Cybersecurity & Compliance Specialist
About Salvone Salvone Technology Solutions is the technology arm of one of the leading UK healthcare providers across hospitals, residential homes, supported living, and nursing services.
Skills
About This Role
About Salvone
Salvone Technology Solutions is the technology arm of one of the leading UK healthcare providers across hospitals, residential homes, supported living, and nursing services.
We design and operate the platforms, ERP, integrations, analytics, and workforce systems; that power operations, compliance, and care delivery across the group.
Our environment moves regulated, often clinical, data between systems on behalf of the people in our care.
As our client base and platform estate grow, so does the bar for how we protect that data.
We are hiring a Cybersecurity & Compliance Specialist to be the hands-on engine of our security and compliance programme.
Role Purpose
You will own the day-to-day security posture of our estate and drive the certifications and data-protection obligations our clients and regulators expect — ISO 27001, Cyber Essentials Plus, the NHS Data Security and Protection Toolkit (DSPT), the NHS Digital Technology Assessment Criteria (DTAC), and UK GDPR / Data Protection Act 2018.
This is a hands-on specialist role.
You will work closely with the development and enterprise applications team, with focus on the security and compliance layer that sits across all of it.
Key Responsibilities
- Security operations & posture
- Run vulnerability management end-to-end: scanning, triage, remediation tracking, and verification with the infrastructure team.
- Oversee patch compliance and hardening baselines across cloud, servers, and endpoints.
- Monitor security events and alerts through our SIEM (Wazuh), investigate anomalies, and tune detection.
- Maintain endpoint protection coverage and review logs for early signs of compromise.
- Track and reduce security debt with clear owners and dates.
- Compliance & certifications
- Drive the ISO 27001 programme day-to-day: maintain the ISMS, implement and evidence controls, and prepare for internal and external audits.
- Deliver Cyber Essentials Plus and the NHS DSPT submission, keeping evidence current year-round rather than scrambling at deadline.
- Assemble and maintain NHS DTAC assessment packs for our platforms — clinical safety, data protection, technical security, interoperability, and usability.
- Maintain a single, audit-ready control and evidence library; run and improve compliance tooling (e.g. Vanta, Drata) where adopted.
Data protection (UK GDPR / DPA 2018)
- Maintain the Record of Processing Activities (ROPA) and data-retention schedules.
- Run Data Protection Impact Assessments (DPIAs) for new systems and data flows.
- Operate the data-subject-request and breach processes, including ICO notification timelines.
- Support our obligations as a data processor to our clients — security questionnaires, contracts, and assurance.
- Identity, access & resilience
- Run quarterly access reviews and enforce least privilege across systems.
- Apply a security lens to joiner / mover / leaver and to secrets hygiene, partnering with infrastructure on MFA and conditional-access posture.
- Maintain incident-response runbooks, run tabletop drills, and lead post-incident reviews.
- Verify backups and recovery from a security standpoint — tested, not assumed.
- Vendor security & awareness
- Complete inbound client security questionnaires and run outbound supplier security reviews.
- Run security-awareness training and phishing simulations, and write policies people will actually follow.
Required Qualifications
- 2–4 years in a cybersecurity, GRC, or security-focused IT role.
- Hands-on contribution to at least one compliance framework — ISO 27001, Cyber Essentials, SOC 2, or NHS DSPT.
- Working knowledge of UK GDPR / Data Protection Act 2018 (or an equivalent data-protection regime) in practice, not just theory.
- Familiarity with cloud security (AWS preferred): IAM, security groups, GuardDuty, Config, and logging.
- Microsoft 365 / Entra ID security: conditional access, MFA, and Secure Score.
- Exposure to vulnerability management and SIEM tooling (Wazuh, Sentinel, Splunk, or similar).
- Scripting for automation: Python, Bash, or PowerShell.
- Strong documentation discipline. If it isn’t written down, it didn’t happen.
- Clear written and spoken English; able to write a policy someone will actually read.
Desirable Skills
- ISO 27001 Lead Implementer or Lead Auditor certification; Cyber Essentials assessor experience.
- NHS DTAC, DSPT, or clinical-safety exposure (DCB0129 / DCB0160).
- Security certifications: CompTIA Security+, SSCP, AZ-500, AWS Security Specialty, CEH, or working towards CISSP.
- Compliance automation tooling (Vanta, Drata, or similar).
- Experience in a regulated industry — healthcare, finance, or public sector.
- Penetration-testing fundamentals and a solid grasp of OWASP.
- Container and image scanning; zero-trust networking (Tailscale or similar).
- Healthcare integration or data context (HL7, FHIR, Mirth).
What We’re Looking For
- Beyond the checklist, we value people who are methodical, evidence-driven, and pragmatic about risk.
- The ideal candidate treats compliance as something you build into operations, not bolt on at audit time.
- Ownership mentality: you see a gap, you log it, you close it, and you evidence it.
- Pragmatism: you can tell a real risk from a theoretical one and prioritise accordingly.
- Documentation discipline: policies, runbooks, and evidence kept current as a matter of habit.
- Calm under pressure: some of what we protect runs 24/7 in clinical settings.
What Success Looks Like
- By 90 days
- A clear inventory of systems, data flows, identities, and secrets, with the riskiest gaps logged and owned.
- ISO 27001 gap analysis supported and the evidence library structured.
- ROPA started and the first DPIAs underway.
- Early, visible posture wins shipped with the infrastructure team.
- By 6 months
- ISO 27001 certification achieved.
- Cyber Essentials Plus passed, and DSPT submitted at “Standards Met” or higher.
- DTAC packs assembled and current for our in-scope platforms.
- Quarterly access reviews, incident drills, and supplier reviews running as routine.
Application Question(s)
- What is your current visa status in the UAE? (e.g. employment visa, own visa / freelance, spouse/dependent visa, visit visa, not currently in UAE
- What is your current notice period, and what is your earliest realistic start date
- What is your current/last salary, and what is your expected monthly salary in AED (total package)?
- Do you have at least 2 years of hands-on experience in a cybersecurity, GRC, or security-focused IT role?
- Have you personally contributed to implementing or evidencing at least one of: ISO 27001, Cyber Essentials, SOC 2, or NHS DSPT?
- Do you have practical experience applying UK GDPR / Data Protection Act 2018 (or an equivalent regime) — not just theory
- Have you worked hands-on with vulnerability management and SIEM tooling (e.g. Wazuh, Sentinel, Splunk, or similar)?
- Can you write automation scripts in at least one of Python, Bash, or PowerShell?
Location
- Dubai (Preferred)
Your resume, rewritten
for this exact role.
Sign up free — Base Career tailors your CV to this job description in 60 seconds.
01 / 05
Resume Tailored to This Job

