Chief Information Security Officer

Public Sector
Aberdeen, UK
7 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Security Management Cyber Threat Analysis

Job description

The role reports to the Chief Digital & Information Officer and is one of the small leadership group standing up GBE’s digital function, alongside the CDIO and the Enterprise Architect & Innovation. The postholder is the senior executive accountable for advising on, coordinating and assuring GBE’s approach to the NCSC Cyber Assessment Framework and the security of personal data under UK GDPR, and ensures GBE meets the standards expected of both a public body and the energy sector - a sector where the resilience bar is deliberately high., * Take ownership of the security decisions made during the establishment phase: review the recorded decision log, confirm or adjust the recommendations against the evidence, and carry them into delivery.

  • Establish GBE’s security operating model and minimum security requirements as the standard all delivery - internal and partner - works to, leveraging best practice and selecting which of the established ICS security foundations within DESNZ GBE carries forward.
  • Decide and implement the delivery model for detecting and responding to attacks, with accountability agreed in writing at every stage of the separation from shared services.
  • Confirm the standards GBE must meet, close the priority gaps, and stand up the assurance regime that reports through the Digital Investment Governance Committee to the Audit, Assurance and Enterprise Risk Committee.
  • Secure the establishment of GBE’s own environments - cloud, collaboration, and staff identity and access - as they stand up, so that new services launch on secure foundations.
  • Establish incident response for real: plans, roles, on-call arrangements and exercises that prove GBE can handle an incident, not just describe one.
  • Baseline GBE’s security maturity, agree the target state and publish a prioritised security improvement roadmap with clear ownership and measures of progress.
  • Build security requirements into GBE’s procurements and strategic partner framework, and assure the first major deliveries against them.
  • Build the case and the plan for GBE’s permanent security function, growing the capability in step with the estate it protects.

Requirements

  • Hands on: willing to both govern and personally deliver key parts of GBE’s security capability.
  • A senior security leader - CISO, deputy CISO or head of security - with a track record in complex, fast-moving organisations, including standing up or substantially rebuilding a security function.
  • Ownership of security strategy, risk and assurance at executive level, including presenting risk clearly and honestly to boards and audit committees.
  • Operational depth: accountability for detection, response and incident management, including choosing and directing the right delivery model - in-house, managed service or hybrid.
  • Depth in security standards and compliance - the NCSC Cyber Assessment Framework, government security standards or comparable regulated regimes - and a record of turning them into practical, proportionate controls.
  • Desire to keep abreast of the changing landscape of the security and regulatory environment GBE will be exposed to, and the changing nature of GBE’s business.
  • Demonstrable expertise in strategic cyber security planning, cyber security governance, cyber risk management, security architecture and cyber incident management.
  • Experience securing major technology transitions: cloud adoption, separations from shared or outsourced services, and programmes delivered through multiple partners.
  • Accountability for the security of personal data under UK GDPR, including breach response.
  • The communication skills and credibility to make security clear and compelling to executives, boards and non-specialists.
  • Comfort operating where structures, processes and ways of working are still being established, with the pragmatism to make sound decisions at pace with imperfect information., * Experience in the energy, utilities or critical national infrastructure sectors, including an appreciation of operational technology and the resilience expected of energy systems.
  • Experience in government, arm’s-length bodies or other high-assurance settings, including working with the NCSC.
  • Experience exiting shared or outsourced services and standing up independently owned security operations.
  • Recognised security qualifications (such as CISSP or CISM), or an equivalent demonstrable record.

Personal Qualities:

  • Takes ownership, shows confidence in decision-making, and is willing to challenge constructively
  • Focuses on delivering meaningful outcomes and making a positive, lasting impact
  • Works collaboratively, valuing different perspectives and building inclusive relationships
  • Proactive and adaptable, with a curiosity to explore new ideas and improve ways of working
  • Resilient and resourceful in a fast-paced environment

Benefits & conditions

  • Competitive base salary
  • Performance-related bonus scheme
  • Excellent pension scheme
  • 4x salary life assurance
  • Group income protection
  • 38 days annual leave
  • Flexible working arrangements
  • Ongoing professional development and training
  • Supportive, inclusive working environment

About the company

Join Great British Energy and be part of powering the UK’s Clean Energy Future.

At GBE, we’re not just building an energy company - we’re shaping the future of the UK’s energy landscape.

Our mission is clear:

  • Drive clean energy deployment across the UK as a strategic developer, investor, and owner of renewable projects
  • Deliver benefits for communities and taxpayers, ensuring the clean energy transition creates jobs, boosts local economies, and increases public ownership
  • We focus on innovation, sustainability, and impact, working on projects that matter - from large-scale national renewable investments to empowering local and community energy initiatives.

Joining GBE means

  • Purpose-driven work Be part of a national effort to accelerate the clean energy transition
  • Career growth Opportunities to develop expertise in cutting-edge energy technologies and strategic investment
  • Collaboration and flexibility Work with passionate professionals in a dynamic, forward-thinking environment

If you want to make a real difference and help power a greener, fairer future for the UK, GBE is the place for you.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:29 min

Forecasting organizational cybersecurity risks through public employee reviews

4:25 min

The growing power and security responsibility of developers

Tino Sokic · World Congress 2023

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all