We are looking for a skilled and motivated Information Governance Specialist to join our team and play a key role in safeguarding patient data, ensuring regulatory compliance, and driving best practice across information governance, cybersecurity, and clinical safety.
You will work closely with clinical and technical teams, helping shape policy, deliver training, and respond to complex data protection challenges. This is an excellent opportunity for someone passionate about protecting patient safety and organisational integrity while influencing how information risk is managed at scale.
This is a full-time permanent position working remotely, with an expectation to travel as required.
What You Will Do
In this role, you will:
- Lead Information Governance initiatives – Develop and maintain IG policies, deliver training for key IG roles, and provide expert advice on complex information governance queries.
- Support data protection compliance – Manage Data Subject Access Requests, oversee DPIAs, Privacy Notices, and Information Sharing Agreements, and lead IG-related incident reporting and resolution.
- Strengthen Cyber Security resilience – Create cyber playbooks, support ISO 27001 alignment, analyse incidents, and deliver tailored cyber threat training across the business, including at board level.
- Enhance Digital Clinical Safety – Deliver training on DCB standards, publish clinical safety guidance, and support root cause analysis of safety incidents.
- Promote Quality Management – Conduct internal audits, contribute to QMS documentation, and support process owners with implementing improvements in line with ISO 9001 standards.
About You
You are an experienced Information Governance professional with a proven track record of translating regulatory requirements into practical solutions. You will have:
Essential qualifications:
- Postgraduate qualification in a relevant field (e.g., Law, Corporate Governance, Data Protection).
- A current Data Protection or Information Governance qualification (e.g., CIPP/E, BCS Practitioner Certificate, Level 4 Data Protection and IG Practitioner).
Essential skills and experience:
- In-depth knowledge of data protection laws, cybersecurity frameworks, DCB safety standards, and ISO 9001.
- Experience handling incidents and conducting root cause analysis across clinical and technical environments.
- Strong communication skills with the ability to engage, mentor, and influence stakeholders.
- A calm, analytical approach, able to respond quickly to time-sensitive issues.
- Passion for patient safety, data protection, and organisational excellence.
Desirable:
- Membership of a professional body such as The Chartered Governance Institute UK & Ireland.
- Knowledge of NHS systems and data flows.