Cyber Risk Manager

Cyber Risk Manager

Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
S

At a Glance

  • Tasks: Lead cyber risk management for one of the UK's largest energy projects.
  • Company: Join Sizewell C, a key player in low-carbon energy innovation.
  • Benefits: Enjoy 28 days annual leave, a 10% bonus, and a strong pension scheme.
  • Other info: Flexible hybrid working and a collaborative team culture await you.
  • Why this job: Make a real impact on national energy security while developing your career.
  • Qualifications: Degree in Cyber Security or related field; 5+ years in cyber risk management.

The predicted salary is between 63000 - 77000 £ per year.

Sizewell C is entering an exciting phase of growth as we mature into an independent organisation and continue building one of the UK’s largest and most important energy projects.

We are now recruiting the below position

Security Clearance

Active Security Clearance is required and must already be in place

Location

London, Leiston or Ipswich, with hybrid working and a minimum of 2 days per week on-site. Travel to other Sizewell C locations may be required.

Contract

Permanent, full-time

Benefits include

Annual Leave

28 days per annum, increasing to 30 days after 5 years of service, plus bank holidays

Bonus

10% annual bonus

Pension Contributions

Defined Contribution Pension Scheme with up to 7.5% employee contribution 15% employer contribution

Life Assurance

Up to 8 x salary

Closing Date

1st October 2026

About the Role

The Cyber Risk Manager plays a critical role in ensuring Sizewell C's cyber risks are identified, understood, prioritised and effectively managed.

Reporting directly to the Chief Information Security Officer (CISO), you will lead the organisation's cyber risk management framework, maintain oversight of the cyber risk landscape and ensure risks are managed in line with regulatory requirements and business objectives.

Operating at the intersection of technology, security and business risk, you will translate complex cyber threats into clear and actionable insights, enabling informed decision-making at all levels of the organisation.

Working closely with cyber security, digital, assurance and business teams, you will help strengthen organisational resilience and ensure cyber risk remains a key consideration across strategic and operational activities.

Key Responsibilities

  • Own and maintain the organisation's cyber risk register, ensuring risks are clearly documented, appropriately owned and kept audit ready.
  • Develop and maintain the cyber risk taxonomy, including risk categories, threat sources and impact domains aligned to critical business functions.
  • Define and maintain risk scoring methodologies, appetite thresholds and escalation criteria in collaboration with senior leadership.
  • Ensure cyber risks are assessed, prioritised and managed consistently across the organisation.
  • Establish and maintain processes for the identification, assessment and recording of cyber risks.
  • Ensure risk assessments are undertaken at appropriate trigger points, including new system deployments, major projects and significant business change.
  • Oversee the application of recognised risk assessment methodologies and good practice.
  • Provide guidance and support for complex cyber risk assessments where required.
  • Provide line management and leadership to the Cyber Risk Assessment Lead
  • Oversee the development and delivery of cyber risk treatment plans, ensuring clear ownership, realistic timescales and measurable outcomes.
  • Work closely with cyber security and technology teams to ensure controls are implemented, effective and aligned to identified risks.
  • Maintain traceability between identified risks, mitigating controls and remediation activities.
  • Ensure risk acceptance decisions, exceptions and associated approvals are appropriately governed and documented.
  • Prepare and present cyber risk reports, dashboards and insights for the CISO, senior leadership and governance forums.
  • Monitor risk trends, emerging threats and mitigation progress, highlighting areas requiring management action.
  • Escalate significant risks that exceed approved tolerance levels and provide recommendations for resolution.
  • Ensure cyber risks are appropriately reflected within the wider enterprise risk management framework.
  • Support regulatory submissions, audits and reviews by maintaining robust risk management records and evidence.
  • Stakeholder Engagement
  • Provide expert advice and guidance on cyber risk management across the organisation.
  • Collaborate with Security Operations, Digital and wider business teams to understand emerging threats and assess their potential impact.
  • Support threat modelling, business impact assessments and wider cyber resilience activities.
  • Promote a proactive and risk-informed culture across the organisation.

