At a Glance
- Tasks: Join our Cyber Risk & Assurance team to tackle complex cyber challenges and enhance security.
- Company: Southern Water, a leader in transforming the water industry with a focus on sustainability.
- Benefits: Enjoy a competitive salary, generous pension, health benefits, and flexible working options.
- Other info: Be part of a dynamic environment with significant career growth opportunities.
- Why this job: Make a real impact in cyber security while collaborating with diverse teams and experts.
- Qualifications: Degree-level education or equivalent experience in cyber security and risk management.
The predicted salary is between 60000 - 60000 £ per year.
This is a fantastic opportunity to join Southern Water’s Cyber Risk & Assurance team, the organisation’s second line of defence within the wider Cyber Security function. As a Cyber Risk & Assurance Analyst, you’ll play a central role in helping the business understand, manage and reduce cyber risk across critical operations.
You’ll be responsible for developing and improving cyber risk insights in your area of specialism, driving process and tooling enhancements, and supporting stakeholders across Technology, Legal and the wider business. This is a role for someone who enjoys tackling complex problems, breaking them down into actionable solutions, and collaborating with a wide range of experts.
You’ll also act as a trusted advisor helping colleagues understand cyber threats, risks and controls, and supporting the wider team in embedding strong cyber risk management practices across Southern Water.
What you will be responsible for:
- You will conduct complex cyber risk assessments, strengthen key controls, deliver clear risk insights, and drive improvements across cyber domains — all while building collaborative relationships across Technology, Security, Legal and the business.
Key Responsibilities
- Maintain an up‐to‐date understanding of the cyber threat landscape, relevant regulations (including NIS1/NIS2 and GDPR), and emerging risks.
- Lead, plan and perform complex cyber risk assessments aligned to industry‐recognised frameworks, testing the design and effectiveness of cyber controls.
- Produce high‐quality risk assessment reports with clear, actionable conclusions that support timely risk‐based decision‐making.
- Identify and deliver improvements across domains such as identity & access management, application security, endpoint security, and network security.
- Work closely with stakeholders across Security, Technology, Legal, Internal Audit and the wider business to assess control gaps, prioritise remediation actions and track progress to completion.
- Build strong working relationships across teams to influence, support and strengthen cyber risk management practices.
- Drive process improvements and enhancements across the Cyber Risk & Assurance function.
Additional requirements specific to the role
- Will work closely with both technical teams and non‐technical stakeholders, requiring an ability to communicate complex concepts clearly.
- Must be comfortable operating in an environment with regulatory, operational and cyber security obligations.
- Occasional engagement with internal or external audit teams may be required.
What you’ll bring to the role:
Essential
- Degree‐level education or equivalent experience.
- Strong knowledge of cyber security and information security control best practice.
- Proven experience in cyber security, risk management or security assessment (10+ years, or advanced degree with 8+ years).
- In‐depth understanding of key frameworks such as NIST (800‐37, 800‐30, 800‐53), ISO 27001/27005, SOC 2, PCI or MITRE ATT&CK.
- Solid understanding of cloud models, application security, vulnerability and patch management.
- Experience in regulated and/or unionised environments.
- Excellent communication skills with the ability to simplify complex findings for senior management.
- Strong attention to detail and a proactive, positive, innovative mindset.
Desirable
- GRC or security certifications (e.g., CISSP, CISM, CRISC, CISA, GCFE, GSEC, CCSP).
- Experience with cyber risk modelling (e.g., CyberCube, RMS, Cyence).
- Hands‐on experience with frameworks such as ISO 27001, NIST CSF, NCSC CAF or CIS Controls.
- Understanding of ICS/OT environments.
Southern Water is at the forefront of transforming Britain’s water industry, investing significantly to enhance resilience, sustainability, and service excellence. With £7.8bn planned investment for 2025-30, this is an unparalleled opportunity to join a business committed to delivering a generational shift in the way water services are managed.
You will be joining at a time of significant change, working alongside a highly skilled leadership team with a clear vision for the future. We offer an environment where senior professionals can make a meaningful impact, influence major strategic decisions, and drive long-term value creation.
At Southern Water, we believe diverse perspectives drive innovation. If you’re passionate about making a positive impact and think you can bring value to our team, we’d love to hear from you—even if you don’t tick every box. Your unique skills and experiences could be exactly what we need.
If this role isn’t quite what you’re looking for but are keen to be contacted about opportunities at Southern Water, you can register your details here: Introduce Yourself.
