Cybersecurity Careers in the NHS: Skills That Employers Value

Cybersecurity Careers in the NHS: Skills That Employers Value

Important things to know

On 3 June 2024, a ransomware group called Qilin encrypted the systems of Synnovis, the company that runs pathology services for two of the largest hospital trusts in London. Blood testing stopped. Hospitals could not match blood properly, so they fell back on O-negative stock. More than 11,000 outpatient appointments and elective procedures were delayed.

A year later, King's College Hospital NHS Foundation Trust confirmed something the security industry had talked about in theory for years. A patient had died, and the investigation into their care found that a long wait for a blood test result, caused by the attack, was one of the contributing factors.

That is what makes NHS cyber security different from almost every other sector. In a bank, a bad day costs money. In a hospital, a bad day can cost someone their treatment window.

It is also why the NHS is hiring, and why the skills it looks for are not quite the same as the ones a fintech or a consultancy will ask you about. If you are aiming at the UK market, this is a corner of the industry worth understanding properly.

 

What the NHS is actually dealing with in 2026

Three things shape the job adverts you will see.

 

  • The attacker usually comes through the supply chain. Synnovis was not a hospital. Neither was DXS International, the GP software supplier breached in December 2025 whose products are used by around 2,000 GP practices. Neither was Stryker, the medical equipment manufacturer whose attack in March 2026 forced NHS England to run an emergency stock-take across every acute, community, mental health and ambulance trust in the country. Barts Health had patient and staff data stolen after criminals exploited a flaw in Oracle E-Business Suite. The pattern is consistent, and it is the reason supplier assurance work has gone from a back-office chore to a genuine career path.

 

  • The estate is old and hard to patch. A CT scanner or an infusion pump can stay in clinical use for ten years or more, long after the operating system underneath it stops getting updates. Many of these devices cannot be patched at all without the manufacturer signing off, and taking them offline means cancelling clinics. SonicWall's own network telemetry, which is vendor data rather than official statistics so treat it as indicative, recorded 264,000 intrusion prevention events across UK healthcare networks between January and May 2026, compared with about 27,000 across the whole of 2025. Around 41% of those events involved Log4j2, a vulnerability first disclosed at the end of 2021.

 

  • The rules are getting stricter, and fast. The Data Security and Protection Toolkit, which every organisation touching NHS patient data has to complete, is now aligned to the National Cyber Security Centre's Cyber Assessment Framework for trusts, integrated care boards, commissioning support units, arm's length bodies and designated operators of essential services. The 2025/26 submission closed on 30 June 2026, and those organisations now need an independent audit to back up what they claim. From September 2026, NHS England is adding directive policies covering multi-factor authentication, high-severity alerts and endpoint detection. Separately, the Cyber Security and Resilience Bill is currently at committee stage in the House of Lords, and is expected to bring roughly 1,000 NHS suppliers into scope of mandatory security requirements.

Put simply: more rules, more evidence, more auditing, and not enough people to do the work.

 

Where The Jobs Actually Are

People assume "NHS cyber job" means a hospital. There are five distinct routes, and the one most beginners overlook is the last.

  • Hospital trusts. The biggest employer group by headcount. Roles are usually titled Cyber Security Analyst, Information Security Analyst or IT Security Officer, often sitting inside a wider Digital Services or IT department. You will do a bit of everything: vulnerability management, DSPT evidence gathering, security tooling, answering questions from clinicians.
  • NHS England Cyber Operations, including the national Cyber Security Operations Centre. This is the closest thing the NHS has to a classic SOC career ladder, with Tier 1 junior analysts, Tier 2 analysts and senior analysts, split across areas like cloud, networks and infrastructure, and threat intelligence. There is also a governance, risk and compliance team, and a security advisory function that works on programmes rather than alerts.
  • Arm's length and special health authorities. NHS Blood and Transplant, the NHS Business Services Authority and the NHS Counter Fraud Authority all run their own security teams and recruit independently. These are often smaller teams where you get broader exposure faster.
  • Integrated care boards and commissioning support units. More strategy, assurance and coordination than hands-on tooling. Good for people who lean towards governance.
  • Suppliers and managed service providers. This is the underrated route. If roughly a thousand suppliers are about to fall under new legal duties, every one of them needs people who understand both security and how the NHS works. Getting a job at an NHS supplier is usually easier than getting one inside the NHS, and it gives you the sector experience that makes the next application much stronger.

