Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Good Energy

Information Security GRC Lead

Good Energy

. Provide information security GRC oversight, coordination and assurance across IT security, resilience and control governance .

Posted 9/18/2026full-timeChippenham • United KingdomSenior💰 £50,000 - £60,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Information Security Governance, Risk Management, and Compliance (GRC) with a strong focus on IT security controls, incident response, and vulnerability management. Proficient in interpreting standards and frameworks such as ISO27001 and PCI-DSS, translating them into actionable policies and procedures.

Highest-signal resume keywords
Information Security GovernanceRisk ManagementVulnerability ManagementIncident ResponseISO27001 Awareness

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
IT Security ControlsVulnerability ManagementIncident ResponseIT Disaster RecoveryChange GovernanceControl Evidence GatheringPenetration Testing CoordinationTechnical DocumentationRisk AssessmentControl Validation
Soft Skills
Strong Communication SkillsAttention to DetailAbility to Explain Technical MattersStakeholder EngagementClear Documentation Production
Tools & Technologies
ISO27001Cyber EssentialsNCSC CAFPCI-DSSCREST-accredited Testing
Certifications & Qualifications
ISO27001 FoundationCISMPSSCPSecurity+CISA
Industry Keywords
Regulated SectorEnergy SectorSmart Metering Security

About the role

Key responsibilities & impact
  • Provide information security GRC oversight, coordination and assurance across IT security, resilience and control governance
  • Act as a link between IGRC and Technology Teams
  • Identify security and compliance requirements and coordinate related activity
  • Provide guidance and challenge to technical owners
  • Evidence controls and track remediation
  • Maintain oversight of IT security risks, controls, policies and standards
  • Coordinate assurance over IT security controls across people, process, premises and technology
  • Validate control operation, escalate gaps and track remediation
  • Interpret standards and good-practice frameworks and translate requirements into practical actions
  • Support security incident response, impact assessment, evidence coordination and root cause analysis
  • Coordinate oversight of IT disaster recovery arrangements, testing, dependencies and remediation
  • Support IT change governance and the Good Energy Change Advisory Board
  • Coordinate PCI-DSS control activity, evidence gathering, testing and remediation
  • Coordinate penetration testing and support vulnerability management oversight
  • Develop, review and maintain technology security policies, standards and guidance
  • Support employee awareness of security responsibilities
  • Report to the Head of IGRC

Requirements

What you’ll need
  • Good understanding of information technology security, information security risk and control management
  • Experience supporting, coordinating or assuring IT security controls, vulnerability management, incident response, IT disaster recovery or IT change governance
  • Awareness of ISO27001, Cyber Essentials, NCSC CAF and PCI-DSS
  • Strong verbal and written communication skills
  • Ability to explain technical matters clearly to non-technical audiences
  • Demonstrable attention to detail
  • Ability to produce clear, evidence-based documentation
  • Ability to interpret technical workflows, risks and controls and translate them into practical procedures, policies, assurance activity and clear actions
  • Confidence working with technology, governance and business stakeholders to agree actions and track remediation
  • Desirable: experience in a regulated sector, ideally energy
  • Desirable: exposure to Smart Metering security obligations, governance or assurance requirements
  • Desirable: experience coordinating CREST-accredited penetration testing
  • Desirable: ISO27001 Foundation or Implementer, CISMP, SSCP, Security+, CISA or equivalent experience
  • Desirable: working knowledge of data protection requirements intersecting with technology security controls
  • Ability to work full-time, 37.5 hours per week, Monday to Friday
  • Ability to attend the Chippenham office once a week

Benefits

Comp & perks
  • £500 annual work from home allowance, paid monthly
  • £500 annual travel allowance, paid monthly
  • £500 annual development allowance
  • 15% annual bonus
  • 25 days annual leave
  • Day off for your birthday
  • Additional leave for long service
  • Bank holidays
  • Option to buy additional leave
  • Ethical pension with Aviva
  • Employer-matched pension contributions up to 7.5% of base salary
  • Hybrid working and flexible working options
  • Fully accessible office