Current jobs at Gloucestershire Hospitals
Information Governance Data Security and Protection Specialist
Band 7
Main area Information Governance Grade Band 7 Contract Permanent Hours Full time - 37.5 hours per week Job ref 318-26-T0574
Site Victoria Warehouse Town Gloucester Salary £49,387 - £56,515 (pa, pro rata if part-time) Salary period Yearly Closing 31/08/2026 23:59
At Gloucestershire Hospitals, our people are at the heart of everything we do. As the county’s largest employer, we are proud to provide high-quality acute, elective, and specialist services to more than 650,000 people across our county. Our care is delivered across Gloucestershire Royal, Cheltenham General and Stroud Maternity Hospital.
With over 9,000 employees representing more than 95 nationalities, bringing together a mix of cultures and experiences to the care that we deliver. Whether you’re beginning your NHS journey or looking to take the next step in your career, this is an exciting time to join us. We’re investing heavily in innovation, research, and transformation, with more than 100 active clinical studies and major developments underway across our hospitals.
We take pride in working as one team, driven by a shared ambition to grow, develop, and continually improve. Every contribution is valued and by combining our collective strengths, we support not only our diverse communities but one another. You can expect a warm, supportive culture and colleagues who are passionate about teamwork, professional development and delivering exceptional care. We offer structured development programmes, mentoring and leadership opportunities to help you progress in your career.
We are committed to fostering an inclusive environment where everyone feels they belong. By joining our Trust, you will benefit from a comprehensive package that includes flexible working opportunities, generous annual leave, the NHS pension scheme, competitive bank rates, local discounts, access to on-site nurseries, reduced public transport costs, reward and recognition schemes and a wide range of health and wellbeing initiatives.
Be part of Gloucestershire Hospitals, explore your future with us today.
Job overview
Information Governance Data Security and Protection Specialist, Band 7
The post holder supports the Head of Information Governance to ensure that the Trust meets its obligations under Data Protection legislation and ensures general awareness throughout the Trust on Information Governance matters.
The primary focus of the role is to manage the IG/Access to Records (DSARs) team, undertaking data protection Impact assessments (DPIAs) provide support and guidance to all staff, including coordination of data breach investigation and ensuring the Trust has robust processes and plans in place to achieve and maintain UK GDPR compliance.
Main duties of the job
- The post holder will be a specialist in the delivery of the Data Security and Protection Toolkit annual return, Data Protection Impact Assessments, Information Asset Register maintenance, drafting and review of data sharing and data processing agreements and act as a subject matter expert on data protection and data security for the Trust, in accordance with national and local policy
- The post holder will conduct and follow up on Information Governance audits across the Trust and draft associated reports. They will ensure that staff, stakeholders, contractors and members of the public are aware of their rights under Data Protection legislation
- The post holder will identify areas in which the Trust is inadequately covered by IG and IT security policies and procedures and, in consultation with the cyber security specialists, information governance team and IT service team, develop new policies and procedures to cover these areas. Supporting senior managers in presenting these to the relevant Boards or other approval bodies
- The post holder will support the maintenance of data security and data protection training and learning programmes. They will also provide expert IG advice to staff at all levels, departments and corporate / clinical functions
- The post holder will have excellent communication skills, be a compassionate leader, promote good IG with all their exchanges, and will be empowered to make decisions in line with policies and procedures
Working for our organisation
We take pride in placing people at the centre of everything we do, working together as a united team. Driven by a shared ambition to continually grow, develop, and learn, we recognise and value every contribution. By combining our experience and skills, we not only support our vibrant, diverse communities, but also support one another.
With a team of over 9,000 employees, we are proud to be the largest employer in Gloucestershire and rank among the top 10 largest Trusts in the South West region. By joining our Trust, you will benefit from an excellent package that includes exclusive benefits, flexible working opportunities and the chance to gain valuable experience in one or both of our innovative hospitals.
As well as generous annual leave allowance, you will have access to the excellent NHS pension scheme, competitive bank rates, discounts at local shops and restaurants, access to two on-site nurseries, discounted public transport, reward and recognition and a range of health and wellbeing initiatives to support you.
Detailed job description and main responsibilities
Key operational results areas
- Work with the DPO to ensure the completion of the Trust’s Data Security and Protection Toolkit assessment, collating evidence, and undertake compliance audits.
- To advise on and provide updates to IG and cybersecurity e-learning training to ensure staff have access to up to date and relevant IG and Data security and protection training.
- To ensure the development and delivery of the UK GDPR compliance action/improvement plans, monitor progress and report.
- To ensure the Trust's contractors and support organisations have adequate IG arrangements in place.
- To ensure the development of local information sharing agreements as required.
- To provide support/undertake date privacy impact assessments.
- To ensure fair processing notices are adequate for flows of personal confidential information.
- To support the Trusts Information Asset Owners in information asset management and assist with undertaking risk assessments.
- To support the management and response to information security incidents.
- To maintain on-going personal development and knowledge of data protection laws, issues and developments.
- Freedom to take actions as the lead specialist, based on own interpretation of policy, to conduct complex investigations into suspected or actual breaches of data protection and security and provide formal written reports advising how legislation and or policy should be interpreted directly to the Information Asset owner, Human resources business partner and service leads. These cases could lead to disciplinary action being taken against staff.
- Participate in relevant internal and external working groups/projects, services and initiatives to provide information and analytical advice and expertise.
- Liaise with senior managers of stakeholder organisations, NHS cyber security teams, the Counter Fraud Service, the Police and external organisations, as required, when investigating incidents.
