FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Information Security GRC Lead
Good Energy. Provide information security GRC oversight, coordination and assurance across IT security, resilience and control governance .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Information Security Governance, Risk Management, and Compliance (GRC) with a strong focus on IT security controls, incident response, and vulnerability management. Proficient in interpreting standards and frameworks such as ISO27001 and PCI-DSS, translating them into actionable policies and procedures.
Highest-signal resume keywords
Information Security GovernanceRisk ManagementVulnerability ManagementIncident ResponseISO27001 Awareness
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
IT Security ControlsVulnerability ManagementIncident ResponseIT Disaster RecoveryChange GovernanceControl Evidence GatheringPenetration Testing CoordinationTechnical DocumentationRisk AssessmentControl Validation
Soft Skills
Strong Communication SkillsAttention to DetailAbility to Explain Technical MattersStakeholder EngagementClear Documentation Production
Tools & Technologies
ISO27001Cyber EssentialsNCSC CAFPCI-DSSCREST-accredited Testing
Certifications & Qualifications
ISO27001 FoundationCISMPSSCPSecurity+CISA
Industry Keywords
Regulated SectorEnergy SectorSmart Metering Security
About the role
Key responsibilities & impact- Provide information security GRC oversight, coordination and assurance across IT security, resilience and control governance
- Act as a link between IGRC and Technology Teams
- Identify security and compliance requirements and coordinate related activity
- Provide guidance and challenge to technical owners
- Evidence controls and track remediation
- Maintain oversight of IT security risks, controls, policies and standards
- Coordinate assurance over IT security controls across people, process, premises and technology
- Validate control operation, escalate gaps and track remediation
- Interpret standards and good-practice frameworks and translate requirements into practical actions
- Support security incident response, impact assessment, evidence coordination and root cause analysis
- Coordinate oversight of IT disaster recovery arrangements, testing, dependencies and remediation
- Support IT change governance and the Good Energy Change Advisory Board
- Coordinate PCI-DSS control activity, evidence gathering, testing and remediation
- Coordinate penetration testing and support vulnerability management oversight
- Develop, review and maintain technology security policies, standards and guidance
- Support employee awareness of security responsibilities
- Report to the Head of IGRC
Requirements
What you’ll need- Good understanding of information technology security, information security risk and control management
- Experience supporting, coordinating or assuring IT security controls, vulnerability management, incident response, IT disaster recovery or IT change governance
- Awareness of ISO27001, Cyber Essentials, NCSC CAF and PCI-DSS
- Strong verbal and written communication skills
- Ability to explain technical matters clearly to non-technical audiences
- Demonstrable attention to detail
- Ability to produce clear, evidence-based documentation
- Ability to interpret technical workflows, risks and controls and translate them into practical procedures, policies, assurance activity and clear actions
- Confidence working with technology, governance and business stakeholders to agree actions and track remediation
- Desirable: experience in a regulated sector, ideally energy
- Desirable: exposure to Smart Metering security obligations, governance or assurance requirements
- Desirable: experience coordinating CREST-accredited penetration testing
- Desirable: ISO27001 Foundation or Implementer, CISMP, SSCP, Security+, CISA or equivalent experience
- Desirable: working knowledge of data protection requirements intersecting with technology security controls
- Ability to work full-time, 37.5 hours per week, Monday to Friday
- Ability to attend the Chippenham office once a week
Benefits
Comp & perks- £500 annual work from home allowance, paid monthly
- £500 annual travel allowance, paid monthly
- £500 annual development allowance
- 15% annual bonus
- 25 days annual leave
- Day off for your birthday
- Additional leave for long service
- Bank holidays
- Option to buy additional leave
- Ethical pension with Aviva
- Employer-matched pension contributions up to 7.5% of base salary
- Hybrid working and flexible working options
- Fully accessible office