Job Description
Information Governance Manager
n
n
Location: Kent
n
Contract: 6 Month FTC
n
n
An excellent opportunity has arisen for an experienced Information Governance Manager to join an established organisation operating within the healthcare sector.
n
Reporting to the Group Data Protection Officer, you will play a key role in ensuring compliance with data protection legislation, strengthening the organisation's information governance framework and promoting a positive data protection culture.
n
A major focus of the position will be supporting a data protection modernisation programme, including transferring Records of Processing Activities (RoPA), DPIAs and LIAs onto the OneTrust platform.
n
n
The Role
n
n
As Information Governance Manager, you will:
n
n
- n
- Lead the modernisation of the RoPA process, transferring it onto the OneTrust platform.
- Implement streamlined DPIA and LIA processes, supporting assessments and advising on appropriate mitigation strategies.
- Develop, review and update information governance and data protection procedures and guidance.
- Ensure projects embed data protection by design and by default.
- Provide training and guidance on data protection and information governance matters.
- Work closely with stakeholders to ensure data handling processes comply with relevant legal and regulatory requirements.
- Support third-party supplier security and compliance assessments and help identify areas for security improvement.
- Provide advice and challenge around data protection legislation and cyber security.
- Support the Group DPO with audits to assess compliance with information governance policies and procedures.
n
n
n
n
n
n
n
n
n
n
n
About You
n
n
Ideally, you will have:
n
n
- n
- Extensive experience within an Information Governance role within the healthcare environment
- A deep understanding of NHS Information Governance and Caldicott principles.
- Strong knowledge of GDPR, ISO 27001 and PCI DSS requirements.
- Experience supporting information governance programmes, including risk management activities.
- Experience of third-party audit and compliance management.
- A Data Protection qualification such as GDPR Practitioner Certification would be desirable.
- Strong stakeholder management and communication skills, with the ability to communicate effectively with both technical and non-technical audiences.
- A methodical, thorough and highly organised approach.
- The ability to work calmly and collaboratively in a fast-paced environment.
n
n
n
n
n
n
n
n
n
…