Your keywords, structure, and story — rewritten to match this exact role and pass ATS filters.
Free · No card · 60 seconds
02 / 05
Cover Letter for This Role, Done

Job-specific cover letters written in Gulf professional tone — ready in seconds, not hours.
Free · No card · 60 seconds
03 / 05
See How Well You Fit This Role

AI match score with clear reasons — know your fit before investing time in the application.
Free · No card · 60 seconds
04 / 05
Use Autofill When You Apply

Autofill any application form on Workday, LinkedIn, Bayt, Greenhouse — with your tailored content.
Free · No card · 60 seconds
05 / 05
Track It. Follow Up at the Right Time.

Visual pipeline for every application with AI-timed follow-up reminders so nothing slips.
Free · No card · 60 seconds
Similar Jobs
Business Development Manager - Cybersecurity & AI
iConnect IT Business Solutions DMCC · Dubai
We are looking for a Business Development Manager to drive growth and expand our client base across the UAE. This role is suited for a proactive, results-driven professional with strong experience in cybersecurity sales
Skills
3 weeks ago
Tailor Resume↗Tailor Resume ↗Cybersecurity & IT Lead
FundingPips · Dubai
Reports To: Head of Platform Engineering & Security Manages: IT Administrator (1 direct report) Experience: 5–8 years in cybersecurity and/or IT management Overview FundingPips is a Dubai-based fintech building infrastru
Skills
3 weeks ago
Tailor Resume↗Tailor Resume ↗Senior Accountant – Cybersecurity & IT SaaS | US GAAP (Remote)
MAVI · Dubai
US Accounting Ownership. Cybersecurity & Tech Depth. Long-Term Global Partnerships. MAVI partners with high-growth US businesses, embedding experienced accounting professionals directly into their finance operations. In
Skills
1 months ago
Tailor Resume↗Tailor Resume ↗Cybersecurity & IT sales
E.W-SecGuard · Dubai
Cybersecurity & IT Sales Specialist Responsible for identifying client technology needs and offering tailored cybersecurity and IT solutions to businesses. Builds and maintains strong client relationships, generates lead
Skills
1 months ago
Tailor Resume↗Tailor Resume ↗Cybersecurity & BCM Project
VaporVM · Dubai
Date Posted: 27 April, 2026 Industry: IT Services and IT Consulting Location: VAPORVM IT SERVICES DMCC Job Description: -------------------- * Plan, manage, and deliver cybersecurity and business continuity projects in a
Skills
1 months ago
Tailor Resume↗Tailor Resume ↗2.2K+
Cover Letters & Follow-ups
1.8K+
Resumes Tailored
190.5K+
Jobs Tracked
Trusted by professionals at
Stop applying blindly.
Start getting hired.
Base Career automates the hardest parts of job searching — apply smarter, not harder.
AI Resume in 60s
Your resume rewritten for this exact role using the job description as the brief.
ATS-Optimized
Get past automated screening filters with the right keywords matched to each job.
Application Tracker
Track every job, follow-up, and interview in one visual kanban board.
Free plan · No credit card required