At a Glance
- Tasks: Lead cyber security risk assessments and develop compliance strategies to protect vital business operations.
- Company: Join UK Power Networks, a leader in energy sector innovation and security.
- Benefits: Enjoy a competitive salary, bonus, remote work options, and extensive health benefits.
- Why this job: Make a real impact in safeguarding essential services from cyber threats while advancing your career.
- Qualifications: Experience in GRC roles or related fields, with knowledge of cyber security principles.
- Other info: Collaborative team environment with opportunities for mentorship and professional growth.
The predicted salary is between 68000 - 85000 Β£ per year.
This Senior Cyber Security Risk Specialist will report to the Cyber Security Governance, Risk & Compliance Manager and will work within the Information Systems directorate based in either our London or Crawley office. You will be a permanent employee.
You will attract a salary of up to Β£85,000.00 depending on experience, skills and qualifications and a bonus of 7.5%. This role can also offer blended working after probationary period (6 months) - 3 days in the office and 2 remote.
Job purpose: The Senior Cyber Security Risk Specialist will support the Cyber Security GRC Manager in developing IT governance, risk management, and compliance strategies across UK Power Networks information applications and users to safeguard essential business services and operations from cyber threats.
Dimensions:
- People - Work collaboratively in a team of circa 8-10 permanent and temporary GRC resources and specialist 3rd Party GRC service providers. Mentor less experienced GRC analysts, providing guidance and training.
- Industry and Regulatory β deputise for the GRC manager to represent UKPN in energy sector industry forums and regulatory working groups, working collaboratively with Ofgem and the Department for Energy Security and Net Zero.
- Communication β communicate and work with all teams and partners in UK Power Networks. Good verbal, written, and presentational skills to express risks and the potential possible effects to the business and make reasoned recommendations for management action to mitigate or reduce the risks.
- Stakeholders β regular and ongoing interaction with senior management across IT, IS and the Business; Build relationships with internal support teams, internal and external auditors, specialist 3rd party service providers and partners to manage IT risk, and to monitor mitigation plans and actions.
Principal accountabilities:
- Risk Management: Conduct cyber security risk assessments following the UK Power Networks risk assessment framework and methodology, identifying and explaining findings and treatment actions to important partners.
- Reporting: Produce management information related to the risk and control environment. Support IS teams to define main control metrics to demonstrate their effectiveness.
- Information Security Management System Support: Operate and maintain the information security management system and artefacts, in compliance with ISO 27001/27002.
- Policies and Standards: establish GRC policies, standards and procedures to monitor UKPN information security controls, exceptions, risks, and testing including management reporting on performance.
- Controls Framework: Ensure a fit for purpose and robust IT control environment and support a roadmap for IT controls improvements.
- Compliance: Design, implement, and run processes to monitor UKPN IT compliance to legal and regulatory requirements.
- Business Continuity and Disaster Recovery: Own and maintain IT resilience and business continuity plans, plan, coordinate test exercises.
- GRC Systems and Tools Support: support the technical implementation, maintenance and configuration of the suite of GRC tools, products and systems.
- Stakeholder Management: Engage and work with important partners across IT, IS and the Business.
- Supply Chain and 3rd Party: Engage, interact and ensure 3rd party supplies are meeting cyber security expectations.
Nature and scope: The Information Systems Department works across UK Power Networks, supporting us in the achievement of our vision to maintain its position as best DNO. Continuous improvement, customer service and seamless delivery is at the heart of this ethos and are therefore underpinned by effective cyber security.
You will assess Cyber and IT risks and undertake risk management activities within UK Power Networks. You will support UK Power Networks cyber security maturity improvements in processes that are necessary to protect our customers from cyber threats.
Knowledge: We ask that you understand governance, risk management, and compliance principles, in addition to a knowledge of relevant laws, regulations, and industry standards. We are looking for a detailed knowledge and practical expertise in at least 3 of the following specialist areas:
- Specific Industry Standards
- IS/IT Operational Controls and Governance
- Business Continuity Planning and Disaster Recovery
- Supply Chain and 3rd Party Risk Management
Problem Solving: The role must have strong analytical and problem-solving skills to recommend pragmatic mitigating solutions for IT risks across the organisation.
Accountability: The Senior role ensures we are compliant with relevant laws, regulations, and industry standards, in a sustainable way.
Qualifications: Practical experience in a GRC role or related profession e.g. risk, audit, cyber security or similar practical experience in IT or OT role with a desire to move into cyber security.
We are committed to equal employment opportunity regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, or veteran status.
Senior Cyber Security (GRC) Analyst in Crawley employer: UK Power Networks
Contact Detail:
UK Power Networks Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Senior Cyber Security (GRC) Analyst in Crawley
β¨Tip Number 1
Network like a pro! Get out there and connect with folks in the cyber security field. Attend industry events, join online forums, and donβt be shy about reaching out on LinkedIn. You never know who might have the inside scoop on job openings!
β¨Tip Number 2
Prepare for interviews by brushing up on your knowledge of GRC principles and relevant regulations. Be ready to discuss how youβve tackled risk management challenges in the past. We want to see your problem-solving skills in action!
β¨Tip Number 3
Showcase your expertise! Create a portfolio or a personal website where you can highlight your projects, certifications, and any relevant experience. This is a great way to stand out and demonstrate your passion for cyber security.
β¨Tip Number 4
Donβt forget to apply through our website! Itβs the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace Senior Cyber Security (GRC) Analyst in Crawley
Some tips for your application π«‘
Tailor Your CV: Make sure your CV is tailored to the Senior Cyber Security Risk Specialist role. Highlight relevant experience in governance, risk management, and compliance, and donβt forget to showcase any specific industry standards youβre familiar with.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're the perfect fit for the role. Mention your passion for cyber security and how your skills align with our mission at UK Power Networks.
Showcase Your Problem-Solving Skills: In your application, be sure to highlight your analytical and problem-solving skills. Give examples of how you've tackled challenges in previous roles, especially those related to IT risks and compliance.
Apply Through Our Website: We encourage you to apply through our website for a smoother process. Itβs the best way for us to receive your application and ensures you donβt miss out on any important updates!
How to prepare for a job interview at UK Power Networks
β¨Know Your GRC Fundamentals
Make sure you brush up on governance, risk management, and compliance principles. Familiarise yourself with relevant laws and industry standards like ISO 27001 and Cyber Essentials. This will help you speak confidently about how you can contribute to the company's cyber security posture.
β¨Showcase Your Problem-Solving Skills
Prepare to discuss specific examples where you've identified risks and implemented solutions in previous roles. Highlight your analytical skills and how you've developed governance strategies that effectively mitigate IT risks. Real-life scenarios will make your answers stand out!
β¨Engage with Stakeholders
Since this role involves regular interaction with senior management and external partners, practice how you would communicate complex risks and recommendations clearly. Think of ways to demonstrate your ability to build relationships and work collaboratively across teams.
β¨Prepare for Technical Questions
Expect questions related to IT operational controls, business continuity planning, and third-party risk management. Brush up on your technical knowledge and be ready to discuss how you would assess and improve the control environment within the organisation.