Senior Security Risk Manager

4 weeks ago


United Kingdom Vantage Consulting Full time

The purpose of this post is to lead the Security Risk Team to ensure that cyber & physical risks facing the business are assessed and data is available to inform business-level and Exec decision-making. The scope includes (but is not limited to), Operational Technology (OT) and associated IT environments comprising of

Optel Network & Services
Critical data centres
The focus being on critical systems that support the operation of the essential service to deliver electricity transmission across England and Wales and that form the scope of NIS Critical Systems.

Responsible for setting the strategy and leading the formation of a consistent cyber risk management framework. The framework will ensure risks are understood by stakeholders, are documented, assessed and appropriate risk mitigation strategies are in place.

The role will lead the engagement on the Cyber Risk Framework with senior leadership, group security and external bodies including Ofgem, DESNZ and NCSC.

You will lead a team of specialists, collaborate with cross-functional teams, and implement risk management strategies tailored to the unique cyber challenges.

ET Asset Operations (AO)
Global Strategic Risk group who provides a risk framework for high level risks
Ensure a regular cadence for OT Cyber risk capture, appraisal, and assessment for NIS critical systems.
Ensure Improvement plans are underpinned by comprehensive risk registers that quantify gaps in our controls that support our NIS critical environment.
Take a lead in ensuring our regulatory submissions have strong risk-based justifications in order to ensure our Improvement plans financed.
Defining the OT Cyber Risk Framework
Driving a consistent approach to the capturing, recording and management of OT Cyber Security risks across the business
Take a lead in OT Cyber Risk Management Governance Forums
Collaborate with Group security to ensure OT Risk Framework aligns to and support group strategic risk assessments.
Leading the business to deliver frequent risk assessments for approval by supported business functions and the Control & Cyber Strategy Manager, ensuring registers are maintained/amended as required.
Leading and managing a team of Operational Technology Cyber risk specialists who will conduct risk assessments of NIS Critical systems.
Ensuring risk assessments are resourced appropriately.
Leads the development of risk assessment processes for ET NIS critical system level risks.
Ensuring risk assessments are completed according to agreed processes and the timescales demanded by the risk assessment programme and supporting group security's strategic risk assessment processes.
Directly supporting selected risk assessments as required.
Ensuring data resulting from risk assessments is shared with the Control & Cyber Strategy team, Cyber risk governance forums and senior managers as required in accordance with agreed processes.
Work closely with leadership to report on risk posture, metrics, mitigation strategies and investment priorities.
Demonstrable experience utilising risk assessment methodologies (e.g., Demonstrable experience working with industry best practices and security control frameworks (e.g., Demonstrable experience implementing security risk management frameworks (e.g., Ability to communicate complex messages both orally & in writing using quantitative & qualitative measures to senior leaders across the business.
Confidence to challenge, take ownership of complex challenges, lead risk assessments, agree and build future improvement plans.
Understanding of UK Network & Information Systems (NIS) Regulations desirable.
Communicating complex messages both orally & in writing using quantitative & qualitative measures.
Able to operate as a highly independent motivated worker and as part of a strong team with a collaborative approach, delivering high-quality outputs.
Previous experience of risk management within an Operational Technology environment


  • Senior Risk

    2 days ago


    United Kingdom Maxwell Bond® Full time

    Security Consultant - Hybrid - Gloucestershire - £80,000 Maxwell Bond have partnered with a consultancy who specialise in cyber risk management and are in an exciting period of growth and are looking to add some more heads to help deliver projects within the MoD. For the nature of this work it is essential that you are able to obtain security clearance or...

  • Senior Consultant

    2 weeks ago


    United Kingdom Electus Recruitment Solutions Full time

    Senior Consultant (Nuclear Weapon Systems) This company is a leading provider of specialised engineering solutions in the defense and security sector. With their expertise spanning critical infrastructure protection, risk management, and advanced technology solutions, they pride themselves on delivering high-quality services to their clients, ensuring...

  • Senior Consultant

    6 days ago


    United Kingdom Electus Recruitment Solutions Full time

    Senior Consultant (Nuclear Weapon Systems) This company is a leading provider of specialised engineering solutions in the defense and security sector. With their expertise spanning critical infrastructure protection, risk management, and advanced technology solutions, they pride themselves on delivering high-quality services to their clients, ensuring...


  • United Kingdom Momentum Security Recruitment Full time

    Security Contract Manager Salary: £42,000 + car/car allowance Location: This is a field based role. As a guide, applicants should live close to the M25 SOUTH: for example Surrey, Sussex, Kent, Croydon etc. Tremendous opportunity to manage the delivery of security services to a portfolio of high-profile corporate sites. We are seeking a candidate that...


  • United Kingdom Atlas Recruitment Group Full time

    Sign in to save Product Security Consultant at Atlas Recruitment Group Ltd . Implementing Security Controls · Good experience of assessing and managing risk (NIST, ISO27001) · Significant experience with using security baselines, mitigations and controls · Experience of MOD Policies and regulations · Experience with security artefacts such as...


