Key Accountabilities
Ensure that ESO fulfils all applicable legal rules and regulations relating to cyber, personnel and physical security.
Remain up to date on regulations and legislations relevant to ESO and ensure policies are updated accordingly.
Develop and implement security policies, standards and procedures to ensure compliance with applicable legal and regulatory requirements.
Collaborate with cross-functional teams to identify, assess and mitigate security compliance risks. Ensure that relevant evidence is available and kept up to date.
Communicate compliance requirements with the business and external stakeholders, be first port of call for Security Compliance questions.
Provide training content to support training and awareness of compliance requirements across ESO
Perform security assessments and compliance testing across complex IT systems to determine compliance status and maturity.
Prepare for, facilitate and co-ordinate all Security compliance inspections and audits, directing 3rd party support where required.
Record regulatory/compliance breaches or incidents, ensuring appropriate records are maintained and lessons learned with corrective actions implemented to prevent future problems.
Provide improvement planning for relevant compliance requirements and implement and monitor processes to support those requirements.
Manage and coordinate the completion of all regulatory submissions on behalf of the Security function.
Determine compliance metrics and establish a system for tracking them, escalating major issues and/or highlighting where trends exist.
Provide periodic reports to the Head of GRC and CISO on compliance activities, status and outputs.
Contribute to the continual improvement of ESO’s Control Framework to meet evolving needs and industry standards.
About You
Excellent understanding of the Network and Information Systems Regulations (NISR).
Experience working with frameworks/standards such as ISO27001, NIST 800-53, and NCSC CAF.
CISA, CISM, CISSP or other relevant security certifications.
Numerous years of relevant work experience in cyber security, risk advisory, or internal audit.
Experience with GDPR, and other relevant regulations for energy organisations in the UK and Europe.
Excellent written and verbal communication and presentation skills.
Ability to identify opportunities for business efficiency, develop and implement internal systems and controls.
Excellent problem-solving skills, including the ability to resolve complex issues and devise actionable solutions.
Ability to compile, analyse and interpret management information and data to facilitate decision making.
An inclusive approach that creates belonging, builds trust and promotes innovation.