Red Snapper Recruitment are recruiting for a Security Improvement Programme Lead (Principal) for a UK regulatory body. The Guidance and Monitoring (G&M) team sits within the Cyber and Emerging Technologies directorate. The goal of the directorate is to protect energy consumers by working across government, regulators and industry to shape cyber and security resilience for the energy sector.
This role will lead a couple of critical security improvement projects, specifically:
- Leading CAF v4 transition project across the Downstream Gas and Electricity Sector (including any related CAF DGE profile and guidance updates as sub-projects)
- Developing a resilient and scalable new onboarding process internally, which is used to onboard newly designated OES (Operators of Essential Services) under the NIS Regulations 2018.
Location: London, Glasgow or Cardiff (1-day a week in the office).
Contract: 6 months
Salary: £750 per day (inside IR35)
Vetting: Must have existing active SC
Main Responsibilities
- Lead the CAF v4 Transition Programme across the Downstream Gas and Electricity (DGE) sector, including the planning, coordination, delivery and governance of all related activities, milestones and stakeholder engagement (both internal, with our key partner organisations, and external with industry)
- Lead and manage the development and implementation of CAF v4-related products or uplifts, including updates to the CAF DGE Profile, supporting guidance documentation, and associated regulatory communications
- Design, develop and implement a resilient, scalable onboarding process for newly designated Operators of Essential Services (OES) under the NIS Regulations 2018, ensuring consistency, efficiency and a positive stakeholder experience
- Collaborate with key external partners where relevant, including DESNZ, NCSC, NESO and regulated entities, to ensure alignment on cyber resilience priorities, regulatory expectations and security improvement initiatives
- Engage and influence internal and external stakeholders to drive successful programme delivery, build consensus, and support the adoption of security and resilience improvements across the sector
- Monitor regulatory, policy and legislative developments for any impacts to your projects, including changes relating to NIS, cyber resilience and wider critical national infrastructure regulation, ensuring programme activities remain aligned and effective
- Provide programme governance, reporting and coordination, maintaining clear records of decisions, risks, dependencies, actions and outcomes, while coordinating subject matter experts and stakeholders across multiple workstreams.
- Identify opportunities to improve sector-wide cyber resilience, working with G&M colleagues and industry partners to embed best practice and drive continuous improvement across the UK’s energy infrastructure.
Person Specification
- Experience working in a security, resilience or regulatory role within the energy sector or wider Critical National Infrastructure (CNI)
- Knowledge of both Operational Technology (OT) and Information Technology (IT) security and their application within regulated environments
- Experience of applying or assessing security frameworks such as the NCSC Cyber Assessment Framework (CAF), IEC 62443 and ISO 27001
- Working knowledge of the NIS Regulations 2018 and the UK cyber resilience regulatory landscape
- Experience leading complex change, transformation or security improvement programmes involving multiple stakeholders and competing priorities
- Experience developing operational processes, governance frameworks or onboarding models within a regulatory or assurance environment
If this role is not for you but you do know somebody who would be interested, please refer them. We have a referral bonus scheme and will pay £75, in retail vouchers of your choice, for referrals who are not already known to us.
Due to the high volume of applications received, if you do not hear from us within 7 working days, I am afraid your application has been unsuccessful.
RSR is a public safety & enterprise security recruitment specialist. We assist public safety employers find the right talent. We assist all employers when they want to source public safety and enterprise security skills and experience.
Red Snapper Recruitment is a member of the Red Snapper Group. The Red Snapper Group acts as an employment agency (permanent) and as an employment business (temporary) – a free and confidential service to candidates. The Red Snapper Recruitment Group is an equal opportunities employer.
Apply for this job