at least 5 years in an IT management position in an Ambulance Service. Proven record in applying IT Management Responsibilities in an Ambulance Service, including evidence of input into projects that impact the wider Trust. Experience of the following:- LAN, WAN, Wireless technologies Computer Aided Dispatch systems The CAD associated interfaces. Telephony Systems including analogue, digital and VoIP services. Windows Server and workstation operating systems. Exchange Server. Firewall technologies Active directory Digital Radio implementing ITIL processes in an organisation.
Proven record in applying IT Management Responsibilities in an NHS organisation, including evidence of input into projects that impact the wider Trust. advising of changes to policies and writing new policies which have an impact on the whole Trust, including clinical areas. making judgements on complex IT problems where there is no precedent. Personal Attributes Self-confident and enthusiastic. Good organisational skills ability to tackle more than one task at once. Ability to stay composed with conflicting priorities Ability to show tact and discretion Ability to develop complex processes and procedures with minimal direction. Ability to work on own initiative and take responsibility effectively. Prioritise and manage own workload and meet deadlines under pressure. Other Ability to travel between sites (driving licence)
PART H: JOB DESCRIPTION RECORD This job description reflects the current main organisational priorities for the post. In the context of rapid change taking place within the NHS/Trust, these priorities will develop and change in consultation with the postholder in line with service needs and priorities. Date Created: Created by: Postholder s signature: