Chief Information Security Officer in Aberdeen

Chief Information Security Officer in Aberdeen

Aberdeen Full-Time On-site
R

Job Title: Chief Information Security Officer
Location: Aberdeen
Reporting to: Chief Digital & Information Officer
Number of Roles Available: 1
Company Overview:
Join Great British Energy and be part of powering the UK's Clean Energy Future.
At GBE, we're not just building an energy company - we're shaping the future of the UK's energy landscape.
Our mission is clear:
* Drive clean energy deployment across the UK as a strategic developer, investor, and owner of renewable projects
* Deliver benefits for communities and taxpayers, ensuring the clean energy transition creates jobs, boosts local economies, and increases public ownership
* We focus on innovation, sustainability, and impact, working on projects that matter - from large-scale national renewable investments to empowering local and community energy initiatives.
Joining GBE means
* Purpose-driven work Be part of a national effort to accelerate the clean energy transition
* Career growth Opportunities to develop expertise in cutting-edge energy technologies and strategic investment
* Collaboration and flexibility Work with passionate professionals in a dynamic, forward-thinking environment
If you want to make a real difference and help power a greener, fairer future for the UK, GBE is the place for you.
We welcome applications from all backgrounds and communities. If you require reasonable adjustments during the recruitment process, please let us know.
About the Role:
The role reports to the Chief Digital & Information Officer and is one of the small leadership group standing up GBE's digital function, alongside the CDIO and the Enterprise Architect & Innovation. The postholder is the senior executive accountable for advising on, coordinating and assuring GBE's approach to the NCSC Cyber Assessment Framework and the security of personal data under UK GDPR, and ensures GBE meets the standards expected of both a public body and the energy sector - a sector where the resilience bar is deliberately high.
This is a rare greenfield mandate. The foundational work on GBE's security standards and operating model is already underway, with every significant decision and its reasoning recorded so that the incoming postholder can review, confirm and own those decisions rather than start from a blank page. The role leads initially through delivery partners, the transition arrangements with GBE's incumbent provider and the chosen security delivery model, building the permanent function as GBE's own estate grows. Few roles offer the chance to design the security of a national institution from first principles.
Key Responsibilities:
* Take ownership of the security decisions made during the establishment phase: review the recorded decision log, confirm or adjust the recommendations against the evidence, and carry them into delivery.
* Establish GBE's security operating model and minimum security requirements as the standard all delivery - internal and partner - works to, leveraging best practice and selecting which of the established ICS security foundations within DESNZ GBE carries forward.
* Decide and implement the delivery model for detecting and responding to attacks, with accountability agreed in writing at every stage of the separation from shared services.
* Confirm the standards GBE must meet, close the priority gaps, and stand up the assurance regime that reports through the Digital Investment Governance Committee to the Audit, Assurance and Enterprise Risk Committee.
* Secure the establishment of GBE's own environments - cloud, collaboration, and staff identity and access - as they stand up, so that new services launch on secure foundations.
* Establish incident response for real: plans, roles, on-call arrangements and exercises that prove GBE can handle an incident, not just describe one.
* Baseline GBE's security maturity, agree the target state and publish a prioritised security improvement roadmap with clear ownership and measures of progress.
* Build security requirements into GBE's procurements and strategic partner framework, and assure the first major deliveries against them.
* Build the case and the plan for GBE's permanent security function, growing the capability in step with the estate it protects.
Qualifications and Experience:
Essential:
* Hands on: willing to both govern and personally deliver key parts of GBE's security capability.
* A senior security leader - CISO, deputy CISO or head of security - with a track record in complex, fast-moving organisations, including standing up or substantially rebuilding a security function.
* Ownership of security strategy, risk and assurance at executive level, including presenting risk clearly and honestly to boards and audit committees.
* Operational depth: accountability for detection, response and incident management, including choosing and directing the right delivery model - in-house, managed service or hybrid.
* Depth in security standards and compliance - the NCSC Cyber Assessment Framework, government security standards or comparable regulated regimes - and a record of turning them into practical, proportionate controls.
* Desire to keep abreast of the changing landscape of the security and regulatory environment GBE will be exposed to, and the changing nature of GBE's business.
* Demonstrable expertise in strategic cyber security planning, cyber security governance, cyber risk management, security architecture and cyber incident management.
* Experience securing major technology transitions: cloud adoption, separations from shared or outsourced services, and programmes delivered through multiple partners.
* Accountability for the security of personal data under UK GDPR, including breach response.
* The communication skills and credibility to make security clear and compelling to executives, boards and non-specialists.
* Comfort operating where structures, processes and ways of working are still being established, with the pragmatism to make sound decisions at pace with imperfect information.
Desirable skills
Desirable:
* Experience in the energy, utilities or critical national infrastructure sectors, including an appreciation of operational technology and the resilience expected of energy systems.
* Experience in government, arm's-length bodies or other high-assurance settings, including working with the NCSC.
* Experience exiting shared or outsourced services and standing up independently owned security operations.
* Recognised security qualifications (such as CISSP or CISM), or an equivalent demonstrable record.
Personal Qualities:
* Takes ownership, shows confidence in decision-making, and is willing to challenge constructively
* Focuses on delivering meaningful outcomes and making a positive, lasting impact
* Works collaboratively, valuing different perspectives and building inclusive relationships
* Proactive and adaptable, with a curiosity to explore new ideas and improve ways of working
* Resilient and resourceful in a fast-paced environment
What We Offer:
* Competitive base salary
* Performance-related bonus scheme
* Excellent pension scheme
* 4x salary life assurance
* Group income protection
* 38 days annual leave
* Flexible working arrangements
* Ongoing professional development and training
* Supportive, inclusive working environment
How to Apply:
For further information please contact:
* Caoimhe McCullagh
* Principal Sourcing Specialist
Application Close Date: 15th October


JBRP1_UKTJ

Chief Information Security Officer in Aberdeen employer: Resourcing Group

At MHCLG, we pride ourselves on being an exceptional employer dedicated to making a positive impact in the UK. Our remote working model offers flexibility while fostering a collaborative culture that values innovation and continuous improvement. With opportunities for professional growth and development, you will be part of a mission-driven team committed to empowering communities and enhancing recruitment processes through cutting-edge technology.

R

Contact Details:

Resourcing Group Recruitment Team