identifi Global Resources
Information Governance Assurance Officer – NHS

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Information Governance Assurance Officer – NHS
Band 6 - £25 / 30 per hour
Norfolk & Norwich
Digital Health – Information Governance
We are looking for an experienced Information Governance Assurance Officer to join the Digital Health Information Governance team within a major NHS organisation.
This is a hands-on Information Governance and Data Protection role supporting the organisation's compliance, assurance and risk management activities across DSPT, UK data protection requirements, CQC assurance and wider NHS Information Governance.
You will work closely with the Head of Information Governance & Data Protection Officer and the Information Governance Assurance Manager, engaging with clinical, operational, digital and corporate teams across the organisation.
This would particularly suit an established Information Governance Officer, Data Protection Officer, IG Assurance Officer or Information Governance Specialist with previous NHS or healthcare experience who understands how IG operates in practice within a complex organisation.
The Role
You will support the delivery and assurance of the Trust's Information Governance work programme, helping ensure that appropriate controls, evidence and processes are in place to meet regulatory, statutory and NHS requirements.
Key responsibilities will include:
- Supporting delivery and assurance of the Data Security and Protection Toolkit (DSPT), including evidence gathering, gap analysis, action tracking and monitoring progress against assertions.
- Supporting the implementation and ongoing assurance of the organisation's Information Governance framework.
- Undertaking and supporting Data Protection Impact Assessments (DPIAs) for new projects, systems, policies and initiatives involving personal information.
- Developing and supporting the Information Governance audit programme, including audits, spot checks and assurance activity.
- Monitoring IG compliance, risks and actions and escalating issues appropriately.
- Supporting the management and investigation of information governance incidents and data breaches, including analysis and reporting.
- Supporting data subject rights, including Subject Access Requests, data protection complaints and associated statutory requirements.
- Maintaining and assuring data flow mapping and Information Asset Register activities.
- Supporting and monitoring appropriate data and information-sharing agreements with third parties and partner organisations.
- Maintaining IG policies, procedures, guidance, registers and supporting documentation.
- Collating, analysing and presenting IG assurance, compliance, training and risk information.
- Producing clear reports for senior stakeholders and governance committees, including the Caldicott and Information Governance Assurance Committee.
- Identifying trends, themes and emerging risks from qualitative and quantitative IG data.
- Supporting the development and delivery of Information Governance training and awareness across the organisation.
- Working with Divisional Governance teams, Digital Health, clinical services, senior management and other stakeholders to embed a practical, risk-based approach to Information Governance.
- Deputising for the Information Governance Assurance Manager at relevant governance, risk and assurance meetings when required.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What We're Looking For
We are particularly interested in candidates who bring practical experience of Information Governance and Data Protection within an NHS, healthcare or similarly regulated environment.
You should have:
- Good working knowledge of NHS Information Governance and relevant data protection requirements.
- Experience supporting DSPT compliance and assurance activities.
- Understanding of UK data protection legislation and its practical application.
- Experience undertaking or supporting DPIAs and information risk assessments.
- Experience working with sensitive and confidential information.
- Understanding of good governance, assurance and risk-based Information Governance.
- Experience collating and analysing governance, compliance or assurance data.
- Strong audit, evidence-gathering and documentation skills.
- Ability to interpret complex information and turn it into clear, meaningful reports.
- Experience producing reports suitable for senior management, boards or governance committees.
- Strong stakeholder-management skills and the confidence to work across clinical, operational, digital and corporate teams.
- Excellent attention to detail and the ability to manage competing priorities with minimal supervision.
- Strong Microsoft Office skills, particularly Excel, Word and PowerPoint.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Qualifications
You should be educated to degree level in a relevant discipline or be able to demonstrate equivalent significant professional experience.
A formal qualification in Information Governance/Data Protection, such as an ISEB, GDPR/Data Protection Practitioner qualification or equivalent, is required.
Relevant postgraduate qualifications or further professional development would be advantageous.
The Person
This role needs someone who can do more than interpret policy.
You will need to be comfortable working with different parts of a large healthcare organisation, identifying potential IG risks, challenging where necessary and helping stakeholders find practical ways of meeting their Information Governance responsibilities.
You should be analytical, organised and confident working independently, while also being able to build productive relationships with colleagues at all levels.
Previous experience within a healthcare environment is essential.
If you have practical NHS Information Governance experience across DSPT, Data Protection, DPIAs, assurance, audit and information risk, we would be interested in hearing from you.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location