Our Commitment to Diversity
We welcome applicants from all backgrounds, identities, and experiences. We do not discriminate based on race, ethnicity, gender, sexual orientation, age, disability, religion, or any other protected characteristic. If you need reasonable adjustments during the recruitment process, please let us know.
Additional information:
In line with Southern Water’s security requirements, successful candidates will be required to provide evidence of their identity, eligibility to work in the UK, criminal record check (DBS) and verification of their employment and/or education history for the past three years. Appointment to this role is subject to the successful completion of all preemployment checks, including security vetting. Please note that if a candidate does not meet the required security standards or fails to pass the vetting process, Southern Water reserves the right to withdraw the offer of employment. Some positions may also require higher levels of security vetting, which may involve providing additional documentation.
Interested in the role?
We reserve the right to close this advertisement early if we receive a high volume of suitable applications, so if you are interested in the position please do send your application over today to ensure consideration. We truly appreciate every application. Please note, that due to the volume of interest, we may not be able to provide personalised feedback to all applicants.
Our Benefits
- Company and performance-related bonus
- Generous pension with up to 11% company contribution
- Life assurance payment equal to four times your annual salary
- Health benefits through a Cash Plan
- Two paid community volunteering days a year
- 25 days annual holiday
- Occupational health service
- Retail discount app
- We offer competitive maternity leave, and flexible return to work options
Everybody Welcome
We value diversity and are committed to providing an inclusive and accessible recruitment process. If you require any reasonable adjustments to facilitate your participation in the recruitment process, please do not hesitate to let us know.
Need flexibility in your work?
Does this opportunity excite you but you’re not 100% sure if you meet all the requirements for the role? Or are you concerned that ‘normal’ office hours aren’t possible given your personal circumstances? Whilst we can’t accommodate every flexible working request, we’ll try to find a practical solution. So why not engage with us and find out more about this role?
Cyber Risk & Assurance Analyst in Durrington employer: Southern Water group
Southern Water is an exceptional employer, offering a dynamic work environment in Durrington where innovation and collaboration thrive. With a strong commitment to employee growth, competitive benefits including a generous pension scheme and health plans, and a culture that values diversity and inclusion, you will have the opportunity to make a meaningful impact in the water industry while enjoying a supportive and flexible workplace.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Risk & Assurance Analyst in Durrington
✨Tip Number 1
Network like a pro! Reach out to folks in the cyber security field, especially those at Southern Water. A friendly chat can open doors and give you insights that a job description just can't.
✨Tip Number 2
Prepare for the interview by brushing up on your knowledge of cyber risk frameworks like NIST and ISO. Be ready to discuss how you've tackled complex problems in the past—this is your chance to shine!
✨Tip Number 3
Show off your communication skills! Practice explaining complex cyber concepts in simple terms. This will help you connect with both technical and non-technical stakeholders during interviews.
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you're genuinely interested in joining the Southern Water team.
We think you need these skills to ace Cyber Risk & Assurance Analyst in Durrington
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in cyber security and risk management. We want to see how your skills align with the role of Cyber Risk & Assurance Analyst, so don’t hold back on showcasing your relevant achievements!
Showcase Your Communication Skills:Since this role involves working with both technical and non-technical stakeholders, it’s crucial to demonstrate your ability to simplify complex concepts. Use clear language in your application to show us you can communicate effectively across different teams.
Highlight Your Problem-Solving Abilities:We’re looking for someone who enjoys tackling complex problems. In your application, share examples of how you've approached challenges in the past and the actionable solutions you implemented. This will help us see your analytical mindset in action!
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows us you’re keen to join our team at Southern Water!
How to prepare for a job interview at Southern Water group
✨Know Your Cyber Landscape
Before the interview, make sure you’re up-to-date with the latest trends in cyber threats and regulations like NIS1/NIS2 and GDPR. This knowledge will not only impress your interviewers but also show that you’re proactive about understanding the environment you'll be working in.
✨Master the Frameworks
Familiarise yourself with key frameworks such as NIST and ISO 27001. Be prepared to discuss how you've applied these in past roles, especially in conducting risk assessments or improving security controls. Real-world examples will help demonstrate your expertise.
✨Communicate Clearly
Since this role involves liaising with both technical and non-technical stakeholders, practice simplifying complex concepts. Think of ways to explain your past projects or findings in a way that anyone can understand, which will showcase your communication skills.
✨Show Your Collaborative Spirit
Highlight your experience in building relationships across teams. Prepare examples of how you’ve worked with different departments to enhance cyber risk management practices. This will illustrate your ability to be a trusted advisor and team player.