Cyber Controls Specialist

Cyber Controls Specialist

Full-Time 56700 - 69300 £ / year (est.) Home office (partial)
S

At a Glance

  • Tasks: Manage and improve cyber security controls to protect critical national infrastructure.
  • Company: Join Sizewell C, a key player in the UK's low-carbon energy future.
  • Benefits: Enjoy 28 days annual leave, a 5% bonus, and a generous pension scheme.
  • Other info: Flexible hybrid working and a collaborative team culture await you.
  • Why this job: Make a real impact on national security while developing your cyber skills.
  • Qualifications: Degree in Cyber Security or related field with 3+ years of experience.

The predicted salary is between 56700 - 69300 £ per year.

Sizewell C is entering an exciting phase of growth as we mature into an independent organisation and continue building one of the UK’s largest and most important energy projects. We are now recruiting the below position:

Position: Cyber Controls Specialist

Security Clearance: Active Security Clearance is required and must already be in place

Location: London, Leiston or Ipswich, with hybrid working and a minimum of 2 days per week on-site. Travel to other Sizewell C locations may be required.

Contract: Permanent, full-time

Benefits include:

  • Annual Leave: 28 days per annum, increasing to 30 days after 5 years of service, plus bank holidays
  • Bonus: 5% annual bonus
  • Pension Contributions: Defined Contribution Pension Scheme with up to 7.5% employee contribution 15% employer contribution
  • Life Assurance: Up to 8 x salary

Closing Date: 1st October 2026

About the Role: The Cyber Controls Specialist plays an important role in maintaining and improving Sizewell C's cyber security controls environment. Reporting to the Cyber Controls Manager, you will be responsible for the day-to-day management of the cyber security controls library, ensuring controls are accurately documented, supported by appropriate evidence and aligned to organisational risks and regulatory requirements. Working closely with cyber security, digital and risk management teams, you will help ensure controls remain effective, auditable and fit for purpose. This is an excellent opportunity for a cyber security professional with experience in controls governance, risk management or security assurance to contribute to the protection of critical national infrastructure.

Key Responsibilities:

  • Controls Library Management
    • Maintain the cyber security controls library, ensuring records remain accurate, complete and up to date.
    • Process additions, amendments and retirements of controls through established governance and change management processes.
    • Conduct regular reviews of controls documentation, identifying gaps, inconsistencies, duplicate records or missing evidence.
    • Support the ongoing development and maintenance of the control’s taxonomy, ensuring controls are correctly classified and aligned to organisational standards.
    • Maintain clear audit trails and documentation standards across all control records.
    • Maintain the relationship between the cyber risk register and the cyber controls library, ensuring mappings remain accurate and current.
    • Support the identification of gaps in control coverage and work with stakeholders to address discrepancies between risk treatments and implemented controls.
    • Assist in the evaluation of risk treatment options and provide input into risk-based decision-making activities.
    • Support the assessment of control effectiveness and identify opportunities for improvement.
    • Contribute to the enhancement of processes, governance arrangements and working practices.
  • Controls Monitoring & Assurance
    • Support ongoing monitoring activities by gathering evidence of control operation and coordinating testing activities with control owners.
    • Assist in the preparation of evidence packs, audit materials and supporting documentation for regulatory inspections, compliance reviews and assurance activities.
    • Monitor remediation activities and highlight overdue actions for escalation.
    • Track outcomes from control testing, audits and reviews, ensuring findings are appropriately recorded and addressed.
    • Keep up to date with emerging cyber threats, regulatory developments and industry good practice, assessing their potential impact on existing controls.
  • Governance & Stakeholder Engagement
    • Attend governance forums and provide accurate updates on control status, remediation activities and risk-related controls.
    • Prepare reports, dashboards and status updates for cyber security governance activities.
    • Record and track actions arising from governance meetings through to completion.
    • Build effective relationships with control owners, risk specialists and technical teams to ensure controls information remains accurate and aligned.
    • Support the Cyber Controls Manager in maintaining an effective and auditable controls framework.

Knowledge & Skills:

  • Good understanding of cyber security controls and the principles of control design, implementation and governance.
  • Working knowledge of recognised cyber security frameworks such as ISO 27001.
  • Understanding of the relationship between cyber risks, risk treatments and security controls.
  • Strong attention to detail, with the ability to maintain structured documentation to a consistent and auditable standard.
  • Good written and verbal communication skills, with the ability to prepare reports and contribute effectively to governance discussions.
  • Understanding of audit requirements and evidence management practices.
  • Collaborative approach with the ability to engage effectively with technical teams, control owners and stakeholders across the business.
  • Familiarity with Governance, Risk and Compliance (GRC) tools or risk and controls management platforms.
  • Understanding of cloud security concepts within Microsoft Azure and Microsoft 365 environments.
  • Knowledge of cyber security governance, assurance and compliance activities within regulated environments.

Qualifications & Experience:

  • Degree qualified, or equivalent, in Cyber Security, Information Security, Information Technology, Computer Science or a related discipline.
  • Minimum of three years' experience within cyber security, information security, controls governance or risk management.
  • Experience contributing to a cyber security controls framework, controls library or equivalent governance structure.
  • Working within formal risk management processes and supporting risk register activities.
  • Collection, maintenance and organisation of evidence used to demonstrate control effectiveness.
  • Participation in governance, assurance or compliance activities.
  • Production of reports, status updates and management information for technical or non-technical audiences.
  • Recognised certification such as CompTIA Security+, SSCP, ISO 27001 Foundation, or progress towards CISSP, CISM, CISA or CRISC.
  • Experience within the nuclear sector or another highly regulated Critical National Infrastructure environment, such as defence, energy, transport or water.
  • Supporting governance committees, assurance reviews or regulatory activities in a technical or advisory capacity.

Why Join us?

  • Be part of one of the most important low-carbon energy projects in the UK.
  • Work in a mission-driven environment that values innovation, integrity, and long-term sustainability.
  • Competitive salary, comprehensive benefits, and opportunities for career development.
  • Flexible and hybrid working options.

Humility

  • Recognise the value brought from different cultures and experiences
  • Be open to others' points of view and ideas, be willing to debate and to compromise

Positivity

  • Positively challenge poor quality and performance
  • Identify solutions at the lowest possible level
  • Encourage tier 1s and others to bring new ideas forward

Respect

  • Value the rules and environment in which we operate
  • Give and receive feedback with respect
  • Embrace and engage with new people and ideas

One team, working closely together and helping each other

  • Empowered teams always looking forward.
  • Shared responsibility for delivering the project outcomes.

Clarity

  • Communicate clearly and consistently
  • Promote collaboration and team alignment
  • Drive simplification at all levels

Cyber Controls Specialist employer: Sizewell C Limited

Sizewell C Limited is an exceptional employer, offering a dynamic work environment in the heart of London where innovation meets infrastructure. With a strong focus on employee development, you will have access to comprehensive training and growth opportunities, alongside a competitive benefits package that includes a 5% bonus and a robust pension scheme. Join a collaborative culture that values your expertise in large-scale projects and empowers you to make a meaningful impact in the nuclear sector.

S

Contact Details:

Sizewell C Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Controls Specialist

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Sizewell C Limited, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Sizewell C Limited

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Sizewell C Limited. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Controls Specialist

Cyber Security Controls Management
Controls Governance
Risk Management
Security Assurance
ISO 27001
Attention to Detail
Documentation Standards

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Sizewell C Limited insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Sizewell C Limited that you’re committed to staying ahead in the game.

How to prepare for a job interview at Sizewell C Limited

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Sizewell C Limited to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Sizewell C Limited.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.