 

What the money looks like

NHS pay runs on Agenda for Change. Everyone is on a published band, so unlike the private sector you can check the number before you apply. Three things to know about those numbers:

If you work in or near London you also get a High Cost Area Supplement on top: 20% of basic salary in Inner London, 15% in Outer London, 5% in the fringe zone, each with a floor and a ceiling.

Some hard-to-fill security posts carry a Recruitment and Retention Premium. NHS England has advertised analyst roles with a 20% premium on top of the band, though it is non-contractual and gets reviewed.

And the line that appears in almost every advert: "staff recruited from outside the NHS will usually be appointed at the bottom of the pay band." Budget for the entry point, not the top.

 

The skills employers actually value

Here is what shows up again and again when you read a stack of real NHS cyber adverts side by side.

1. The Microsoft security stack

The NHS runs on Microsoft. Adverts routinely name Microsoft 365, Azure, Entra ID, Intune, Defender and Microsoft Sentinel. If you are choosing where to spend your practice time, this is the highest-return decision you will make. Being able to say "I built detection rules in Sentinel and here is why I tuned this one" beats a general awareness of five different SIEM products.

2. Vulnerability management you can evidence

Not just "I know what a CVE is". Employers want the full loop: discover, prioritise by actual risk, agree remediation with the team that owns the system, patch, verify, report. In healthcare the hard part is never the scan. It is negotiating a maintenance window with a department that cannot take its equipment offline. Show that you understand that and you sound like someone who has done the job.

3. Alert triage and log analysis, written up properly

The Tier 1 job in the NHS England CSOC is described almost exactly like this: perform first line triage on alerts from monitoring tooling, evaluate and investigate, reach a conclusion, and hand that conclusion back to the healthcare organisation affected. The investigation matters. So does the write-up, because someone else has to act on it.

4. Framework literacy, especially CAF and DSPT

This is the single biggest thing that separates a candidate who has clearly studied the NHS from one who has not. You do not need to be an auditor. You do need to know what the DSPT is, that it is now built on the NCSC Cyber Assessment Framework for larger organisations, that it works on outcomes rather than a tick-box checklist, and that organisations have to show how well a control works rather than just that it exists. Add Cyber Essentials, ISO 27001, the NIS Regulations 2018 and UK GDPR and you can hold a sensible conversation in an interview.

5. Understanding clinical risk, not just technical risk

A vulnerability score does not tell you whether people get hurt. In the NHS, risk is measured in delayed diagnoses, cancelled operations and patient harm. The Synnovis attack generated close to 600 patient safety incidents. Candidates who can frame a finding in terms of which clinical service it threatens, rather than just its CVSS score, get taken seriously much faster.

6. Supplier and third party assurance

Reading a supplier's security documentation, checking their DSPT status, asking the right follow-up questions, and being honest in writing about residual risk. Given where the attacks are coming from, this skill is only going to grow.

7. Writing and explaining

You will spend a surprising amount of time explaining security to people who did not ask and are already busy. Consultants, ward managers, procurement, board members. Adverts ask for the ability to give clear advice to technical and non-technical colleagues, and to present metrics and risk information that support decisions. If your writing is clear, say so and show it.

