Information Systems and Security Compliance Manager

Drax
Northampton, UK
1 day ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£57,478.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems PCI Data Security Standards

Job description

We’re looking for an experienced Information Systems & Security Compliance Manager to play a critical role in ensuring Drax meets its technology and security compliance obligations across a complex and evolving regulatory landscape.

Working within our Information Security, Governance, Risk & Compliance function, you’ll help shape a robust compliance culture, influence senior stakeholders, and support the delivery of our security strategy.

This role represents a great opportunity to be part of a collaborative and evolving security function!

Who we are: We’re not just talking about making a difference, we’re making it happen. We generate dispatchable, renewable power and create stable energy in an uncertain world. Building on our proud heritage, we have ambition to become the global leader in sustainable biomass and carbon removals.

You’ll be joining our teams of practical doers, future thinkers and business champions. We’re enabling a zero carbon, lower cost energy future for all, and working hard to decarbonise the planet for generations to come., Reporting to the Head of InfoSec Governance, Risk and Compliance, you’ll act as the central point of contact for Information Systems and Security (IS&S) compliance across the Group., * Lead IS&S compliance governance activities, reviews and stakeholder engagement.

  • Oversee IS&S compliance against regulatory and contractual obligations including Smart Energy Code (SEC), PCI DSS, ISO27001 and NIS Regulations.
  • Develop IS&S compliance reporting, schedules and improvement plans.
  • Support audits, assurance activities and security input into projects.

Requirements

To be successful in this role you’ll ideally have…

  • Proven experience in information security compliance, governance and risk management.
  • An understanding of regulatory regulations such as the Smart Energy Code (SEC), PCI DSS, 27001 and NIS Regulation.
  • Experience engaging with auditors, regulators and business stakeholders
  • Ability to translate complex security compliance requirements for both technical and non-technical audiences.
  • Ideally be certified in either CISSP, CISA, CISM or equivalent.

Benefits & conditions

As you help us to shape the future, we’ve shaped our rewards and benefits to help you thrive and support your lifestyle. If successful in this role, you’ll get:

  • A discretionary bonus depending on company performance
  • Private Healthcare
  • SAYE (Sharesave): discretionary scheme from time to time
  • Personal accident cover
  • Group personal pension plan where we’ll contribute up to 10%
  • Holiday - 25 days plus bank holidays
  • Reimbursement of the cost of your annual membership of one relevant and appropriate professional body

We’re committed to making a tangible impact on the climate challenge we all face. Drax is where your individual purpose can work alongside your career drive. We work as part of a team that shares a passion for doing what’s right for the future. With Drax you can shape your career and a future for generations to come.

Together, we make it happen.

At Drax, we’re committed to fostering an environment where everyone feels valued and respected, regardless of their role. To make this a reality, we actively work to better represent the communities we operate in, foster inclusion, and establish fair processes. Through these actions, we build the trust needed for all colleagues at Drax to contribute their perspectives and talents, no matter their background.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson · World Congress 2021

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

Videos

See all

Related articles

See all