- Investigations into abuse of IT services such as internet and email may occasionally expose the post holder to distressing images and require the post holder to act as a professional witness in disciplinary hearings etc.
- The alignment of digital and operational processes with legislative, NHS and business security requirements.
- Work with the wider digital team in the identification and management of data protection and data security risks ensuring that digital and operational services maintains compliance in line with the overall Trust corporate governance framework, designing and maintaining appropriate data protection and data security controls and plans with procedures for their operation and maintenance.
- Work with services and digital teams to Identify and classify information assets and the level of control and protection required.
- Ensuring that the confidentiality, integrity and availability of trust information is maintained and the public trust in the organisation is promoted and maintained.
- Ensuring that all access to services by external partners and suppliers is subject to contractual agreements and appropriate responsibilities documented.
- Be responsible for a high standard of work supporting the delivery of Information Governance to quality standards and in a cost-effective manner. Maintain documentation and associated plans with regular team meetings to monitor progress and resources.
- Overseeing team members to deliver the requirements listed above; engage and liaise with key stakeholder, in particular:
- To support the delivery of day-to-day activities and projects
- Support the development and maintenance of a high performing IG team
- Advocate data protection and cyber security during all interactions with staff across all roles and levels within the trust.
- At as Information asset administrator for IG related assets including the Trust’s Information asset register.
Customer care for patients and/or service users
- To act as a champion for patients and their interests in relation to data security and protection
- To ensure all staff and occasional public and patient contact with the office is of the highest professional standard
Leadership and management
- To provide line management for the IG team
- Responsible for undertaking appraisal and personal development for staff within the team
- To support, motivate and develop staff within the team to ensure that they are able to deliver the trust and team objectives
- Liaise with other Managers to share best practice
- Plan, organise, deliver, and review regular IG and ad hoc stakeholder awareness workshops and training sessions on data security and data protection that raise the awareness of staff of information governance issues and ensure their compliance with policies and procedures, ensuring the collaboration of Human Resources, Training, Data Protection and Information Governance Lead. Take personal responsibility for delivering some of these awareness training programmes. Develop materials to enable others to deliver training in a standard manner
Communications and working relationships
- The post holder will be a contact point in the organisation for IG and provide advice to IAOs, IAAs and liaise with the DPO, Caldicott Guardian and SIRO.
- Provide advice and take action, where necessary, in response to Audit findings and recommendations in respect of information governance.
- Work internally in the development and implementation of IG policies and procedures.
- Act as a consultant to projects, advising on matters relating to information governance & security.
- To work with the Head of Information Governance (DPO) to ensure that the Trust fully complies with relevant legislation, agreed policies and procedures.
- To deputise for the Head of Information Governance (DPO) as required in representing the Trust both on internal and external user groups ensuring that the Trust's priorities are effectively communicated, promoted and implemented.
- Ensure that Trust staff know how to report any data protection and data security breaches, incidents, malfunctions and suspected system weaknesses and threats.
- Management of IT security policies, and supporting set of policies, and their controls including their development and review and facilitation of their ratification
- Responsible for proposing and drafting changes, implementation and interpretation to policies and guidelines.
- Ensure that IT security and IG policy is enforced and communicated to all parties.
- Where necessary to liaise with external organisations on IT/cyber security matters, drafting and implementing joint policies and procedures and ensuring external network connections adhere to all appropriate security policies.
- Identify areas within the trust that are inadequately covered by IT/cyber security policies and procedures and, in consultation with operational manager IT specialists, and Data Protection Officer, develop new policies and procedures to cover these areas. Support Digital senior leads in presenting these to the relevant Boards or other approval bodies.
- The post holder will need to maintain a good knowledge of emerging policies from government departments. This will assist in the thinking and definition of the strategy discussions for the network and stakeholders.
Key Relationships:
- Head of Information Governance (DPO)
- Chief Delivery & Governance Officer
- Head of Records, Digital Risk & Compliance
- Health and Corporate Records manager
Information Governance/Access to Records team
- Cyber security team
- Information Asset Owners (IAO)
- Information Asset Administrators (IAA)
- IG colleagues in local partner organisations
Research and development
- Develop and implement ad-hoc audit programmes to test system and data security measures, review findings and improve those system and data security measures
- Plan, develop and evaluate methods and processes for gathering, analysing, interpreting and presenting data and information
Person specification
Qualifications
- Degree level or equivalent in a discipline directly relevant to the role
- Evidence of CPD
- SSCP/CISSP/CISMP
Experience
- Data protection and data security risk management in an enterprise setting
- Significant experience of working in, or managing, an IT Security or IG function
- Demonstrable experience in delivery of training / education to large groups of staff at all levels of the organisation
- Experience of managing and motivating a team and reviewing performance of the individuals
- Previous experience of working within the NHS or other healthcare setting
- Previous experience of report preparation and delivery
- Previous experience of risk assessment
- Experience of identifying and interpreting National policy. Experience of researching best practice (globally, private and public sector), interpreting its relevance and processes/ practices which could be implemented successfully to achieve system reform (advising on policy implementation)
We reserve the right to expire vacancies prior to the advertised closing date once a sufficient number of applications have been received.
You will only be contacted by the Recruitment Team via email if you are shortlisted for this post. Please ensure therefore that you check your e‑mail account regularly.
If you require sponsorshipfor a visa to work in the UK, to avoid disappointment, please check to ensure you are eligible under theUKVI points based system
Employer certification / accreditation badges