Job Description
The GM - Information Security Officer is an Executive role within the CTO Portfolio which services
the entire Hospitals. The role holder will provide a clear vision and direction for information and Cyber
Security operations. They will promote continuous improvement, innovation and agility in service
delivery, whilst working in consultation and collaboration with colleagues across all Branches. As the GM -
Information Security Officer, you will be responsible for overseeing a range of technical and process
security controls and leading a programme of continuous improvement in response to changing
security threats and risk. The role requires a thorough understanding of the technology
underpinning the Hospital IT systems, as well as a broad, up-to-date knowledge of information
security frameworks, pertinent regulation and legislation, vulnerability management, incident
management and response, secure development techniques and approaches, Cyber Security
engineering and operations, and management and governance of Cyber risk and Cyber Security.
Having performed a similar role in a large, distributed organisation, you will have a strong
information and Cyber Security background along with formal qualifications. You will have
established and led a large, progressive information security function, developing innovative, future
focused information and Cyber Security capability in support of business objectives. You will be a
strategic and lateral thinker with exceptional leadership credentials and a sophisticated approach to
stakeholder and supplier management. This is a fantastic opportunity to join a world class healthcare
institution in a pivotal and highly visible leadership role which will require high levels of personal
energy and commitment.
Key responsibilities
• Information and Cyber Security Strategic Direction
o Define, develop and maintain a business-aligned Information and Cyber Security
strategy and operating model
o Define and embed an Information Security Policy Framework across the all Branches that
addresses the needs of hospital and its staff, doctors, and other external stakeholders
in line with relevant legislation and industry standards
o Provide advice and direction to the hospital senior leadership team, in the integration
of security practices into hospital strategic and operational processes
o Drive and deliver change to hospital Information and Cyber Security systems, processes
and procedures by continuously analysing and reviewing new security technologies
and practices as informed by industry best practice
o Report to hospital internal audit/risk committees and management groups on
Information and Cyber Security matters
o Represent hospital on national and international external consortium groups and
boards and engage effectively in appropriate external networks, ensuring KIMS can
anticipate, meet and respond to new Information and Cyber Security challenges and
threats
• Leadership and People Management
o Develop and lead an effective, high-performance Information Security team
retaining and attracting key talent to ensure continuous improvement in staff
competencies, skills and knowledge
o Establish and maintain clear and measurable Information and Cyber Security
strategic plans, budgets and targets, and robust and fit-for-purpose operational
procedures and deliver measurable service improvements and ensure that all
elements of the service represent the best value for money
o Ensure that the culture, policies, structures and reporting systems are in place to
allow the Information Security team to achieve the highest standards of quality,
legal and regulatory compliance and corporate governance in all areas
o Play an effective role as a member of the CTO Portfolio Executive in the leadership
of the Unit.
o Foster a culture of innovation and continuous improvement that encourages,
engages and supports a high level of professional development and personal
responsibility
o Ensure that the Unit's resources and budget are managed effectively, in accordance
with institutional policy and procedures, and provide best value for money to KIMS
o Provide the Information Security team with high-quality and empowering
leadership, setting and delivering the highest service standards and a strong
performance culture by developing and sustaining best practice within the Unit
• Information and Cyber Security Management
o Provide senior leadership and oversight of effective information and Cyber Security
risk management, integrated with KIMS institutional risk management framework
o Ensure that information and Cyber Security risks to KIMS presented through
suppliers and delivery partners are identified and managed appropriately
o Develop and maintain an effective Information Security Management System and
processes for continual improvement
o Ensure Information Security is managed effectively throughout the IT service
delivery lifecycle (incl. Security Operations, Security Architecture and Security
Assurance)
o Lead on development and delivery of measures and metrics to support the
assessment, reporting and ongoing improvement of the information security
posture
o Work closely with internal stakeholders and business units to keep abreast of
planned changes to technologies, working practices, and business activities that
could have an impact on hospital Information Security or risk profile
o Define and implement an appropriate information assurance framework for KIMS,
enforcing compliance with policies in conjunction with internal audit
o Ensure and promote an appropriate level of information security culture and
awareness across hospital
o Direct, and assist as necessary, investigations into information security breaches and
pursue associated disciplinary and legal matters, liaising with the Information Rights
team on data protection legislation ensuring root-causes of such breaches are
understood and addressed
EXPERIENCE
• Substantial experience in senior management in a complex IT organisation
encompassing service delivery, application development and IT
infrastructure
• A track record in the management and delivery of transformational security
improvements across an organisation
• Proven experience at engaging, influencing and managing stakeholders
across departmental and organisational boundaries up to and including
director/CxO Executive level
• A track record in directing and managing innovative change and continuous
improvement, ensuring excellent organisational performance and outcomes
across a complex portfolio of responsibilities
• Proven experience at managing complex budgets and resources with a track
record of identifying and securing approval for business cases at enterprise
level for organisational investment in information and cyber security
• Experienced in leading, developing and motivating a team of subject matter
experts
KNOWLEDGE
• An excellent understanding of best practice within Information Security and
risk management including standards such as ISO/IEC 27001, Cyber
Essentials and CObIT
• An excellent understanding of legislation and regulations that impact
information Security E.g. DPDP Act (2025),NIST, IT Act, NABH, ABDM,HIPAA,
PCIDSS
• An understanding of current and emerging threats and countermeasures
and the organisational challenges to addressing these threats
• An understanding of Application Security threats and countermeasures
• A good practical knowledge of security technologies and wider business
solutions including Firewalls, IDS/IPS, Identity and access management,
SIEM, remote working and cloud technologies
SKILLS
• A collaborative leader with strategic acumen and problem-solving skills,
able to inspire and motivate colleagues
• An ability to articulate strategy in an empowering, collegiate and
inspiring way which also informs transparent, viable and sustainable
planning processes
• The ability to work within a regulatory framework and to articulate its
potential as a tool for continuous improvement
• Demonstrable creativity and a commitment to future-proofing service
and delivery in a fast paced, ever-changing environment
• A Self Starter with the ability to lead and drive change through an
organisation
• Excellent communication skills, both written and verbal. Ability to
present complex or highly technical issues in simple and easy-tounderstand formats
• Ability to build strong relationships and influence decisions with internal
and external stakeholders
• A good understanding of project management methodology and how to
implement security within them
• Good analytical skills and the ability to challenge the norm
• An ability to think and plan strategically and systematically while
recognising the need to deliver to the business requirements
• The ability to be pragmatic while balancing the needs of KIMS against
security
• The ability to cut through organisational and political barriers to achieve
the overall goal
Qualifications
• An appropriate degree, equivalent qualification or experience
• ONE OR MORE OF THE FOLLOWING QUALIFICATIONS ARE HIGHLY DESIRABLE:
o Certified Information Security Manager (CISM)
o Certified Information Systems Security Professional (CISSP)
o Certified Information systems Auditor (CISA)
o Full membership of the Institute of Information Security
Professional