At a Glance
- Tasks: Join our team as a Senior Cyber Security Analyst, tackling cyber threats and ensuring compliance.
- Company: UK Power Networks is a leading energy provider committed to safeguarding essential services.
- Benefits: Enjoy blended working, generous pension contributions, and discounts on gym memberships and retailers.
- Why this job: Make a real impact in cyber security while collaborating with industry experts and enhancing your skills.
- Qualifications: Experience in GRC or related fields, with knowledge of cyber security risk assessment and compliance standards.
- Other info: This role offers a competitive salary and the chance to mentor junior analysts.
The predicted salary is between 54000 - 84000 £ per year.
This Senior Cyber Security (GRC) Analyst will report to the Cyber Security Governance, Risk & Compliance Manager and will work within the Information Systems directorate based in either our London or Crawley office. You will be a permanent employee.
You will attract a salary of up to £75,000.00 and a bonus of 7.5%. This role can also offer blended working after probationary period (6 months) - 3 days in the office and 2 remote.
Job Purpose
The Senior Governance Risk and Compliance (GRC) Analyst will support the Cyber Security GRC Manager in developing IT governance, risk management, and compliance strategies across UK Power Networks information applications and users to safeguard essential business services and operations from cyber threats.
Dimensions
- People: Work collaboratively in a team of circa 8-10 permanent and temporary GRC resources and specialist 3rd Party GRC service providers. Mentor less experienced GRC analysts, providing guidance and training.
- Industry and Regulatory: Deputise for the GRC manager to represent UKPN in energy sector industry forums and regulatory working groups, working collaboratively with Ofgem and the Department for Energy Security and Net Zero.
- Communication: Communicate and work with all teams and partners in UK Power Networks. Good verbal, written, and presentational skills to express risks and the potential possible effects to the business and make reasoned recommendations for management action to mitigate or reduce the risks.
- Stakeholders: Regular and ongoing interaction with senior management across IT, IS and the Business; build relationships with internal support teams, internal and external auditors, specialist 3rd party service providers and partners to manage IT risk, and to monitor mitigation plans and actions.
Principal Accountabilities
- Risk Management: Conduct cyber security risk assessments following the UK Power Networks risk assessment framework and methodology, identifying and explaining findings and treatment actions to important partners. Ensure all risks relating to the control environment are captured and remediation actions defined, tracked, monitored and followed-up with owners including communication of third-party assessments and actions.
- Reporting: Produce management information related to the risk and control environment. Support IS teams to define main control metrics to demonstrate their effectiveness. Prepare regulatory submissions and provide assurance for UK Power Networks policy compliance within IT which includes main performance metrics and management reporting.
- Information Security Management System Support: Operate and maintain the information security management system and artefacts, in compliance with ISO 27001/27002 including the governance forum agenda and minutes.
- Policies and Standards: Establish GRC policies, standards and procedures to monitor UKPN information security controls, exceptions, risks, and testing including management reporting on performance.
- Controls Framework: Ensure a fit for purpose and robust IT control environment and support a roadmap for IT controls improvements. Requiring an understanding of technical issues and controls.
- Compliance: Design, implement, and run processes to monitor UKPN IT compliance to legal and regulatory requirements such as Smart Energy Code, Cyber Essentials, National Cyber Security Centre (NCSC) Networks & Information Systems (NIS) Regulations Cyber Assessment Framework (CAF) and all IT related audits (internal and external) where the scope is wholly or significantly relevant to the companies cyber security controls.
- Business Continuity and Disaster Recovery: Own and maintain IT resilience and business continuity plans, plan, coordinate test exercises. Conduct business continuity reviews and evaluate resilience and business continuity activities.
- GRC Systems and Tools Support: Support the technical implementation, maintenance and configuration of the suite of GRC tools, products and systems to ensure effective operation of GRC frameworks and capabilities.
- Stakeholder Management: Engage and work with important partners across IT, IS and the Business, maintaining daily working relationships with internal and external support teams, internal and external auditors, UKPN regulator Ofgem, third party managed service providers and partners to manage all IT risks across the enterprise.
- Supply Chain and 3rd Party: Engage, interact and ensure 3rd party supplies are meeting cyber security expectations. Gather evidence and assurance, risk assess and create reports and governance metrics for measuring the ongoing risk and impact that 3rd party suppliers present to UKPN.
Nature and Scope
The Information Systems Department works across UK Power Networks, supporting us in the achievement of our vision to maintain its position as best DNO. The team achieve this through the provision of technology solutions, and the optimisation of current solutions to improve how we operate. Continuous improvement, customer service and seamless delivery is at the heart of this ethos and are therefore underpinned by effective cyber security.
You will assess Cyber and IT risks and undertake risk management activities within UK Power Networks. Also you will support UK Power Networks cyber security maturity improvements in processes that are necessary to protect our customers from cyber threats.
You will support all other team members, the rest of Information Systems teams, IT Service Providers and partners across UK Power Networks to implement and improve IS and IT risk management and operational control capabilities that are important to safeguarding UKPN information assets, business services and operations.
Knowledge:
We ask that you understand governance, risk management, and compliance principles, in addition to a knowledge of relevant laws, regulations, and industry standards. We are looking for a detailed knowledge and practical expertise in at least 3 of the following specialist areas:
- Specific Industry Standards.
- IS/IT Operational Controls and Governance.
- Business Continuity Planning and Disaster Recovery.
- Supply Chain and 3rd Party Risk Management.
Problem Solving: The role must have strong analytical and problem-solving skills to recommend pragmatic mitigating solutions for IT risks across the organisation; must also be able to develop and implement new governance and compliance strategies and procedures.
