أبلاي إيدج ابدأ البحث عن عمل

Governance, Risk & Compliance Lead

InfoSec People Ltd · London Area, United Kingdom

قدّم وتابع مع أبلاي إيدج
Our client, an essential services operator within the utilities and technology sectors, is seeking a Cyber Security Governance, Risk & Compliance Lead for a permanent position based in London with hybrid working. The role will support regulatory engagement, cyber resilience and compliance activities, helping to ensure alignment with NIS Regulations, NIS2, Ofgem expectations, the Enhanced Cyber Assessment Framework (ECAF) and ISO 27001. Occasional travel to Belgium and Norfolk may be required.Key Responsibilities:Act as the primary point of contact for cyber security regulatory engagement with Ofgem, competent authorities, auditors and external stakeholdersCoordinate regulatory submissions, NIS self-assessments, improvement plans, evidence packs and responses to regulatory enquiries, inspections and auditsLead assurance activities across NIS Regulations, NIS2, Ofgem cyber security requirements, ECAF, ISO 27001 and other relevant resilience frameworksMonitor emerging cyber security legislation, regulatory requirements and industry guidance, assessing their impact and recommending appropriate actionsMaintain and review the Cyber Security Risk Register, ensuring threat scenarios, mitigations, treatment plans and governance arrangements remain currentSupport the governance and status reporting of the Cyber Security Roadmap, including risks, issues, actions, dependencies and third-party deliverablesDevelop and maintain a cyber security supply chain assurance programme, including supplier risk assessments, due diligence and ongoing third-party assurancePrepare dashboards, key performance indicators, reports and briefing materials for senior leadership and Board-level oversightJob Requirements:Significant experience in cyber security governance, risk and compliance within a regulated or critical infrastructure environmentStrong knowledge of risk assessments, risk analysis, risk registers and cyber security treatment plansExperience of third-party management, supplier risk assessments and supply chain assuranceUnderstanding of NIS Regulations, NIS2, Ofgem requirements, ECAF and the regulatory obligations of an Operator of Essential ServicesExperience supporting audit and review activities, regulatory submissions, assurance programmes and improvement plansKnowledge of Information Security Management Systems, including cyber security policies, standards, procedures and governanceAbility to interpret changing legislation and industry guidance, translating requirements into practical compliance actionsExcellent report writing, stakeholder management and communication skills, with the confidence to present complex information clearly to senior audiencesAdditional Information:Hybrid working in line with the organisation’s policy, combining office and remote workingOccasional travel to Belgium, Norfolk and other locations as requiredOpportunity to contribute to the cyber resilience of essential national infrastructureRole with broad exposure to regulatory engagement, cyber risk management and strategic improvement programmesIf you are an experienced Cyber Security Governance, Risk & Compliance professional seeking a role within the utilities and critical infrastructure sectors, apply now to support the continued development of cyber resilience and regulatory compliance.