UK Biobank
Cheadle, Staffordshire
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
Salary is competitive and commensurate with experience, plus a 14.5% pension contribution and a relocation package where applicable. Shape the future of information security for one of the world's most important organisations supporting biomedical research. At UK Biobank, information security isn't simply about protecting systems, it's about safeguarding one of the world's most valuable health research resources. Our data is trusted by more than 22,000 approved researchers across over 60 countries, helping advance our understanding of cancer, dementia, cardiovascular disease, mental health and hundreds of other conditions. Protecting that trust while enabling scientific discovery is fundamental to everything we do. We're entering one of the most significant periods of technology transformation in our history. As we continue to invest in modern cloud platforms, AI-enabled services, new digital capabilities and our £127.6 million headquarters at Manchester Science Park, we're looking for a Director of Information Security to lead the next phase of our information security maturity. This isn't a role focused on maintaining an established security function. It's an opportunity to shape and define a world-class capability Can you do it? As Director of Information Security, you'll report directly to our Chief Technology Officer and provide strategic leadership for information security across UK Biobank. You'll be responsible for ensuring our governance, cyber security, identity management, business continuity, and risk management capabilities continue to evolve alongside an increasingly complex threat landscape. Working closely with colleagues across Data and Technology, Legal, and the wider organisation, you'll embed security into organisational decision-making, providing confidence that our platforms remain secure, resilient, and compliant while continuing to support innovation and world-leading research. This is a unique opportunity to build on the strong foundations already in place while leading the next phase of UK Biobank's security maturity. As we continue our wider technology transformation, you'll shape the organisation's security strategy, strengthen operational capability, and help embed security into every aspect of our cloud platforms, digital services, AI initiatives, and future technologies. You'll lead a growing Information Security function, with the opportunity to develop capability, evolve the team, and foster a positive security culture across the organisation. Working at both strategic and operational levels, you'll influence Executive Leadership and Board discussions while providing the leadership needed to respond to emerging threats, manage organisational risk, and ensure security enables innovation rather than becoming a barrier to it. This is a unique and rare opportunity to shape the future of information security within one of the world's leading biomedical research organisations, protecting data that supports thousands of researchers across the globe while helping deliver the next generation of scientific discovery. You will be responsible for Developing, implementing, and creating a comprehensive information security strategy, providing direction and support to ensure effective implementation of security controls. Conducting regular risk assessments, audits, tests, and modelling to identify and evaluate vulnerabilities and potential threats. Providing regular updates to the executive leadership team and represent information security at board, audit, and governance committees Establishing metrics and enforcing information security policies, procedures, and guidelines aligned with standards and frameworks, particularly ISO27001 and the NCSC Cyber Assessment Framework, as well as regulatory requirements and industry best practices. Ensuring that critical data and assets have been identified, classified, and subject to appropriate controls, including for handling, ownership, and destruction. Leading the organisation's response to major cyber incidents, including providing out-of-hours and crisis-level support when required. Promoting and communicating a culture of security awareness so all staff understand their role in maintaining information security. Managing the Information Security budget, setting investment priorities, and contributing to financial planning. Is this 'you'? To be successful, you will have: Significant experience in information security management, with a proven track record of leadership in the field. Relevant industry certifications, preferably CISSP, CISM, or CCISO. Strong knowledge of information security standards, frameworks, and best practices. Previous experience of ISO270001 is a key requirement. A clear understanding of the laws and regulations associated with controlling and processing personal data, directing organisation responses to cyber incidents. Strong knowledge and understanding of the cyber threat landscape. Experience securing cloud environments with a knowledge of the vulnerability detection tools and security services available in AWS and /or MS Azure. Experience of deploying controls across networking, end-user compute, identity and access management, software development, and business operations to minimise the likelihood of security incidents. Experience of recruiting specialist staff, building teams, and developing existing colleagues through training, coaching and mentoring. Working hours are 35 hours per week, Monday to Friday, with 3 days onsite and hybrid working available. The role will be based at Greenheys, Manchester Science Park's headquarters. Our passion for diversity and equality means creating a work environment for all employees that is welcoming, respectful, engaging, and enriched with opportunities for personal and professional development. We actively welcome applications from people with disabilities, long-term health conditions, neurodivergent candidates, and those with diverse thinking styles. We are committed to making reasonable adjustments throughout our recruitment process and in the workplace so that everyone can perform at their best. If you require any adjustments during the recruitment process, please contact Tommy Wilson at so we can support you. Your Wellbeing Matters to Us Colleagues at UK Biobank often highlight feeling supported, included, and connected to meaningful work, with wellbeing and work-life balance genuinely valued across teams. We're proud to offer a benefits package that supports your health, financial security, and development from day one: Currently 14.5% employer contribution to the USS Pension Scheme Healthcare Cash Plan to help cover everyday healthcare costs ️ 30 days' annual leave, plus bank holidays Buy up to 5 additional days' annual leave through our Holiday Buy Scheme A paid day off for your birthday Enhanced maternity, paternity, adoption and shared parental pay Hybrid and flexible working for many office-based roles Up to 6 months' full sick pay ️ Free on-site gym Subsidised lunch when working on site ️ Life Assurance Cycle to Work Scheme Season Ticket Loan Training and development opportunities, including a £500 annual personal development allowance Paid professional subscriptions, where applicable ️ Employee Discounts Portal Wellbeing support, including an Employee Assistance Programme Free annual flu vaccination and Hepatitis B vaccination, where applicable An active social committee with regular social events Free on-site parking Payroll Giving (Give As You Earn) The job advert closing date may change, so early applications are encouraged. About UK Biobank UK Biobank is a large-scale biomedical database and research resource containing in-depth genetic and health information from half a million UK participants. The database, the largest and most comprehensive of its kind in the world, is anonymised and made widely accessible by UK Biobank to global researchers who use it to find new scientific discoveries about common and life-threatening diseases - such as cancer, heart disease and stroke which strike in mid-later life. UK Biobank is an innovative organisation with over 350 staff across four sites in the UK that fosters an engaging environment and supports the development of our staff. Our dedicated teams work alongside the world's leading biomedical scientists in our joint mission to improve public health.
