24 Sep
|
EDF Energy
|
Ipswich
24 Sep
EDF Energy
Ipswich
Job Description
Select how often (in days) to receive an alert:
n
The Sizewell C Jobs Service supports local people into exciting, long-term careers across our Project.#SZCJobs
n
Cyber Controls Manager
n Sizewell C
n
Security Clearance: Active Security Clearance is required and must already be in place
n
Location: London, Leiston or Ipswich, with hybrid working and a minimum of 2 days per week on-site. Travel to other Sizewell C locations may be required.
n
Contract: Permanent, full-time
n
Salary: £82,200 - £84,000 depending on experience, plus benefits
n
n
- Annual Leave: 28 days per annum, increasing to 30 days after 5 years of service, plus bank holidays
n
- Bonus: 5% annual bonus
n
- Pension Contributions: Defined Contribution Pension Scheme with up to 7.5% employee contribution 15% employer contribution
n
- Life Assurance: Up to 8 x salary
n
n
Closing Date: 30th September 2026
n
About the Role:
n
The Cyber Controls Manager plays a pivotal role in ensuring Sizewell C's cyber security controls are effective, auditable and aligned to organisational, regulatory and business requirements.
n
Key Responsibilities:
n
Cyber Controls Framework
n
n
- Own and maintain the organisation's cyber security controls library, ensuring it remains comprehensive, structured and audit ready.
n
- Define and maintain the controls taxonomy, categorising controls by domain and control type.
n
- Ensure controls are documented consistently, including ownership, implementation status, associated risks, supporting requirements and effectiveness evidence.
n
- Maintain alignment between controls, regulatory obligations, contractual requirements and recognised cyber security frameworks.
n
- Establish robust governance and change management processes to support the continual improvement of the control's framework.
n
- Work closely with the Cyber Risk Manager to ensure controls are identified, assessed and mapped against new and existing cyber risks.
n
- Maintain end-to-end traceability between cyber risks, regulatory requirements and implemented controls.
n
- Define control objectives and collaborate with technical teams to develop implementation guidance, testing criteria and evidence requirements.
n
- Support the continuous enhancement of the control environment in response to emerging threats, incidents, audits and lessons learned.
n
- Provide leadership and direction to the Cyber Controls Specialist, ensuring the effective delivery of cyber controls management activities.
n
n
Controls Monitoring & Assurance
n
n
- Support compliance and regulatory activities by providing control evidence and demonstrating control effectiveness.
n
- Collaborate with assurance teams to align control monitoring activities with assurance programmes and remediation plans.
n
- Monitor control performance, identifying weaknesses, gaps or degraded controls and recommending corrective action.
n
- Evaluate control effectiveness against current and emerging cyber threats.
n
- Track the outcomes of control testing activities, including penetration testing, vulnerability assessments and security exercises, ensuring identified actions are progressed to completion.
n
n
Governance, Reporting & Stakeholder Engagement
n
n
- Attend governance forums and provide updates on control effectiveness, control coverage, remediation activities and emerging risks.
n
- Advise stakeholders on appropriate control selection and implementation in support of risk treatment activities.
n
- Prepare reports and dashboards for the CISO and senior leadership, communicating technical information in a clear and accessible manner.
n
- Maintain governance records, testing evidence and supporting documentation to an auditable standard.
n
- Work with programme and project teams to ensure security controls are embedded throughout the system lifecycle and considered within governance processes from the outset.
n
n
Knowledge & Skills
n
n
- Strong understanding of cyber security control frameworks, including ISO 27001, and the principles of control design, implementation, assessment and governance.
n
- Ability to develop and maintain risk-to-control and requirement-to-control mappings, providing clear traceability across the cyber security landscape.
n
- Knowledge of preventive, detective, corrective and compensating controls, with the ability to assess both design adequacy and operational effectiveness.
n
- Experience presenting cyber security controls and risk information to senior stakeholders and governance forums.
n
- Strong leadership, communication and stakeholder management skills, with the ability to influence technical teams, control owners and business leaders.
n
- Ability to operate effectively within a complex and highly regulated environment.
n
- Familiarity with GRC platforms and integrated risk and controls management tools.
n
- Understanding of penetration testing, vulnerability management and red team activities, and how outputs support control improvement.
n
- Knowledge of security control automation and continuous control monitoring approaches.
n
n
Qualifications & Experience
n
n
- Degree qualified, or equivalent, in Cyber Security, Information Security, Computer Science or a related discipline.
n
- Minimum of five years' experience within cyber security, including at least three years with direct responsibility for cyber security controls, controls frameworks or assurance programmes.
n
- Proven track record assessing the effectiveness of cyber security controls and managing remediation activities.
n
- Contribution to governance forums where control performance, remediation progress and risk treatment activities are reviewed.
n
- Experience supporting internal audits, assurance activities or compliance reviews.
n
- Preparation of control evidence and supporting documentation for audits, certifications or regulatory inspections.
n
- Experience working within, or closely alongside, Critical National Infrastructure sectors such as nuclear, defence, energy, transport, water or telecommunications.
n
- Professional certification such as CISSP, CISM, CRISC or equivalent.
n
- Experience designing or significantly enhancing enterprise cyber security control frameworks aligned to ISO 27001 or equivalent standards.
n
- Previous people management, team leadership or functional leadership experience.
n
- Experience working with regulators, auditors or external assurance bodies.
n
n
Why Join us?
n
n
- Be part of one of the most important low-carbon energy projects in the UK.
n
- Work in a mission-driven setting that values innovation, integrity, and long-term sustainability.
n
- Competitive salary, comprehensive benefits, and opportunities for career development.
n
- Flexible and hybrid working options.
n
n
For this role you must have evidence of right to work in the UK. As a project, we do not discriminate on the grounds of age, gender, race, colour, religion, disability or sexual orientation, and we welcome applications from all sections of the community.
n
Why Join Us?
n
For more than 60 years, nuclear power stations in the UK have been quietly keeping Britain fuelled with massive amounts of home-grown energy.
n
Our teams up and down the country are proudly continuing to serve the nation – but they also have an eye on the future.
n
EDF is leading the UK's nuclear renaissance with the construction of a new nuclear power station at Hinkley Point C and plans for a new power station at Sizewell C in Suffolk.
n
Nuclear power is the most reliable, low-carbon energy source currently available to the UK. EDF is playing a key role in the development of nuclear sites, while Hinkley Point C will provide low-carbon electricity to meet 7% of the UK demand. The project is already making a positive impact on the local and national economy as well as boosting skills and education.
n
We're not just building new nuclear power stations. We're developing careers, upskilling generations and creating thousands of employment and apprenticeship opportunities across a variety of skills areas.
n
It takes a special kind of person to work in the nuclear energy industry and although we have thousands of them there's always a need for more.
n
Our industry has a mind-boggling range of opportunities and more jobs, and in more places, than you might think. But it's also an industry which is changing.
n
We're a responsible business and proud to be Britain's biggest generator of zero carbon electricity. With size, age and experience, we believe we can do even more.
📌 Cyber Controls Manager (Sizewell C) (Ipswich)
🏢 EDF Energy
📍 Ipswich