At a Glance
- Tasks: Lead cyber security initiatives and provide expert advice to shape the UK's energy market.
- Company: Join Elexon, a forward-thinking organisation committed to innovation and diversity.
- Benefits: Enjoy a competitive salary, bonuses, private medical insurance, and a generous pension scheme.
- Other info: Hybrid working model with a focus on employee wellbeing and continuous improvement.
- Why this job: Make a real impact on energy services while developing your career in a dynamic environment.
- Qualifications: Proven experience in Information Security management and strong stakeholder engagement skills.
The predicted salary is between 63000 - 77000 £ per year.
We’re looking for an experienced
SSES Cyber Security Lead (Grade 12) to join our Information Security team and play a pivotal role in shaping the cyber security arrangements underpinning the UK's future energy markets.
This is a senior subject matter expert role, providing independent, authoritative technical and strategic advice to the Chair of the SSES Security Governance Group and working across government, regulators, industry and Elexon.
What you’ll do
- Provide independent, authoritative cyber security advice and technical leadership to the Chair of the SSES Security Governance Group.
- Lead and contribute to the development and maintenance of
Threat and Risk Assessments , ensuring cyber risks are identified, assessed and appropriately treated.
- Monitor the evolving cyber security, Internet of Things and grid stability landscape, both in the UK and internationally, and assess the implications for SSES.
- Identify emerging threats, risks and vulnerabilities and propose appropriate controls or approaches to ensure risks remain within tolerance.
- Develop and maintain key security documentation, including Trust Modelling, Consumer Led Flexibility Security Architecture, Security Requirements and supporting guidance.
- Support Ofgem with the audit and assurance regime for organisations within the scope of the load control licence, including Cyber Assessment Framework (CAF) returns and audits.
- Work with
Ofgem and the SSES Security Governance Group to oversee and monitor remediation activity where assurance requirements are not met.
- Provide specialist cyber security expertise to SSES workgroups and contribute to the development and maintenance of key security documentation.
- Provide SME support on the design, assessment and delivery of industry change, particularly where new or updated standards and regulatory developments impact flexibility markets.
- Advise on cyber risk, security architecture, information security standards, governance and assurance across Consumer Led Flexibility.
- Provide cyber security advice and support to regulators, government and industry stakeholders.
- Contribute to the development of the SSES sub-sector State of the Sector report.
Lead or contribute to strategic initiatives and technical projects across Information Security and, where required, the wider Elexon organisation.
- Build and maintain strong relationships with a broad range of external stakeholders, including government departments, regulators, industry participants, technology providers and standards bodies.
- Support knowledge sharing across the Information Security team and wider Elexon.
- Develop consultation responses, engagement materials and other communications relating to SSES security governance.
- Identify opportunities to improve Elexon’s approaches, methodologies and use of tools to strengthen cyber security and resilience.
What you’ll bring
- Significant experience in
Information Security management , with a minimum of five years' relevant professional experience.
- Significant experience of
Security Architecture approaches and frameworks.
- Significant experience of
Cyber Risk approaches and frameworks, including identifying, assessing and treating cyber threats and risks.
- Significant experience of
Cyber Assessment Frameworks and Cyber Resilience Audits , ideally within the energy industry.
- Extensive knowledge and practical experience of
NCSC's Cyber Assessment Framework (CAF) and the Network and Information Systems (NIS) landscape.
- Extensive experience conducting or supporting
Information Security audits , including ISO 27001 certification audits.
- Strong technical knowledge of domestic and international Information Security standards and associated processes, with expert knowledge in relevant specialist areas.
- The ability to analyse complex problems, assess potential solutions and provide clear, evidence-based recommendations.
- The credibility and confidence to provide authoritative guidance and leadership to a wide range of external stakeholders.
- Strong presentation and public speaking skills, with the ability to communicate complex technical issues effectively to different audiences.
- Knowledge of the roles and responsibilities of organisations involved in flexibility markets, including OEMs, Flexibility Service Providers (FSPs), DSOs and NESO.
- Strong stakeholder management and influencing skills, with the ability to build trusted relationships across government, regulators, industry and technical communities.
- Proficiency in Microsoft Office and an openness to learning and adopting new programmes, tools and methodologies.
- Relevant academic and/or professional experience.
ISO 27001 Lead Implementer and CISSP qualifications.
SC Clearance , or willingness to attain SC Clearance following a successful application.
It would also be useful, although not essential, if you have
- Good knowledge of electricity market arrangements and procedures.
- Knowledge of Information Security data exchanges used by Energy Smart Appliances and Load Controllers.
- An understanding of industry developments that could impact Elexon, its processes and systems over the medium to long term.
- Experience using data processing tools and techniques.
- An understanding of the impact of change on customers’ systems and processes.
- An interest in developing knowledge of complex technical energy market arrangements and procedures.
What’s in it for you
- Salary –
- £80,000
- Excellent benefits including bonus, private medical insurance and generous pension scheme
- The opportunity to work within a thriving organisation which can support your growth and development
- We operate a hybrid working approach with 2 days in our London office
Our culture
We believe a diverse and inclusive culture allows innovation and creativity to flourish. We are committed to continuously improving our culture for our colleagues and stakeholders.
Through our Diversity Forum, Mental Health First Aid network and regular programme of activities and events, we celebrate difference and recognise the value of employee wellbeing.
At Elexon, we want to
- Provide true equality of opportunity.
- Attract and retain diverse talent.
- Listen to all voices.
- Be representative of the communities we work in.
- Be a role model for Diversity and Inclusion in the industry.
Our values shape the way we work. We think beyond, put customers first, focus on what matters, work at pace and work as one team .
Elexon together — embracing differences, listening to all voices.
Ready to make an impact? Join us and help shape the future of energy services.
#J-18808-Ljbffr
Cyber Security Manager employer: Elexon
Elexon is an exceptional employer, offering a dynamic work environment in the heart of London where you can thrive as a Settlement Analyst. With a strong commitment to employee growth, a diverse and inclusive culture, and excellent benefits including a competitive salary, private medical insurance, and a generous pension scheme, Elexon ensures that every team member feels valued and supported. Join us to be part of a forward-thinking organisation that prioritises innovation and employee wellbeing while making a significant impact in the energy sector.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Manager
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Elexon, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Elexon
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Elexon. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Cyber Security Manager
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Elexon insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Elexon that you’re committed to staying ahead in the game.
How to prepare for a job interview at Elexon
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Elexon to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Elexon.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.