Cyber Security Manager

Cyber Security Manager

Full-Time 60000 - 75000 ÂŁ / year (est.) Home office (partial)
Energy Saving Trust

At a Glance

  • Tasks: Lead cyber security strategy and manage risk to protect information assets.
  • Company: Join the Energy Saving Trust's innovative Marketing, Digital and Technology Centre of Excellence.
  • Benefits: Enjoy 25 days holiday, flexible working, and professional development support.
  • Other info: Diverse and inclusive workplace with excellent career growth opportunities.
  • Why this job: Make a real impact in cyber security while tackling the climate emergency.
  • Qualifications: Proven experience in cyber security leadership and strong technical understanding.

The predicted salary is between 60000 - 75000 ÂŁ per year.

The role involves leading the development, delivery and continuous improvement of our cyber security strategy and operational controls. You will work across the organisation to protect information assets, manage risk, and ensure compliance with relevant regulatory and industry standards. This role combines technical leadership, stakeholder engagement and practical governance to reduce cyber risk while enabling secure, resilient service delivery.

It is an exciting time to join the newly formed Marketing, Digital and Technology Centre of Excellence at Energy Saving Trust. We are on an ambitious growth journey to accelerate the use of our services through customer‑centric digital transformation, adopting a product‑oriented approach, an increasingly Agile delivery model and leveraging data to enhance our digital products and services. Our approach is open and collaborative, inviting everyone to bring their unique perspectives to help tackle the climate emergency.

What you will do:

  • Lead cyber security strategy and governance – Develop, maintain and drive the delivery of the cyber security strategy, policies and standards; chair or support security governance forums and provide clear, executive‑level reporting on risk and progress.
  • Manage risk and compliance – Own the cyber risk register, lead risk assessments, and ensure appropriate mitigations are in place; oversee compliance with relevant standards and legislation (e.g., UK GDPR, NIS, ISO 27001 or equivalent frameworks).
  • Operational security and incident management – Oversee detection, response and recovery arrangements; lead incident response activities when required, coordinate cross‑functional actions, conduct post‑incident reviews and embed lessons learned.
  • Secure architecture and technical controls – Work with architects and engineers to influence secure design, deployment and hardening of systems and cloud services; promote and oversee implementation of technical controls such as identity and access management, endpoint protection, network security and encryption.
  • Build capability and culture – Design and deliver security awareness, training and guidance for staff; support teams to adopt secure practices and foster a positive, risk‑aware culture across the organisation.
  • Supplier and third‑party security – Assess and manage supplier security risk, define security requirements in contracts and lead assurance activities, including security questionnaires and audits.
  • Continuous improvement – Monitor threat intelligence and industry developments; run vulnerability and assurance programmes, and lead projects to improve our security posture and resilience.

What you will bring:

  • Proven experience in cyber security leadership or senior technical security roles with responsibility for strategy, governance and incident response.
  • Practical knowledge of security frameworks and regulations (e.g., ISO 27001, NIST, UK GDPR, NIS) and experience delivering compliance programmes.
  • Strong technical understanding of cloud security, network security, identity and access management, endpoint protection and secure application practices.
  • Experience managing security incidents and leading cross‑functional response and remediation activities.
  • Excellent communication skills with the ability to explain technical risk to non‑technical stakeholders and influence senior leaders.
  • Strong planning and organisational skills, with experience managing multiple priorities and delivering change across an organisation.
  • Relevant professional qualifications or certifications (e.g., CISSP, CISM, CISA) and/or demonstrable equivalent experience.

Benefits:

  • Generous holiday – 25 days plus bank holidays and extra Christmas leave.
  • True flexibility in how and where you work – Home‑based, regional office or field as required.
  • Strong pension & life assurance.
  • Enhanced family leave.
  • Professional development support.
  • Yearly wellbeing allowance.

Diversity and inclusion: We are committed to creating a diverse, inclusive and equitable workplace where everyone can be themselves and thrive. We strongly encourage applicants from a wide range of backgrounds to apply.

Reasonable adjustments: We want to ensure that our recruitment process is inclusive and accessible for everyone. If you need additional support or reasonable adjustments, please get in touch with recruitment.

Cyber Security Manager employer: Energy Saving Trust

Energy Saving Trust is an exceptional employer, offering a dynamic work environment that champions innovation and collaboration. As part of our newly formed Marketing, Digital and Technology Centre of Excellence, you will have the opportunity to lead impactful cyber security initiatives while enjoying generous benefits such as 25 days of holiday, true flexibility in your work location, and robust professional development support. We are dedicated to fostering a diverse and inclusive culture, ensuring that every employee can thrive and contribute to our mission of tackling the climate emergency.
Energy Saving Trust

Contact Detail:

Energy Saving Trust Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Cyber Security Manager

✨Tip Number 1

Network like a pro! Get out there and connect with folks in the cyber security field. Attend industry events, join online forums, and don’t be shy about reaching out on LinkedIn. You never know who might have the inside scoop on job openings!

✨Tip Number 2

Show off your skills! Create a portfolio or a personal website that highlights your projects, achievements, and any relevant certifications. This is your chance to demonstrate your expertise in cyber security and make a lasting impression.

✨Tip Number 3

Prepare for interviews by brushing up on common cyber security scenarios and challenges. Be ready to discuss how you would handle incidents or improve security measures. Practice makes perfect, so consider mock interviews with friends or mentors.

✨Tip Number 4

Don’t forget to apply through our website! We’re always on the lookout for passionate individuals to join our team. Keep an eye on our careers page for the latest opportunities and make sure your application stands out!

We think you need these skills to ace Cyber Security Manager

Cyber Security Strategy Development
Risk Management
Compliance with Regulatory Standards
Incident Response Management
Cloud Security
Network Security
Identity and Access Management
Endpoint Protection
Secure Application Practices
Communication Skills
Stakeholder Engagement
Project Management
Security Frameworks Knowledge (e.g., ISO 27001, NIST)
Training and Awareness Delivery
Supplier Security Risk Management

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in cyber security leadership and governance. We want to see how your skills align with our needs, so don’t hold back on showcasing your relevant achievements!

Showcase Your Technical Know-How: When writing your application, be sure to mention your practical knowledge of security frameworks like ISO 27001 or NIST. We’re looking for someone who can demonstrate a strong technical understanding, so let us know about your experience with cloud security and incident management.

Communicate Clearly: Remember, you’ll need to explain technical risks to non-technical stakeholders. Use clear and concise language in your application to show us that you can communicate complex ideas effectively. This will help us see your potential for influencing senior leaders.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about our culture and values!

How to prepare for a job interview at Energy Saving Trust

✨Know Your Cyber Security Frameworks

Familiarise yourself with key security frameworks like ISO 27001 and NIST. Be ready to discuss how you've applied these in your previous roles, especially in relation to compliance and risk management.

✨Showcase Your Incident Response Experience

Prepare specific examples of incidents you've managed, detailing your role in the response and recovery process. Highlight how you coordinated cross-functional teams and what lessons were learned from those experiences.

✨Communicate Clearly with Non-Technical Stakeholders

Practice explaining complex cyber security concepts in simple terms. This will demonstrate your ability to engage with senior leaders and non-technical staff, which is crucial for this role.

✨Emphasise Continuous Improvement Mindset

Be ready to discuss how you stay updated on industry developments and threat intelligence. Share examples of how you've led initiatives to enhance security posture and resilience in your previous positions.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>