At the forefront of the fight to protect energy consumers, Ofgem is strengthening its internal defences - because safeguarding our systems against cyber threats is vital to delivering our mission. We’re looking for a Principal Cyber Security Architect to join us and lead the charge in shaping secure, resilient digital systems at the heart of our organisation. Ofgem is Great Britain’s independent energy regulator. Our primary responsibility is to protect energy consumers, especially the most vulnerable, while at the same time working with government, industry and consumer groups to deliver a clean, more affordable and secure net-zero energy system at the lowest cost to consumers and drive economic growth.
We’re offering a permanent role where you’ll apply your security architecture expertise to projects with strategic impact, influencing decisions at the highest level. This is an opportunity to make a tangible difference by helping us transform our technology landscape while reducing cyber risk across the organisation. Your work will ensure we stay secure by design, resilient by default, and consistently prepared for evolving threats. You’ll work at the heart of a multidisciplinary team, collaborating with internal stakeholders and leading national security partners to embed robust security into every stage of the digital lifecycle.
As a recognised expert, you’ll play a central role in building long-term cyber strategies and providing guidance that sets standards across our organisation and the wider energy ecosystem. We’re looking for someone with a deep understanding of security architecture and a proven track record of influencing complex programmes and senior leaders. Your approach to solving challenges will be methodical and strategic, and you’ll be comfortable operating in fast-paced, high-stakes environments where your guidance truly matters.
In return, you’ll join a collaborative and inclusive culture that values innovation and supports development. You’ll benefit from flexible working arrangements, excellent civil service benefits, and the opportunity to be part of a high-profile mission that impacts millions of people and the UK’s energy future. We have a critical purpose to lead the development of secure digital systems and architecture within our organisation, combating cyber threats and strengthening resilience across the UK’s energy landscape through trusted design, strategic leadership, and expert guidance.
Key Responsibilities:- Lead projects with high strategic impact, setting a strategy that can be used in the long term and across the whole organisation.
- Ensure the CTO function and teams have a constantly updated repository of best practice resources available to reduce cyber risk whilst transforming towards Secure By Design.
- Review and assess threats affecting the market, based on effective partnerships with the Security, Intelligence and Law Enforcement Agencies, other Regulators and energy sector partners.
- Leverage a variety of sources to continuously maintain Ofgem Cyber Reference Architecture with principles, requirements, patterns, anti-patterns, implementation, engineering and operational maintenance options.
- Influence key organisational and architectural decisions, and interact with senior stakeholders across organisations to reach and influence a wide range of people across larger teams and communities.
- Provide clear and transparent work objectives, milestones and success metrics in your area of expertise to oversee and co-ordinate successful team outcomes.
- Collaborate closely with other teams to manage interdependencies, risks and resourcing to support portfolio delivery.
- Demonstrate effective diversity and inclusive team management within their team and the wider organisation.
- Use applied security expertise to develop and maintain solutions that align with Ofgem Cyber guidance, to support the improvement of cyber resilience for the organisation.
- Identify key programme and technical risks, leading the design of mitigating security architectures.
- Create and clearly communicate security expectations to industry, providing expert guidance to operators on interpreting such statements into meaningful and appropriate security requirements.
- Document expert cyber architecture design reviews of operator system architectures to identify security weaknesses and recommend mitigations.
- Identify and Document Cyber Risks within the Secure By Design lifecycle.
- Provide expert advice on security architecture implications of technological trends when applied to existing systems.
- Effectively communicate difficult risk and security concepts in accessible ways that can be clearly understood by business leaders.
- Contribute to and develop risk communication strategies.
- Attend, lead and provide expert input to Specialist Interest Groups to share security best practice across the sector.
- Follow a methodical and repeatable approach to reviewing the security of a system architecture and describe that approach.
- Expertise in security architecture and applied security capability.
- Certified to one or more of the following: CISSP, GICSP, GRID, SABSA, TOGAF.
- Experience of working in Cyber Security within Critical National Infrastructure.
- Extensive experience working collaboratively with diverse colleagues.
- Able to achieve and maintain SC clearance.
- Experience of working in the Energy Sector.
- Seeing the Big Picture
- Changing and Improving
- Making Effective Decisions
- Communicating and Influencing
Please refer to the Candidate Pack and Role Profile attached for full details.
Alongside your salary of £61,446, OFGEM contributes £17,800 towards you being a member of the Civil Service Defined Benefit Pension scheme. Ofgem can offer you a comprehensive and competitive benefits package which includes; 30 days annual leave after 2 years; Excellent training and development opportunities; Hybrid working, flexible working hours and family friendly policies.
This exciting blend of professional challenge and personal reward identifies career opportunities at Ofgem as something to get excited about.
This vacancy is using Success Profiles, and will assess your Behaviours, Experience and Technical skills. When you press the ‘Apply now’ button, you will be asked to complete personal details (not seen by the sift panel), and upload a copy of your CV anonymising all details where necessary. You will then be asked to provide a 1250 word ‘personal statement’ evidencing how you meet the essential and desirable skills and capabilities listed in the role profile.
The Civil Service values honesty and integrity and expects all candidates to abide by these principles. Ofgem takes any incidences of cheating very seriously. Please ensure all examples provided are of your own experience. Any instances of plagiarism or other forms of cheating will be investigated and, if proven, the relevant applications will be withdrawn from the process.
Principal Security Architect employer: Ofgem
Contact Detail:
Ofgem Recruiting Team