Senior Cyber Risk Manager

6 days ago


London, Greater London, United Kingdom EDF Energy Limited Full time £60,000 - £120,000 per year

About the Role

As the Senior Cyber Risk Manager here at EDF, you will be responsible for providing organisational oversight, leadership, and delivery of risk management across EDF Business Units together with producing the aggregated EDF UK holistic risk management position.

What you'll be doing

  • Identify and oversee the mitigation of cyber risks owned by the central Enterprise Information Security team – involving identifying, managing, mitigating and reporting cyber-related risks.
  • Development and management of the organisational Cyber Risk Management Framework including the related processes aligned with industry best practices and organisational capabilities.
  • Responsible for the development of risk management-related policies and ensuring alignment of the policy with regulation and wider EDF UK business policies.
  • Responsible for oversight and governance of organisational risk management, ensuring effective and comprehensive risk oversight, ensuring Risk Owners are actively managing and remediating their risks.
  • Monitoring the efficiency and effectiveness of the risk management processes across EDF UK and making recommendations for continuous improvement and incorporating emerging risks such as those related to AI systems and other similar disruptive technologies.
  • Actively communicate the cyber risk position to stakeholders, including attending senior risk forums, and provide advice to address cybersecurity risk. You will foster strong relationships with internal stakeholders, being a cyber risk advocate driving focus to ensure cyber risk considerations are integrated into all business processes.
  • Build, maintain and manage risk tooling, currently ServiceNow Integrated Risk Management to facilitate active risk management, supporting an up-to-date central risk register. Using this tool, you will be accountable for ensuring continuous review and reporting to senior leaders to ensure the cyber risks are understood and being managed.
  • Work with the Assurance team to ensure the Enterprise ISMS remains current and effective.. You will also need to ensure the cyber security controls are defined and effectively deployed to manage risk, with exceptions and control gaps being captured and reported.

You will:

  • Own the delivery of the EDF Enterprise risk position, driving risk management operational practices and embedding a proactive risk culture within both the central and business unit risk management teams.
  • Work with and challenge businesses to create and maintain appropriate risk registers.
  • Curate the aggregate risk position for the EDF UK business, covering the cyber security top risks and control statements.
  • Communicate the aggregated risk position to senior executive stakeholders.
  • Lead the Cyber Risk Management Community of Practice to provide alignment and sharing of best practice amongst EDF UK businesses
  • Stay current with emerging cyber threats, risk management techniques, and regulatory changes.

Who you are

We're looking for someone with experience in risk management delivery within a large, complex and regulated environment with the ability to evaluate risk treatment options and ensure decisions are pragmatic and aligned with strategic and business objectives. You'll also be able to establish and operationalise risk processes and generating actionable risk reporting.

Our ideal candidate will have demonstrable hands-on delivery experience in the cyber security field, with practical exposure to implementing and managing technical or procedural controls in operational environments.

You'll be confident in influencing and persuading stakeholders and have the ability to build strong working relationships built on trust and credibility.

The proven experience of working with external partners and ensuring controls are tested and improved in line with standards such as Cyber Essentials+, ISO27001, both of which cover supplier-related risk and third-party assurance.

Experience in identifying, assessing and mitigating cyber risks, with a strong grasp of CNI or enterprise level risk frameworks (e.g., ISO 27001/27005, NIST, CAF, Cyber Essentials+) is desirable as well as knowledge of security concepts and controls within both IT and OT environments.

Pay, benefits and culture

Alongside a salary negotiable depending on experience, potential to earn 10% bonus, 28 days holiday plus bank holidays and a market-leading pension scheme, your package will include a range of benefits, from the big and formal to the small and personal.

We're talking about everything from enhanced parental leave to electric vehicle leasing, health insurance to product discounts, critical illness insurance to technology vouchers, gym membership to season ticket loans.

At EDF UK, we embrace flexibility while recognising that everyone's working needs are different. Whether you're in our office spaces, on site, or working remotely, we promote an environment that supports collaboration, connection, and comfort. No matter where you are, our priority is to make sure you feel safe, valued, and celebrated.

Here, we do right by each other and everyone's welcome. We're on an action-oriented journey, championing equity, diversity, and inclusion. We'd like our future workforce to have an equal gender balance, represent a broad mix of people from minority ethnic backgrounds, LGBTQ+, those with a disability and supporting social mobility.

We're a disability confident employer and we'll do all we can to help with your application. Please let us know if you need to request reasonable adjustments.