 

The things nobody tells you

  • Security clearance is a real barrier. Every NHS England cyber security post requires Security Check clearance as a minimum, and SC normally requires five years of continuous UK residency. It can sometimes be reduced to three years with additional overseas checks. Many NHS England adverts also state plainly that they cannot offer visa sponsorship. Individual trusts vary and some do sponsor, but if you are applying from outside the UK, check this before you invest time in an application. Suppliers are often a more realistic starting point.
  • The supporting statement is the whole game. NHS shortlisting is done against the person specification, criterion by criterion. Adverts spell this out: your supporting statement must include demonstrable evidence and specific examples showing how you meet each of the key skills listed. The practical move is to use the essential criteria as your headings and write one concrete example under each. Most rejected applications are rejected because the candidate wrote a general cover letter instead.
  • You may be tested before you speak to anyone. NHS England uses Immersive Labs, a hands-on gamified assessment platform, as part of screening for CSOC roles. Reading about security will not get you through that. Practising will.
  • Entry level is genuinely tight. The government's most recent labour market research found the UK cyber workforce at around 143,000 people and the annual shortfall down to 3,800 from 11,100 two years earlier. But only about 15% of cyber recruitment was aimed at career starters. The shortage is real and it is mostly a shortage of experienced people. That is uncomfortable, and it is better to know it than to be surprised by it.

 

How to build the evidence before you have the job

You cannot get NHS experience without an NHS job, but you can build work that looks like NHS work. You can start by taking advantage of our cybersecurity work experience program. Book a free clarity call here to speak with one of our Career Consultants and learn how this program will prepare you for your role in the NHS. Five projects worth doing, each of which gives you something concrete to put in a supporting statement:

  1. Run the full vulnerability loop in a home lab. Build two or three virtual machines, run a credentialed scan, patch, rescan, and write a one-page remediation report showing before and after. Include a section on what you would have had to negotiate if one of those machines had been a clinical system.
  2. Do a mock DSPT gap assessment. The CAF-aligned outcomes are published openly on the DSP Toolkit website. Invent a 300-bed trust, pick five outcomes, and assess them honestly with evidence you would expect to see. This is close to real assurance work.
  3. Investigate a phishing email end to end. Headers, sender infrastructure, URL analysis in a safe sandbox, indicators extracted, timeline written up, containment recommended. Present it as an incident record, not a blog post.
  4. Get hands on a SIEM. Stand up a Microsoft Sentinel or Defender trial, ingest some sample logs, write two detection rules, and document why you wrote them that way and what would generate a false positive.
  5. Write a supplier assurance questionnaire. Base it on DSPT expectations and the NHS supplier cyber security charter. Then answer it as if you were a small supplier, and mark your own answers.

Then practise the format that actually gets people shortlisted: take a real NHS advert, copy out the essential criteria, and write your evidence against each one. 

 

NHS cyber security is not the highest-paying corner of the industry. Band 6 tops out around £48,000 outside London, and you will earn more in financial services. What you get instead is scope, a published pay structure with a clear ladder, one of the best pensions available in the UK, and work where the consequences are obvious. The Synnovis case removed any remaining doubt that this is patient safety work rather than IT housekeeping.

 

The regulation is tightening, the supply chain is under legal scrutiny for the first time, and the sector is short of people who understand both security controls and how a hospital actually runs. That combination does not come along often. If you can pair solid Microsoft security fundamentals with genuine framework literacy and the ability to write clearly about risk, you are looking at a sector that will keep needing you for a long time.

Recommended Post

cybersecurity-careers-in-the-nhs-skills-that-employers-value

Frequently Asked Questions

Amdari is a platform that provides internship programs and real-world project opportunities to help individuals gain practical experience and build their portfolios. We offer structured programs with expert guidance and curated project videos.

Amdari is designed for individuals looking to transition into tech careers, recent graduates seeking practical experience, and professionals wanting to upskill in data science, product design, software engineering, and related fields.

Our internship program provides hands-on experience through real-world projects. You'll work on carefully curated projects, receive expert-guided instruction, build a professional portfolio, and get interview preparation support to help you land your dream job.

No prior experience is required! Our programs are designed to help individuals at all levels, from beginners to those looking to advance their careers. We provide comprehensive guidance and resources to support your learning journey.

Amdari offers internships in various fields including Data Science, Product Design, Software Engineering, UX Design, Product Management, Data Analysis, and more. We continuously expand our offerings based on industry demand.

Amdari's internship programs are fully remote, allowing you to participate from anywhere in the world. This flexibility enables you to learn at your own pace while balancing other commitments.

Need To Talk To Us?

Chat with us on whatsapp

Couldn't find an answer?

Chat with us