NCC Group plc
Manchester, Lancashire
Director, Digital Forensics & Incident Response (Global) Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Matt Hull (Open to Associate Director with progression path to Director) Description The purpose of this role is to lead NCC Group's global Digital Forensics and Incident Response (DFIR) capability, ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The global DFIR team will consist of regionally distributed colleagues, delivering a consistent, scalable, and market-leading service that protects client assets, reputation, and business operations. The role is responsible for setting strategic direction, driving operational excellence, evolving people, process and technology capabilities, and supporting commercial growth through the conversion of incident response engagements into ongoing security service opportunities. The Director, DFIR will be responsible for ensuring robust cyber resilience capabilities, overseeing major cyber incidents, maintaining advanced forensic practices, and ensuring the function remains aligned with changing client requirements, regulatory obligations, and emerging cyber threats. The role also serves as a senior leader within the Cyber Intelligence and Response business, influencing stakeholders and driving continuous service improvement. A key part of the role is engaging and collaborating with leaders across NCC Group to achieve the following ambitions: Define and execute a global DFIR strategy aligned to business priorities and risk appetite. Strengthen cyber incident preparedness, response, and recovery capabilities. Develop and scale advanced digital forensic capabilities across endpoint, network, and cloud environments. Embed lessons learned from incidents, exercises, and reviews into continuous improvement initiatives. Drive operational excellence through effective capacity planning, resource management, and performance measurement. Support business growth by identifying opportunities to transition incident response engagements into long-term security services. Key Responsibilities Lead the global DFIR function, ensuring effective delivery of digital forensics and incident response services across multiple regions. Define and execute the global DFIR strategy, ensuring alignment with business objectives, client needs, and organisational risk appetite. Manage regional performance through effective resource planning, utilisation management, and alignment to revenue forecasts and delivery demand. Implement clear measures of capacity, utilisation, and operational performance to optimise scalability and efficiency. Drive effective offshoring strategies that balance quality, efficiency, and cost. Oversee the management of major cyber incidents and act as the senior escalation point during high severity events. Ensure coordinated incident response across technical teams, business leadership, clients, and external stakeholders. Drive effective containment, remediation, recovery, and post incident review activities. Lead the development of advanced forensic capabilities across endpoint, network, cloud, and emerging technology environments. Ensure forensic readiness, evidential integrity, and compliance with legal and regulatory requirements. Maintain incident response plans, playbooks, and testing programmes through simulations and exercises. Partner with Legal, Risk, Compliance, and senior business stakeholders to meet regulatory and client obligations. Define, measure, and report on key operational KPIs, including quality, responsiveness, accuracy, and customer satisfaction. Build, mentor, and lead a high performing, diverse, and globally distributed DFIR organisation. Foster a culture of innovation, collaboration, continuous learning, and operational excellence. Represent NCC Group externally through industry forums, conferences, and customer engagements, demonstrating thought leadership in DFIR and cyber resilience. Skills, Knowledge & Expertise Extensive experience leading Digital Forensics and Incident Response (DFIR) teams within complex cyber security environments. Proven experience developing and executing global operational strategies aligned to business objectives. Strong experience managing large scale cyber incidents, breaches, and crisis response activities. Expertise in digital forensics across endpoint, network, cloud, and hybrid environments. Experience building, developing, and retaining high performing technical teams across multiple geographies. Strong process improvement and operational transformation experience. Experience managing budgets, forecasting demand, and optimising resource allocation. Ability to influence and communicate effectively with executive stakeholders, clients, regulators, and technical teams. Strong written and verbal communication skills, with the ability to translate complex cyber security concepts into business focused language. Experience leading organisational change and technology transformation initiatives. Experience within Managed Security Services (MSSP) or large scale cyber security consulting environments. Experience supporting commercial growth, sales enablement, and service expansion opportunities. Strong knowledge of current cyber threat trends, regulatory requirements, and industry best practices. Active participation in industry forums, conferences, or recognised cybersecurity communities. Job Benefits We have a high performance culture which is balanced evenly with world class well being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Enhanced Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme. Financial & Investment Benefits: Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes. Green Car Scheme. Cycle to Work Scheme. Special Time Off for important life events. Enhanced Family Planning, Maternity, and Paternity Support.
