At a Glance
- Tasks: Support risk management and governance in a dynamic energy sector.
- Company: Join Scottish Power, a leader in energy innovation.
- Benefits: Competitive salary, professional development, and potential international travel.
- Other info: Collaborative team environment with opportunities for growth.
- Why this job: Make a real impact on cyber security and risk management.
- Qualifications: 3-5 years in risk management, with relevant cyber security qualifications.
The predicted salary is between 40000 - 50000 £ per year.
Our client Scottish Power are currently recruiting for a Risk and Assurance Analyst to join their team based in Glasgow on a contract basis initially. Ideally for this role they are looking for an experienced Risk and Assurance Analyst with a relevant background.
The role will be responsible for working across key areas within SPEN to support the implementation of the Operational Risk Framework, and oversee risk assessment activities. The role will support the Senior Risk and Governance Manager in all aspects of OT risk management and governance, part of the wider Cyber Risk function. This role will also provide a support role in SPEN's ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations and deliver a cyber resilient business.
Accountability Statements- Collaborate with control owners to validate effectiveness of security controls and ensure testability.
- Oversight of the risk reports written by the responsible risk owners.
- Provide support and guidance to risk owners on identifying risks and to ensure that appropriate controls are implemented to mitigate the risk in line with risk tolerance.
- Identifying gaps in action planning and highlighting areas of improvement to ensure risks are adequately managed within the risk tolerance of SPEN risk appetite.
- Deliver training and awareness portfolio for internal and external stakeholders.
- Carrying out independent reporting of organisational risk to senior management and relevant governance forums.
- Facilitating reporting of the effectiveness of security controls and processes through Key Performance Indicators (KPIs), Key Risk Indicators (KRIs) and Key Control Indicators (KCIs).
Work within established security and risk management governance structures, usually under supervision to support, review and undertake risk management activities such as:
- Provide a support role as part of the regular NIS Cyber Assessment framework (CAF) compliance and regular reporting requirements.
- Support the Senior Risk and Governance Manager on all risk and compliance activities.
- Support the Senior Risk and Governance Manager to work collaboratively with the Regulator and the associated professional bodies to ensure the security strategies and plans are understood and in line with regulatory requirements.
- Helping with the analysis and derivation of business-supporting security needs.
- Provide advice to address identified Cyber Security related risks by applying a variety of security capabilities, which may include using published guidance, standards or experts as appropriate.
Technical Skills:
- Obtained or working towards relevant industry cyber security qualifications (e.g. GICSP, CISSP, CISM).
- Experience of developing Cyber Security Risk Management and Governance in an organisation of similar scope and scale to ScottishPower.
- Knowledge in cyber security frameworks and standards. An understanding of cyber security regulations as they apply to a UK energy supplier would be preferred.
- Knowledge in developing and delivering cyber risk assurance programmes.
- Experience of risk assessing cyber security risks and articulating these so that these can be understood at all levels of the organisation.
- Aware of key legislation and regulation impacting the delivery of IT and OT Cyber Security in an energy utility.
- Experienced in developing and communicating Cyber Security Risks.
Personal Skills/Abilities:
- Excellent communication skills.
- Developing and coaching team members.
- Experience of team productivity control.
- Ability to build effective relationships with key stakeholders, with a global perspective multi-cultural understanding and approach.
- Ability to adapt quickly to change.
- High integrity and emotional maturity.
Planning & Organising
- Planning and supporting the delivery of the ongoing SPEN cyber security transformation programme.
- Defining, delivering and reporting remediation plans for internal/external audit and regulatory non-compliance issues.
Internal and External Relationships
- Reports to Senior Cyber Risk & Governance Manager.
Special Requirements (not mandatory)
- Post holder must have the credibility associated with operating at a senior level and have demonstrable experience of influencing at Director Level.
- The role operates as part of a global team and periodic travel to Spain and other company locations may be required.
Minimum Criteria (mandatory)
- 3-5 years in similar work, preference for having worked in industrial sectors (energy or otherwise).
- Experience of developing Cyber Security Risk Management and Governance in an organisation, preferably of similar scope and scale to ScottishPower.
- Knowledge in cyber security frameworks and standards as well as an understanding of cyber security regulations as they apply to a UK energy supplier.
- Record of academic achievement, including some form of recognised qualification from further education, such as a degree or diploma.
- Good oral and written communication skills.
- Numerate and able to deal with finances for the purposes of managing budgets or contracts with suppliers.
- Willingness to travel internationally on business.
- Driving licence.
- Must be a proven team player to work, promote and consolidate efficient team working relationships.
Risk and Assurance Analyst in Glasgow employer: Morson Edge
Contact Detail:
Morson Edge Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Risk and Assurance Analyst in Glasgow
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, especially those at Scottish Power. A friendly chat can sometimes lead to opportunities that aren’t even advertised.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of cyber security frameworks and regulations. Be ready to discuss how your experience aligns with the role's requirements.
✨Tip Number 3
Showcase your communication skills! During interviews, make sure to articulate your thoughts clearly and confidently. This is key for a role that involves collaboration and reporting.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed and you’re considered for the Risk and Assurance Analyst position.
We think you need these skills to ace Risk and Assurance Analyst in Glasgow
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Risk and Assurance Analyst role. Highlight your relevant experience in cyber security risk management and governance, and don’t forget to mention any qualifications you have that align with the job description.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're the perfect fit for this role at Scottish Power. Mention specific experiences that demonstrate your skills in risk assessment and compliance, and show your enthusiasm for the position.
Showcase Your Communication Skills: Since excellent communication is key for this role, make sure your application reflects that. Use clear and concise language, and structure your documents well. This will not only impress us but also show that you can communicate effectively with stakeholders.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It’s the best way to ensure your application gets into the right hands and allows us to keep track of all applicants efficiently.
How to prepare for a job interview at Morson Edge
✨Know Your Cyber Security Frameworks
Make sure you brush up on the key cyber security frameworks and standards relevant to the role. Being able to discuss how these apply to Scottish Power and the energy sector will show that you’re not just familiar with the theory, but also understand its practical implications.
✨Prepare for Scenario-Based Questions
Expect questions that ask you to demonstrate your experience in risk assessment and management. Prepare specific examples from your past roles where you identified risks, implemented controls, or improved processes. This will help you illustrate your problem-solving skills effectively.
✨Showcase Your Communication Skills
As a Risk and Assurance Analyst, you'll need to communicate complex information clearly. Practice explaining technical concepts in simple terms, as you may need to present findings to stakeholders at various levels. This will highlight your ability to build effective relationships.
✨Understand the Regulatory Landscape
Familiarise yourself with the NIS regulations and other relevant legislation impacting the energy sector. Being able to discuss how these regulations influence risk management strategies will demonstrate your readiness to support compliance efforts within the organisation.