Knowledge & Skills

  • Thorough understanding of cyber risk frameworks and assessment methodologies, including ISO 27005 and NIST Risk Management Framework.
  • Ability to develop and maintain cyber risk registers, taxonomies, risk scoring methodologies and risk appetite frameworks.
  • Strong understanding of how cyber risk integrates with enterprise risk management and wider organisational governance processes.
  • Ability to translate complex technical risks into clear and meaningful business language for non-technical audiences.
  • Strong analytical, stakeholder management and communication skills.
  • Experience presenting cyber risk information to senior leaders and governance forums.
  • Ability to influence decision-making and drive effective risk-based outcomes across multiple stakeholder groups.
  • Understanding of the UK nuclear cyber security regulatory landscape, including ONR requirements, Security Assessment Principles (Sy APs), NISR and NIS Regulations.
  • Knowledge of threat intelligence processes and how cyber threat information supports ongoing risk assessment and decision-making.
  • Familiarity with assurance, audit and regulatory compliance activities within highly regulated environments.

Qualifications & Experience

  • Degree qualified in Cyber Security, Information Security, Computer Science, Risk Management or a related discipline, or equivalent professional experience.
  • Minimum of five years' experience within cyber security or information security, including at least three years with significant responsibility for cyber risk management.
  • Proven track record of conducting or overseeing cyber risk assessments using recognised methodologies such as ISO 27005, NIST RMF, FAIR or OCTAVE.
  • Experience developing, maintaining and governing cyber risk registers within complex organisations.
  • Establishing or facilitating risk governance forums involving senior stakeholders and risk-based decision-making.
  • Management of cyber risk treatment activities across multiple teams and competing priorities.
  • Production of cyber risk reporting for executive and board-level audiences.
  • Experience working within, or closely alongside, Critical National Infrastructure sectors such as nuclear, defence, energy, transport, water or telecommunications.
  • Relevant professional certification such as CISSP, CISM, CRISC or equivalent.
  • Background within the nuclear sector or other highly regulated industries.
  • Familiarity with environments subject to external cyber security audits, regulatory inspections or formal assurance activities.
  • Previous people management, mentoring or technical leadership experience within a cyber security or risk management function.

Why Join us?

  • Be part of one of the most important low-carbon energy projects in the UK.
  • Work in a mission-driven environment that values innovation, integrity, and long-term sustainability.
  • Competitive salary, comprehensive benefits, and opportunities for career development.
  • Flexible and hybrid working options.
  • Humility
  • Recognise the value brought fromdifferent culturesand experiences
  • Be open to other’s points of view and ideas, be willing to debate and to compromise
  • Positivity
  • Positively challengepoor qualityand performance
  • Identifysolutions at the lowest possible level
  • Encourage tier 1s and others to bringnew ideasforward
  • Respect
  • Value the rules and environment in which we operate
  • Give and receive feedback with respect
  • Embrace and engage with new people and ideas
  • One team, working closely together and helping each other
  • Empowered teams always looking forward.
  • Shared responsibility for delivery the project outcomes
  • Clarity
  • Communicate clearly and consistently
  • Promote collaboration and team alignment
  • Drive simplification at all levels
  • #J-18808-Ljbffr

Cyber Risk Manager employer: Sizewell C Limited

Sizewell C Limited is an exceptional employer, offering a dynamic work environment in the heart of London where innovation meets infrastructure. With a strong focus on employee development, you will have access to comprehensive training and growth opportunities, alongside a competitive benefits package that includes a 5% bonus and a robust pension scheme. Join a collaborative culture that values your expertise in large-scale projects and empowers you to make a meaningful impact in the nuclear sector.

S

Contact Details:

Sizewell C Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Risk Manager

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Sizewell C Limited, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Sizewell C Limited

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Sizewell C Limited. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Risk Manager

Cyber Risk Management
ISO 27005
NIST Risk Management Framework
Risk Assessment Methodologies
Cyber Risk Register Development
Stakeholder Management
Analytical Skills

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Sizewell C Limited insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Sizewell C Limited that you’re committed to staying ahead in the game.

How to prepare for a job interview at Sizewell C Limited

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Sizewell C Limited to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Sizewell C Limited.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.