At a Glance
- Tasks: Lead cyber security initiatives and ensure robust governance for IT security.
- Company: Join E.ON UK, a leader in energy solutions with a focus on innovation.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Engage with senior leadership and drive a culture of security across the organisation.
- Why this job: Be at the forefront of transforming IT security in a dynamic environment.
- Qualifications: Proven experience in cyber security management and strong technical skills required.
The predicted salary is between 48000 - 72000 £ per year.
We’re looking for a Cyber Security Manager to be the cornerstone of IT security for npower Business Solutions (nBS), the Industrial & Commercial arm of E.ON UK. Based in Nottingham or Solihull, this permanent role (with FTC options considered) sits at the heart of our transformation—establishing and operating a robust Information Security Management System (ISMS), embedding best practices across our evolving BusDevSecOps culture, and providing expert guidance on everything from secure architecture and fraud prevention to emerging governance frameworks.
Operating within the E.ON Group’s overarching cyber security framework, you’ll navigate a complex multi‑supplier ecosystem and lead the security agenda as we transition from a traditional service model to a modern product and DevSecOps environment. This role blends deep governance expertise with hands‑on technical acumen, advising stakeholders at all levels, including the C‑suite.
Responsibilities- Own cyber security, IT risk and controls for nBS—ensuring effective governance, risk management, and audit readiness are embedded and operating smoothly.
- Lead threat and risk assessments to ISO 27005, produce consolidated risk reports, define KRIs, and manage remediation plans through their lifecycle.
- Develop, implement and mature the ISMS aligned to ISO 27001, Smart Energy Code (SEC) and emerging standards including ISO 42001 (AI Management) and the Cyber Assessment Framework (CAF) / CRA.
- Promote heightened cyber risk awareness across nBS—running drop‑in sessions, roadshows, and targeted C‑suite engagements.
- Act as a trusted adviser on strategies, controls and architectural patterns to mitigate external threats, providing pragmatic guidance to product teams and leadership.
- Drive compliance and certification across key regulations and standards—Smart Energy Code (SEC), Retail Energy Code (REC), PCI DSS, GDPR, Cyber Essentials and the Cyber Assurance Framework, including planning and supporting internal control testing and acting as primary liaison with auditors.
- Be the security cornerstone in our product and DevSecOps transition—guiding secure architecture, secure coding practices, threat modelling and integrating controls throughout the SDLC.
- Manage third‑party security posture across our multi‑supplier ecosystem—covering onboarding, contractual controls, auditing and ongoing reviews for SaaS, integration and infrastructure.
- Own legislation and compliance engagement for PCI DSS, DPA/GDPR, SEC, REC, CRA/CAF and related UK initiatives such as the Cyber Resilience Bill and the UK Cyber Security Bill.
- Scope and coordinate penetration tests—managing delivery with relevant teams and ensuring findings are triaged, tracked and resolved in line with nBS’s risk appetite.
- Champion a culture of security—delivering coaching and presentations from engineering squads to the C‑suite, ensuring security is a value‑add, not a block.
- Proven track record of taking companies through audits and certifications—planning, readiness, engagement and successful outcome delivery (e.g., SEC/REC, Cyber Essentials, SOC 2 Type II, PCI DSS, ISO 27001, ISO 27002).
- Strong understanding of the UK energy sector’s regulatory landscape, particularly Smart Energy Code (SEC) and Retail Energy Code (REC), with at least 5 years’ experience in the sector.
- Credibility and presence at senior level, with the confidence to engage and influence the C‑suite.
- Experience operating in a complex, multi‑supplier environment—onboarding, auditing and ongoing review of third‑party security posture.
- Hands‑on ISMS expertise—establishing, operating and maturing an ISMS aligned to ISO 27001.
- Strong technical acumen—secure architecture design, practical security guidance within DevSecOps or Agile settings and integrating controls through the SDLC.
- Significant experience in IT risk management—conducting assessments (e.g., ISO 27005), managing risks end‑to‑end and defining meaningful KRIs.
- Demonstrated subject‑matter expertise in at least two of: ISO 27001, ISO 42001, Data Protection Act/GDPR, SOC 2 Type II.
- Experience ensuring compliance with security policies, controls and procedures; comfortable with frameworks such as the Cyber Assurance Framework (CAF) and Cyber Essentials.
- Familiarity with evolving UK initiatives and audits—Smart Energy Code, UK Cyber Security Bill, FUSA audits (or equivalent) and the Cyber Resilience Bill.
- Certifications: CISSP (must‑have); CISM; ISO 27001 Lead Auditor or Lead Implementation; experience building DevSecOps ways of working (tooling, pipelines, IaC guardrails, policy‑as‑code); understanding of legal frameworks relevant to data protection, cyber resilience and operational compliance in energy markets.
Cyber Security Manager in Nottingham employer: E.ON UK
E.ON UK is an excellent employer for Highways Electricians, offering a supportive work culture that prioritises safety and professional development. Located in Rochdale, employees benefit from opportunities to enhance their skills through ongoing training and a commitment to innovation in street lighting solutions. Join us to be part of a team that values your contributions and fosters a rewarding career in the heart of the North West.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Manager in Nottingham
✨Tip Number 1
Network like a pro! Attend industry events, webinars, and meetups related to cyber security. This is your chance to connect with potential employers and showcase your expertise in person.
✨Tip Number 2
Don’t underestimate the power of LinkedIn! Make sure your profile is up-to-date and reflects your skills in ISMS and risk management. Engage with posts, share insights, and connect with people in the energy sector.
✨Tip Number 3
Prepare for interviews by brushing up on your knowledge of ISO standards and the UK energy sector’s regulatory landscape. Be ready to discuss how you can lead the security agenda and drive compliance effectively.
✨Tip Number 4
Apply through our website! We’re always looking for talented individuals who can help us enhance our cyber security framework. Don’t miss out on the opportunity to be part of our transformation journey!
We think you need these skills to ace Cyber Security Manager in Nottingham
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cyber Security Manager role. Highlight your experience with ISMS, risk management, and compliance frameworks like ISO 27001. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your background makes you the perfect fit for our team. Don’t forget to mention your experience in the UK energy sector!
Showcase Your Achievements:When detailing your past roles, focus on specific achievements—like successful audits or certifications you've led. We love numbers and results, so if you can quantify your impact, do it! It helps us see the value you bring.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re keen on joining our team at StudySmarter!
How to prepare for a job interview at E.ON UK
✨Know Your Stuff
Make sure you brush up on your knowledge of ISO 27001, Cyber Essentials, and the Smart Energy Code. Be ready to discuss how you've applied these standards in previous roles, especially in a multi-supplier environment. This will show that you’re not just familiar with the theory but have practical experience too.
✨Showcase Your Leadership Skills
As a Cyber Security Manager, you'll need to engage with stakeholders at all levels, including the C-suite. Prepare examples of how you've successfully led teams or projects in the past, particularly around risk management and compliance. Highlight your ability to influence and communicate effectively with senior leaders.
✨Demonstrate Your Technical Acumen
Be ready to dive into technical discussions about secure architecture and DevSecOps practices. Prepare to explain how you've integrated security controls throughout the software development lifecycle (SDLC) and any hands-on experience you have with threat modelling or penetration testing.
✨Cultural Fit is Key
Npower Business Solutions values a culture of security. Think about how you can promote cyber risk awareness and foster a security-first mindset within teams. Be prepared to share ideas on how you would run workshops or coaching sessions to engage staff at all levels.