Accountability: The Senior role ensures we are compliant with relevant laws, regulations, and industry standards, in a sustainable way. They are also responsible for conducting regular control and risk assessments, and reporting on GRC activities to senior management and partners.
You will ensure that UKPN can demonstrate and maintain ongoing compliance to the legal and regulatory demands that are necessary for UKPN to retain its 'license to operate' and provide its main services as a DNO. A cornerstone for this is to maintain a strong cyber security posture across the IT estate by developing a comprehensive controls framework whilst ensuring that the daily operational changes and multiple project deliverables reinforce rather than weaken the posture and protect the company's information assets.
Qualifications:
- Practical experience in a GRC role or related profession (e.g., risk, audit, cyber security or similar practical experience in IT or OT role with a desire to move into cyber security), must have some relevant training or experience of cyber security risk assessment.
- Detailed knowledge and experience in defining, implementing, operating, maintaining, and improving information security management systems (ISMS).
- Experience of internal and external audit engagements, orchestrating and delivering cyber security risk and control assessments and a good working knowledge of risk processes, frameworks, and procedures.
- Specific GRC related professional training or an academic level equivalent in a related subject with a recognised information security related certification (e.g., CISSP, CompTIA, CISA, CISM, CRISC, MSc Information Security, degree or other formal technical qualifications in a related area such as networking, cyber security, Information Technology, Operational Technology).
- Knowledge of compliance, security and regulatory frameworks such as Cyber Essentials, Smart Energy Code (SEC), Network and Information Systems Directive (NIS), National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF), ISA/IEC 62443, ISO/IEC 27001/27002, GDPR, Cloud Security Alliance (CSA) Star framework, SOC2 Type 2 audits, Information Technology Infrastructure Library (ITIL), Control Objectives for Information and Related Technologies (CoBIT), etc.
- Proficient in at least one or more of the following, within a corporate environment:
- IT / OT operational risks and controls assessment and assurance.
- Business Continuity Planning and Disaster Recovery testing assurance.
- 3rd Party Supply chain risks, controls and assurance.
- Physical security risks and controls.
- Policy, Process, Documentation and Governance.
Health & Safety Responsibilities
Managers and supervisors carry both legal and company responsibilities for ensuring the health and safety of their employees, those under their control and those who might be affected by the work undertaken, i.e., public, visitors and employees of other organisations. This includes briefing individuals working for them and ensuring there is the necessary understanding, competence and application of requirements to work safely and without harming the environment.
Employees will ensure they understand the health and safety risks involved in their work activities and their responsibility to apply the controls needed to manage those risks to acceptable levels. Similarly, where work activities can have an adverse impact upon the environment, and where there are legal requirements, employees will understand those impacts and the controls they must ensure are applied.
We are committed to equal employment opportunity regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, or veteran status. We are proud to be an equal opportunity workplace.
If you have any queries in connection to this vacancy or your application, please contact us quoting the vacancy reference number and a member of the team will get in touch with you as soon as possible.
Senior Cyber Security (GRC) Analyst (Basé à London) employer: Golden Bees
Contact Detail:
Golden Bees Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Cyber Security (GRC) Analyst (Basé à London)
✨Tip Number 1
Familiarise yourself with the specific governance, risk management, and compliance frameworks mentioned in the job description. Understanding these frameworks will help you speak confidently about how you can contribute to the team during interviews.
✨Tip Number 2
Network with professionals in the cyber security field, especially those who work in GRC roles. Attend industry events or webinars to connect with potential colleagues and learn more about the current trends and challenges in the sector.
✨Tip Number 3
Prepare to discuss your experience with risk assessments and compliance audits in detail. Be ready to provide examples of how you've successfully managed risks or improved compliance in previous roles, as this will demonstrate your practical knowledge.
✨Tip Number 4
Research UK Power Networks and their approach to cyber security. Understanding their specific challenges and initiatives will allow you to tailor your responses in interviews and show that you're genuinely interested in contributing to their mission.
We think you need these skills to ace Senior Cyber Security (GRC) Analyst (Basé à London)
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in governance, risk management, and compliance. Use keywords from the job description to demonstrate that you meet the specific requirements for the Senior Cyber Security (GRC) Analyst role.
Craft a Compelling Cover Letter: Write a cover letter that not only outlines your qualifications but also explains why you're passionate about cyber security and how your skills align with the company's goals. Mention any specific projects or experiences that relate to the responsibilities listed in the job description.
Showcase Relevant Certifications: If you have certifications like CISSP, CISA, or CISM, make sure to prominently display them in your application. These credentials are particularly relevant for this role and can set you apart from other candidates.
Highlight Soft Skills: In addition to technical skills, emphasise your communication and problem-solving abilities. The role requires interaction with various stakeholders, so showcasing your ability to convey complex information clearly will be beneficial.
How to prepare for a job interview at Golden Bees
✨Understand the Role
Make sure you have a solid grasp of the responsibilities and requirements of the Senior Cyber Security (GRC) Analyst position. Familiarise yourself with key concepts in governance, risk management, and compliance, as well as relevant industry standards like ISO 27001.
✨Prepare for Technical Questions
Expect to be asked about your experience with cyber security risk assessments and compliance frameworks. Brush up on your knowledge of specific regulations such as Cyber Essentials and the NIS Regulations, and be ready to discuss how you've applied these in previous roles.
✨Showcase Your Problem-Solving Skills
Be prepared to provide examples of how you've tackled complex IT risks in the past. Highlight your analytical skills and your ability to develop pragmatic solutions that align with business objectives.
✨Demonstrate Communication Skills
Since the role involves regular interaction with senior management and various stakeholders, practice articulating your thoughts clearly. Be ready to explain technical concepts in a way that non-technical audiences can understand, showcasing your ability to bridge the gap between technical and non-technical teams.