Information Governance Data Security and Protection Specialist

Allscreens Nationwide Ltd

New Jersey

On-site

USD 90,000 - 130,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Alscreens Nationwide Ltd. is seeking an Information Governance Data Security and Protection Specialist to support data protection and cyber security within a healthcare governance context.

You will drive training, assess privacy impacts, and oversee GDPR action plans while coordinating with the DPO and IG teams. The role involves leading information asset management, risk assessments, and incident response, ensuring staff compliance with policy and safeguarding patient information across the

Qualifications

  • Experience delivering information governance and cybersecurity training to staff.
  • Ability to conduct data privacy impact assessments.
  • Proven track record in information risk and audit activities.

Responsibilities

  • Support completion of Trusts Data Security Toolkit assessment and audits.
  • Advise on IG/cybersecurity training updates for staff.
  • Develop GDPR compliance action and improvement plans.
  • Lead information asset management and risk assessments.
  • Respond to information security incidents and maintain policies.

Skills

Information governance
Cybersecurity
Audit coordination
DPO liaison
Risk assessments
Staff training
Policy development
Incident response

Tools

Data Protection Toolkit

Job description

Information Governance Data Security and Protection Specialist
  • Work with the DPO to ensure the completion of the Trusts Data Security and Protection Toolkit assessment, collating evidence, and undertake compliance audits.
  • To advise on and provide updates to IG and cybersecurity e-learning training to ensure staff have access to up to date and relevant IG and Data security and protection training.
  • To ensure the development and delivery of the UK GDPR compliance action/improvement plans, monitor progress and report.
  • To ensure the Trust's contractors and support organisations have adequate IG arrangements in place.
  • To ensure the development of local information sharing agreements as required.
  • To provide support/undertake date privacy impact assessments.
  • To ensure fair processing notices are adequate for flows of personal confidential information.
  • To support the Trusts Information Asset Owners in information asset management and assist with undertaking risk assessments.
  • To support the management and response to information security incidents.
  • To maintain on-going personal development and knowledge of data protection laws, issues and developments.
  • Freedom to take actions as the lead specialist, based on own interpretation of policy, to conduct complex investigations into suspected or actual breaches of data protection and security and provide formal written reports advising how legislation and or policy should be interpreted directly to the Information Asset owner, Human resources business partner and service leads. These cases could lead to disciplinary action being taken against staff
  • Participate in relevant internal and external working groups/projects, services and initiatives to provide information and analytical advice and expertise.
  • Liaise with senior managers of stakeholder organisations, NHS cyber security teams, the Counter Fraud Service, the Police and external organisations, as required, when investigating incidents.
  • Investigations into abuse of IT services such as internet and email may occasionally expose the post holder to distressing images and require the post holder to act as a professional witness in disciplinary hearings etc.
  • The alignment of digital and operational processes with legislative, NHS and business security requirements.
  • Work with the wider digital team in the identification and management of data protection and data security risks ensuring that digital and operational services maintains compliance in line with the overall Trust corporate governance framework, designing and maintaining appropriate data protection and data security controls and plans with procedures for their operation and maintenance
  • Work with services and digital teams to Identify and classify information assets and the level of control and protection required.
  • Ensuring that the confidentiality, integrity and availability of trust information is maintained and the public trust in the organisation is promoted and maintained.
  • Ensuring that all access to services by external partners and suppliers is subject to contractual agreements and appropriate responsibilities documented.
  • Be responsible for a high standard of work supporting the delivery of Information Governance to quality standards and in a cost-effective manner. Maintain documentation and associated plans with regular team meetings to monitor progress and resources.
  • Overseeing team members to deliver the requirements listed above; engage and liaise with key stakeholder, in particular: To support the delivery of day-to-day activities and projects Support the development and maintenance of a high performing IG team Advocate data protection and cyber security during all interactions with staff across all roles and levels within the trust. At as Information asset administrator for IG related assets including the Trusts Information asset register. Customer care for patients and/or service users
  • To act as a champion for patients and their interests in relation to data security and protection
  • To ensure all staff and occasional public and patient contact with the office is of the highest professional standard Leadership and management
  • To provide line management for the IG team
  • Responsible for undertaking appraisal and personal development for staff within the team
  • To support, motivate and develop staff within the team to ensure that they are able to deliver the trust and team objectives
  • Liaise with other Managers to share best practice
  • Plan, organise, deliver, and review regular IG and ad hoc stakeholder awareness workshops and training sessions on data security and data protection that raise the awareness of staff of information governance issues and ensure their compliance with policies and procedures, ensuring the collaboration of Human Resources, Training, Data Protection and Information Governance Lead. Take personal responsibility for delivering some of these awareness training programmes. Develop materials to enable others to deliver training in a standard manner
  • Communications and working relationships
  • The post holder will be a contact point in the organisation for IG and provide advice to IAOs, IAAs and liaise with the DPO, Caldicott Guardian and SIRO.
  • Provide advice and take action, where necessary, in response to Audit findings and recommendations in respect of information governance.
  • Work internally in the development and implementation of IG policies and procedures.
  • Act as a consultant to projects, advising on matters relating to information governance & security.
  • To work with the Head of Information Governance (DPO) to ensure that the Trust fully complies with relevant legislation, agreed policies and procedures.
  • To deputise for the Head of Information Governance (DPO) as required in representing the Trust both on internal and external user groups ensuring that the Trust's priorities are effectively communicated, promoted and implemented.
  • Ensure that Trust staff know how to report any data protection and data security breaches, incidents, malfunctions and suspected system weaknesses and threats.
  • Management of IT security policies, and supporting set of policies, and their controls including their development and review and facilitation of their ratification
  • Responsible for proposing and drafting changes, implementation and interpretation to policies and guidelines.
  • Ensure that IT security and IG policy is enforced and communicated to all parties.
  • Where necessary to liaise with external organisations on IT/cyber security matters, drafting and implementing joint policies and procedures and ensuring external network connections adhere to all appropriate security policies.
  • Identify areas within the trust that are inadequately covered by IT/cyber security policies and procedures and, in consultation with operational manager IT specialists, and Data Protection Officer, develop new policies and procedures to cover these areas. Support Digital senior leads in presenting these to the relevant Boards or other approval bodies.
  • The post holder will need to maintain a good knowledge of emerging policies from government departments. This will assist in the thinking and definition of the strategy discussions for the network and stakeholders.
Key Relationships
  • Head of Information Governance (DPO)
  • Chief Delivery & Governance Officer
  • Head of Records, Digital Risk & Compliance
  • Caldicott Guardian
  • Health and Corporate Records manager Information Governance/Access to Records team
  • Cyber security team
  • Digital Senior Leadership Team
  • Clinicians
  • Senior Information Risk Owner (SIRO)
  • Information Asset Owners (IAO)
  • Information Asset Administrators (IAA)
  • IG colleagues in local partner organisations
Research and development
  • Develop and implement ad-hoc audit programmes to test system and data security measures, review findings and improve those system and data security measures
  • Plan, develop and evaluate methods and processes for gathering, analysing, interpreting and presenting data and information
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Governance & Data Security Lead
Information Governance & Data Security Lead

