Cyber Regulation Lead

Sedang Trending 2 minggu yang lalu

As Great Britain's regulator for the vigor industry, Ofgem exists to guarantee a safe, unafraid and sustainable vigor proviso to British households and businesses.

We are seeking a fig of Cyber Regulation Lead with acquisition successful cyber information and the vigor assemblage to play a pivotal relation successful protecting vigor consumers. You volition run wrong the Cyber Directorate and profession.

You volition person important acquisition successful cyber information preferably relating to Critical National Infrastructure. As an experienced leader, you'll person extended cognition of NIS regulations and NCSC's Cyber Assessment Framework, clasp fantastic connection and enactment skills and beryllium capable to execute and support SC clearance. Ideal candidates volition preferably person qualifications, obtained done nonrecreational improvement oregon further acquisition specified arsenic CISSP, CISA, oregon CISM.

Due to our team's accelerated growth, we're looking to capable assorted roles nether this position. These roles inhabit the aforesaid halfway responsibilities, but determination are variations wrong the wider responsibilities attached to the roles. 

Core Responsibilities

  • Leading activities crossed the Cyber Regulation Team.
  • Working collaboratively with teams crossed the organisation to guarantee the transportation of our responsibilities align with the Regulator's Code.
  • Proven grounds of enactment skills and guarantee benefits for vigor consumers' needs.

Under a Cyber Assurance Role, you'll pb manufacture enactment for cyber resilience to support consumers. You'll behaviour audits with meticulous precision to enactment the ongoing process of improvements and attack for the assurance programme.

Within a Cyber Policy Role, you'll make Ofgem's cyber information policies successful collaboration with The Department for Energy Security and Net Zero, pb argumentation implementation, beryllium astatine the forefront of scanning for aboriginal challenges and enactment assemblage probe and innovation.

In a Cyber Investment-based relation you volition guarantee that user wealth is spent with volition and volition clasp organisations accountable for their plans. You volition profoundly analyse manufacture investments and separate erstwhile concern is appropriate.

Positioned wrong the Cyber Guidance and Motioning relation you volition show the vigor sector's cyber information approach, physique beardown relationships with regulators and beryllium an outstanding squad player, providing constructive feedback to the manufacture connected their plans to alteration cross-sector collaboration.

Ofgem has a civilization of inclusion that encourages, supports and celebrates the divers voices and experiences of our colleagues. As an inclusive workplace, our employees are comfy bringing their authentic selves to work.

#LIRemote

Job description

Ofgem works connected behalf of vigor consumers to guarantee that each household and concern successful the UK tin trust connected a safe, affordable, and environmentally sustainable vigor supply. We are playing a captious portion successful accelerating the modulation to Net Zero and a c neutral vigor strategy - a extremity that everyone wants to achieve. Whatever your role, you'll beryllium playing your portion successful creating caller vigor solutions that are large for customers, and large for the environment. 

Ofgem has a civilization of inclusion that encourages, supports, and celebrates the divers voices and experiences of our colleagues. It fuels our innovation and helps guarantee we tin champion correspond the consumers and the communities we serve. Everyone is invited - arsenic an inclusive workplace, our employees are comfy bringing their authentic selves to work.  

This relation volition beryllium portion of Cyber Security Directorate astatine Ofgem which, acts arsenic Joint Competent Authority ("CA") for The Security of Network & Information Systems Regulations ("NIS") and the Authority for Smart Energy Code ("SEC"). The squad is focused connected policy, compliance and enforcement, arsenic good arsenic assisting operators successful improving the cyber resilience posture successful the Downstream Gas and Electricity assemblage ("DGE") successful bid to support consumer's vigor supply. 

Purpose 

  • Protect vigor consumers by moving with the manufacture and different cardinal stakeholders to thrust improvements successful cyber and information resilience crossed the vigor sector.  

Person specification

Key Responsibilities, Outputs and Deliverables  

  • There are a fig of roles that we are seeking to capable done this recruitment process. There are immoderate halfway responsibilities that are applicable to each and further responsibilities that volition alteration depending connected the relation the applicant is assigned to. We are passionate astir upskilling and offering opportunities to our teams for nonrecreational and idiosyncratic improvement crossed the assemblage of Cyber and tin beryllium flexibly deployed crossed antithetic teams and projects. Personal maturation is cardinal astatine Ofgem, and being self-motivated and driven successful your relation tin unfastened opportunities for you. We volition question input from applicants astatine interrogation signifier astir their preferences for their archetypal deployment.  

Core Responsibilities:  

  • Work collaboratively with colleagues from crossed Ofgem, and externally, to guarantee the transportation of our responsibilities successful alignment with the Regulators Code. You should expect to instrumentality a starring relation successful aggregate activities crossed the Cyber Regulation team.  
  • Communicate effectively, some verbally and successful writing, with a scope of stakeholders, including colleagues, those you regulate, and different cardinal partners.  
  • Demonstrate enactment and enactment your acquisition to bully usage for the payment of vigor consumers.  
  • Continue your nonrecreational improvement whilst astatine Ofgem to alteration you to turn and present more. 

Assurance 

  • Protect consumers by playing a starring relation successful straight supporting manufacture summation their cyber resilience. Support the transportation of cyber assurance activities passim their afloat lifecycle. Ensure that manufacture non-compliance with authorities is resolved done existing processes. Support the ongoing process improvements and attack for the assurance programme. 

 Guidance and Monitoring 

  • Protect consumers by guiding and monitoring the vigor sector's cyber information approach. Build beardown relationships with those we regulate. Work with others successful the squad to supply constructive feedback to manufacture connected their plans and activities. Identify systemic hazard crossed the vigor assemblage and alteration cross-sector collaboration and cognition sharing to trim risk. Create and support high-quality written guidance for industry.  Monitor the vigor sectors compliance against existent regulatory expectations. 

Cyber Policy 

  • Protect consumers by shaping the authorities and manufacture attack to expanding cyber resilience successful the vigor sector. Develop Ofgem cyber information policy, strategy and thinking, successful concern with the Department for Energy Security and Net Zero. Lead connected aspects of the implementation of related policies. Carrying retired Horizon Scanning activities to guarantee that we are reasoning up to aboriginal challenges and opportunities. Support Research and Innovation activities crossed the sector. 

Cyber Investment Role 

  • Protect consumers by ensuring that eligible vigor assemblage companies are investing appropriately successful their cyber security. Ensure that user wealth is spent wisely and clasp organisations to relationship for their transportation plans. Analyse manufacture concern requests. Work intimately with manufacture to guarantee that concern is appropriate. Challenge wherever required. Ensure ongoing walk is in-line with agreed plans. Support the ongoing process improvements and approach, including for the RIIO3 programme. 

Essential Criteria

  • Significant acquisition of moving successful Cyber Security, preferably relating to Critical National Infrastructure. Knowledge of NIS Regulations and NCSC's Cyber Assessment Framework. (Lead criteria) 
  • Additional acquisition applicable to astatine slightest 1 of the 4 roles identified: Assurance / Policy / Investment / Guidance and Monitoring.  
  • Strong connection skills and affectional intelligence. Leadership experience.  
  • Able to execute and support SC clearance. 
Atas