  • United Kingdom QCIC group Full time

    Provide a professional security strategy design service to clients on projects as directed by Senior Management. Act as project manager to ensure service and project work are carried out within agreed deadlines and budget. Prepare technical and financial proposals for new work where necessary. Prepare and take responsibility for concept and preliminary...


  • United Kingdom MPCH Full time

    it's a hub of innovation in the security and technology space. As part of our team, you will be at the forefront of developing and utilizing cutting-edge products that shape the future of information security. Our environment is one where innovative ideas are welcomed and rapidly transformed into reality, supported by the latest advancements in technology....


  • United Kingdom MPCH Full time

    it's a hub of innovation in the security and technology space. As part of our team, you will be at the forefront of developing and utilizing cutting-edge products that shape the future of information security. Our environment is one where innovative ideas are welcomed and rapidly transformed into reality, supported by the latest advancements in technology....

  • IT Security Manager

    5 days ago


    United Kingdom LT Harper - Cyber Security Recruitment Full time

    Cyber Security OT Manager – Brownfield Opportunity Location – Hybrid – UK South Salary - £85k + Bonus and Benefits This is a chance to own an entire body of work as you take this CNI company on a OT cyber security journey from its current brownfield state , to achieving regulatory compliance with the governing bodies regulations for OES...


  • United Kingdom Formula Recruitment Limited Full time

    Formula are working with an exciting global entertainment company who are looking to add a dynamic and highly experienced Chief Information Security Officer to their team. As CISO you will be responsible for defining and implementing the information security strategy and framework across the organisation, ensuring the protection of sensitive data, systems,...


  • United Kingdom Formula Recruitment Full time

    Formula are working with an exciting global entertainment company who are looking to add a dynamic and highly experienced Chief Information Security Officer to their team. As CISO you will be responsible for defining and implementing the information security strategy and framework across the organisation, ensuring the protection of sensitive data, systems,...


  • United Kingdom Formula Recruitment Full time

    Formula are working with an exciting global entertainment company who are looking to add a dynamic and highly experienced Chief Information Security Officer to their team. As CISO you will be responsible for defining and implementing the information security strategy and framework across the organisation, ensuring the protection of sensitive data, systems,...


  • United Kingdom Endeavour Recruitment Solutions Full time

    Cyber Security Risk Manager/Brussels/Contract ~ Sector: IT Management ~ Job Type: Contract ~ Technologies: Cyber Security Risk Manager belgium information security RSA Archer GDPR Financial Services CIAT CISSP CISM CIPP CCSK CLOUD SERVICES Cyber Security Risk Manager/Brussels/Contract Posted Friday, 18 May 2018 Endeavour Recruitment has an excellent...


  • United Kingdom Atlas Recruitment Group Ltd Full time

    Product Security Consultant Hybrid - Brough - 2/3days hybrid split £Implementing Security Controls · Good experience of assessing and managing risk (NIST, ISO27001) · Significant experience with using security baselines, mitigations and controls · Experience of MOD Policies and regulations · Experience with security artefacts such as risk...


  • United Kingdom enteles Search Full time

    Job Description This position is tailored for individuals at the early to mid-level of their career, ideally with 2 to 3 years of experience in security risk consulting. Candidates beyond this experience level may not be suitable for the role. As a Risk Consultant your primary responsibility will involve assisting in the execution of risk management...


  • United Kingdom enteles Search Full time

    Job Description This position is tailored for individuals at the early to mid-level of their career, ideally with 2 to 3 years of experience in security risk consulting. Candidates beyond this experience level may not be suitable for the role. As a Risk Consultant your primary responsibility will involve assisting in the execution of risk management...


  • United Kingdom Oak HCFT Full time

    About MPCH MPCH is not just another workplace; it's a hub of innovation in the security and technology space. As part of our team, you will be at the forefront of developing and utilizing cutting-edge products that shape the future of information security. Our environment is one where innovative ideas are welcomed and rapidly transformed into...


  • United Kingdom MPCH Full time

    About MPCHMPCH is not just another workplace; it's a hub of innovation in the security and technology space. As part of our team, you will be at the forefront of developing and utilizing cutting-edge products that shape the future of information security. Our environment is one where innovative ideas are welcomed and rapidly transformed into reality,...


  • United Kingdom MPCH Full time

    About MPCHMPCH is not just another workplace; it's a hub of innovation in the security and technology space. As part of our team, you will be at the forefront of developing and utilizing cutting-edge products that shape the future of information security. Our environment is one where innovative ideas are welcomed and rapidly transformed into reality,...


  • United Kingdom MPCH Full time

    About MPCH MPCH is not just another workplace; it's a hub of innovation in the security and technology space. As part of our team, you will be at the forefront of developing and utilizing cutting-edge products that shape the future of information security. Our environment is one where innovative ideas are welcomed and rapidly transformed into reality,...