TL;DR
Cyber Security Manager: Leading IT security for npower Business Solutions within E.ON UK, establishing and operating a robust ISMS and embedding best practices in a BusDevSecOps culture. Focus on governance, risk management, secure architecture, compliance with UK energy sector regulations, and transitioning to a modern product and DevSecOps environment.
Location: Must be based in the United Kingdom (Nottingham or Solihull)
Company
E.ON is a privately owned international energy company operating in 15 countries, focusing on energy networks, renewable energies, and customer solutions.
What you will do
- Own cyber security, IT risk, and controls ensuring governance, risk management, and audit readiness.
- Lead threat and risk assessments to ISO 27005 and manage remediation plans.
- Develop and mature the ISMS aligned to ISO 27001, SEC, and emerging standards.
- Advise on secure architecture, fraud prevention, and governance frameworks across DevSecOps.
- Manage third-party security posture and compliance with key regulations including PCI DSS, GDPR, and Cyber Essentials.
- Champion a security culture through coaching and engagement from engineering teams to C-suite.
Requirements
- Must be based in the UK with experience in the UK energy sector regulatory landscape (SEC, REC).
- Proven track record with audits and certifications such as ISO 27001, PCI DSS, Cyber Essentials, SOC 2 Type II.
- Strong technical acumen in secure architecture and DevSecOps integration.
- Experience managing multi-supplier environments and third-party security.
- Excellent stakeholder engagement skills including C-suite interaction.
- Certifications like CISSP are essential; CISM and ISO 27001 Lead Auditor are desirable.
Culture & Benefits
- Hybrid working with flexible and family-friendly policies.
- 26 days annual leave plus bank holidays, pension, life cover, and bonus opportunities.
- Inclusive and diverse workplace recognized by multiple awards.
- Support for disabilities and inclusive growth programs.
- Industry-leading benefits and talent development opportunities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →