Regulatory Cyber Assurance Principal
Listed on 2026-09-21
-
Security
Cybersecurity
12 Month Fixed Term Contract,
Location: Glasgow, Cardiff or London
Salary/Grade: Level 3 (Grade
6)
SECURITY CLEARANCE REQUIREMENT
Applicants must hold current and active Security Check (SC) clearance at the point of application. Applications from candidates who do not currently hold SC clearance cannot be considered.
This opportunity is open exclusively to permanent and fixed-term employees currently working within UK Government and the wider Civil Service. Agency workers, contractors, consultants and other contingent labour workers are not eligible to apply.
Protect Great Britain's Critical Energy Infrastructure
At Ofgem, we work on behalf of energy consumers to ensure every household and business across Great Britain can rely on a safe, affordable and environmentally sustainable energy supply.
As Great Britain's energy system continues to evolve, cyber resilience plays a critical role in maintaining secure and reliable services. Through our responsibilities under the Network and Information Systems (NIS) Regulations, Ofgem acts as the Competent Authority for the Downstream Gas and Electricity (DGE) sector, helping ensure operational systems and networks remain resilient against cyber and related security threats.
We're looking for an experienced Regulatory Cyber Assurance Principal to join our Cyber Regulation team on a 12-month fixed-term basis. This is an opportunity to play a leading role in protecting critical national infrastructure, working directly with Operators of Essential Services (OES), government partners and industry stakeholders to strengthen cyber resilience across the energy sector.
The RoleAs Ofgem's Cyber Assurance expert, you will lead and maintain relationships across a designated portfolio of Operators of Essential Services (OES).
You will provide leadership on cyber assurance activities across the Downstream Gas and Electricity sector, assessing compliance with the NIS Regulations, making expert compliance determinations and advising on appropriate regulatory responses where concerns or breaches are identified.
Working at the intersection of cyber security, regulation and critical national infrastructure, you will conduct assurance activities including inspections, review audit, exercising and technical testing outcomes, while influencing improvements that help safeguard services relied upon by millions of consumers across Great Britain.
Key Responsibilities- Lead and maintain relationships across a designated portfolio of Operators of Essential Services (OES).
- Provide expert advice and guidance to the DGE sector on compliance with the NIS Regulations.
- Lead and support regulatory assurance and engagement activities, ensuring alignment with regulatory expectations.
- Contribute to and lead NIS inspections, including evidence reviews, on-site assessments and the production of high-quality inspection reports.
- Review and assess compliance documentation, including assurance reports, audit findings, exercising and testing outcomes, remediation plans and incident reports.
- Assess and make expert determinations on compliance with the NIS Regulations.
- Document inspection outcomes, assurance findings and regulatory decisions accurately and consistently.
- Escalate compliance concerns where appropriate and collaborate with Enforcement teams to support the application of regulatory tools and drive improvements.
- Provide expert advice regarding enforcement action where NIS Regulations have been breached.
- Lead the development and continuous improvement of cyber assurance policies, products, methodologies and regulatory approaches.
- Work collaboratively with government departments, other Competent Authorities, industry stakeholders and external assurance providers to support resilience objectives.
- Provide inclusive leadership through knowledge sharing, coaching and support across the Cyber Regulation team, contributing to Ofgem's values and culture.
- Relevant professional qualification in cyber security, such as: CISSP, CISA, CISM, ISO 27001 Lead Auditor, GICSP, ISA/IEC 62443 Cybersecurity Expert, or a related degree. Equivalent experience in a cyber regulatory environment will also be considered.
LEAD CRITERIA - Expert in understanding cyber risk assessments and methodologies in relation to OT and IT of Critical National Infrastructure environments, and the application of appropriate and proportionate controls across people, process, and technology to mitigate risk.
LEAD CRITERIA - Proven experience of inspecting, auditing, or testing within…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).