Allscreens Nationwide Ltd • New Jersey

On-site
USD 90,000 - 130,000
Quality, Information, Safety and Governance (QISG) Co-ordinator
Quality, Information, Safety and Governance (QISG) Co-ordinator

Allscreens Nationwide Ltd • Town of Ashford (NY)

Hybrid
USD 30,000 - 40,000
NHS Pension Scheme
Annual leave above statutory minimum
Flexible working
21441 - Security Risk & Assurance Practitioner
21441 - Security Risk & Assurance Practitioner

Allscreens Nationwide Ltd • National (WA)

On-site
USD 85,000 - 125,000
Senior Data Privacy & Governance Analyst
Senior Data Privacy & Governance Analyst

Alliant Insurance Services • Kentucky

On-site
USD 110,000 - 165,000
Security Analyst
Security Analyst

DigitalXForce Corporation • United States

On-site
USD 70,000 - 110,000
Information Technology Governance Manager
Information Technology Governance Manager

Green Key Resources • New York (NY)

On-site
USD 120,000 - 170,000
IT Security Manager
IT Security Manager

True North Consulting, LLC • Olathe (KS)

On-site
USD 90,000 - 120,000
Senior Data Privacy & Governance Analyst
Senior Data Privacy & Governance Analyst

Alliant • United States

On-site
USD 120,000 - 180,000
Information Governance Support Officer
Information Governance Support Officer

NHS Ayrshire & Arran • Palestine (TX)

On-site
USD 38,000 - 49,000
Information Security Manager
Information Security Manager

Confidential • Pittsburgh

Hybrid
USD 140,000 - 190,000