Director, Digital Forensics & Incident Response (Global) Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Matt Hull (Open to Associate Director with progression path to Director) Description The purpose of this role is to lead NCC Group's global Digital Forensics and Incident Response (DFIR) capability, ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The global DFIR team will consist of regionally distributed colleagues, delivering a consistent, scalable, and market-leading service that protects client assets, reputation, and business operations. The role is responsible for setting strategic direction, driving operational excellence, evolving people, process and technology capabilities, and supporting commercial growth through the conversion of incident response engagements into ongoing security service opportunities. The Director, DFIR will be responsible for ensuring robust cyber resilience capabilities, overseeing major cyber incidents, maintaining advanced forensic practices, and ensuring the function remains aligned with changing client requirements, regulatory obligations, and emerging cyber threats. The role also serves as a senior leader within the Cyber Intelligence and Response business, influencing stakeholders and driving continuous service improvement. A key part of the role is engaging and collaborating with leaders across NCC Group to achieve the following ambitions: Define and execute a global DFIR strategy aligned to business priorities and risk appetite. Strengthen cyber incident preparedness, response, and recovery capabilities. Develop and scale advanced digital forensic capabilities across endpoint, network, and cloud environments. Embed lessons learned from incidents, exercises, and reviews into continuous improvement initiatives. Drive operational excellence through effective capacity planning, resource management, and performance measurement. Support business growth by identifying opportunities to transition incident response engagements into long-term security services. Key Responsibilities Lead the global DFIR function, ensuring effective delivery of digital forensics and incident response services across multiple regions. Define and execute the global DFIR strategy, ensuring alignment with business objectives, client needs, and organisational risk appetite. Manage regional performance through effective resource planning, utilisation management, and alignment to revenue forecasts and delivery demand. Implement clear measures of capacity, utilisation, and operational performance to optimise scalability and efficiency. Drive effective offshoring strategies that balance quality, efficiency, and cost. Oversee the management of major cyber incidents and act as the senior escalation point during high severity events. Ensure coordinated incident response across technical teams, business leadership, clients, and external stakeholders. Drive effective containment, remediation, recovery, and post incident review activities. Lead the development of advanced forensic capabilities across endpoint, network, cloud, and emerging technology environments. Ensure forensic readiness, evidential integrity, and compliance with legal and regulatory requirements. Maintain incident response plans, playbooks, and testing programmes through simulations and exercises. Partner with Legal, Risk, Compliance, and senior business stakeholders to meet regulatory and client obligations. Define, measure, and report on key operational KPIs, including quality, responsiveness, accuracy, and customer satisfaction. Build, mentor, and lead a high performing, diverse, and globally distributed DFIR organisation. Foster a culture of innovation, collaboration, continuous learning, and operational excellence. Represent NCC Group externally through industry forums, conferences, and customer engagements, demonstrating thought leadership in DFIR and cyber resilience. Skills, Knowledge & Expertise Extensive experience leading Digital Forensics and Incident Response (DFIR) teams within complex cyber security environments. Proven experience developing and executing global operational strategies aligned to business objectives. Strong experience managing large scale cyber incidents, breaches, and crisis response activities. Expertise in digital forensics across endpoint, network, cloud, and hybrid environments. Experience building, developing, and retaining high performing technical teams across multiple geographies. Strong process improvement and operational transformation experience. Experience managing budgets, forecasting demand, and optimising resource allocation. Ability to influence and communicate effectively with executive stakeholders, clients, regulators, and technical teams. Strong written and verbal communication skills, with the ability to translate complex cyber security concepts into business focused language. Experience leading organisational change and technology transformation initiatives. Experience within Managed Security Services (MSSP) or large scale cyber security consulting environments. Experience supporting commercial growth, sales enablement, and service expansion opportunities. Strong knowledge of current cyber threat trends, regulatory requirements, and industry best practices. Active participation in industry forums, conferences, or recognised cybersecurity communities. Job Benefits We have a high performance culture which is balanced evenly with world class well being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Enhanced Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme. Financial & Investment Benefits: Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes. Green Car Scheme. Cycle to Work Scheme. Special Time Off for important life events. Enhanced Family Planning, Maternity, and Paternity Support.