We take pride in fostering a dynamic and inclusive environment, where the diverse backgrounds and experiences of our employees drive fresh thinking and innovation. We understand that success means different things to different people. We believe there are multiple definitions of what it means to succeed. That's why we support you to pursue a career that's unique to you. Because success is personal.

Closing date for applications:

Location: Home working

Success is personal. It's your journey, powered by us. Join us and we'll help Britain achieve Net Zero together.



  • London, Greater London, United Kingdom EDF (UK) Full time £60,000 - £120,000 per year

    About The RoleAs the Senior Cyber Risk Manager here at EDF, you will be responsible for providing organisational oversight, leadership, and delivery of risk management across EDF Business Units together with producing the aggregated EDF UK holistic risk management position.What You'll Be DoingIdentify and oversee the mitigation of cyber risks owned by the...


  • London, Greater London, United Kingdom EDF UK Full time £60,000 - £100,000 per year

    Job Description As the Senior Cyber Risk Manager here at EDF, you will be responsible for providing organisational oversight, leadership, and delivery of risk management across EDF Business Units together with producing the aggregated EDF UK holistic risk management position.What you'll be doingIdentify and oversee the mitigation of cyber risks owned by...

  • Cyber Risk Consultant

    6 hours ago


    London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time £40,000 - £55,000 per year

    Cyber Security ConsultantLocation:Hybrid -Sponsorship:Not availableSalary:£40k–£55kIf you've got around2ish years of client-facing cyber consulting experienceand you're ready to step up, learn fast, and take on more responsibility, this role is for you.We're building a next-generation cybersecurity consultancy that stands out by giving clients clear,...

  • Cyber Risk Consultant

    5 hours ago


    London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time £40,000 - £45,000 per year

    Cyber Security Consultant - Remote UKLocation:UK Remote -Sponsorship:Not availableSalary:£40k–£45kIf you've got around 1ish years of client-facing cyber consulting experienceand you're ready to step up, learn fast, and take on more responsibility, this role is for you.We're building a next-generation cybersecurity consultancy that stands out by giving...


  • London, Greater London, United Kingdom LSEG Full time £80,000 - £120,000 per year

    About us:LSEG (London Stock Exchange Group) is more than a diversified global financial markets infrastructure and data business. We are dedicated, open-access partners with a dedication to excellence in delivering the services our customers expect from us. With extensive experience, deep knowledge and worldwide presence across financial markets, we enable...


  • London, Greater London, United Kingdom Heathrow Airport Full time £60,000 - £120,000 per year

    DescriptionAs Cyber Security Manager, Risk, you'll lead Heathrow's day-to-day cyber risk management, driving a proactive, business-wide approach to identifying and managing threats. You'll shape and refine our risk policies and standards, ensure compliance through close collaboration with assurance teams, and build strong relationships with regulators to...

  • Head of Risk, Cyber

    2 days ago


    London, Greater London, United Kingdom Schroders Full time £80,000 - £120,000 per year

    Job DescriptionHead of Risk – Cyber & TechnologyWho We're Looking ForWe are looking for an experienced cyber and technology risk professional with strong technical skills combined with the ability to communicate with and influence both technical and non-technical senior management.About SchrodersWe're a global investment manager. We help institutions,...

  • Head of Risk, Cyber

    2 hours ago


    London, Greater London, United Kingdom Schroders Full time £54,000 - £110,000 per year

    Description Head of Risk – Cyber & TechnologyWho we're looking forWe are looking for an experienced cyber and technology risk professional with strong technical skills combined with the ability to communicate with and influence both technical and non-technical senior management.About SchrodersWe're a global investment manager. We help institutions,...

  • Cyber Risk Manager

    2 weeks ago


    London, Greater London, United Kingdom Convex Insurance Full time £60,000 - £120,000 per year

    Department:RiskLocation:London, UKDescriptionThe Enterprise Risk Management ('ERM') team sits within the Group Risk Management function, which is comprised of three 'pillars': Insurance Risk, Financial & Market Risk, and ERM. Convex has a strong focus to be market leaders in the use of data and technology.The primary role of the, newly created, Cyber...


  • London, Greater London, United Kingdom Serco Full time £30,000 - £70,000 per year

    Cyber Third Party Risk Management (TPRM) Senior PractitionerHybrid – Flexible Base Location with UK TravelFull Time, PermanentBand 4 / Up To £70,000 (dependent on experience)Join Serco's Growing Cyber Security FunctionThe cyber threat landscape is evolving at pace - and Serco is investing heavily to stay ahead. With increasing reliance on diverse and...