Information Senior Security Specialist; Cyber Security Lead
Job in
London, Greater London, W1B, England, UK
Listed on 2026-08-25
Listing for:
Mace group
Full Time
position Listed on 2026-08-25
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below
Mace combines construction expertise with consultancy to unlock potential in every person or project and redefine the boundaries of ambition. Our values shape the way we consult and define the people we want to join us on our journey.
Are you looking for a career which is rewarding, at the cutting edge of project development and where you can really make a difference? Come and join our expanding Sizewell C (SZC) team and work on one of the most exciting and largest mega projects in the UK, whilst being at the forefront of the UK’s climate change agenda and energy policy.
Sizewell C (SZC) will be a 3.2-gigawatt power station generating low-carbon electricity for around 6 million homes, playing a key role in our energy future, supplying reliable, clean electricity for at least 60 years.
The project:
The Sizewell C (SZC) cyber security lead operates within the SZC construction and nuclear security business landscape and is responsible for assuring the deployed Cyber infrastructure as part of the cyber security and information environment and future developments to the environment and appropriate governance. This is position will focus on the deployed and planned cyber estate including end points both owned and non-owned, physical and virtual together with access to them.
This includes end user devices such as laptops, mobile devices, virtual servers, printers and room meeting systems. The position will drive development of 2nd line of assurance approach, reporting together with effective mapping to cyber security frameworks and standards in this field. The consequence of non-compliance, compromise or vulnerability or incompatible controls with long lead time deliveries can amount to many millions of pounds sanctions or later remedial costs, so the foundations set by this team are critical to the business.
You’ll be responsible for:
Provide assurance to the SZC BISO, and ultimately to the SZC Board, on the efficacy of SZC’s cyber configuration and security arrangements, risks and mitigations for devices and their access controls. Intelligently replicate cyber security policies, standards, procedures and RESA governance from HPC to SZC with NS, EPRP, EIS and alliances peer review. Intelligent customer (IC) responsibility for licensee Cyber Security requirements.
Define and ensure the delivery of all assurance activities required to demonstrate compliance with all security requirements, including those specified and delivered by NS, EIS and EPRP or other third parties, that protect the confidentiality, integrity and availability of SZC information stored or processed upon devices, physical or virtual. Review and acceptance of security designs produced by EPRP and SZC suppliers.
Set the requirements and own the development and implementation of processes and procedures that deliver secure cyber operations at SZC, including to SaaS providers. Ensure that all cyber risks are captured within project risk logs and with the BISO into security risk tools, define and assure delivery of all mitigations. Provide briefings to the SZC Security team on risks. Utilising up-to-date knowledge of cyber security tools including in M365 to advise and support the project in delivering the best cyber security approach that aligns data privacy, business objectives and ensuring information security safeguards are effective through assurance activities.
Evaluate the cyber threat and vulnerability landscape, proposed refinement and develop of SZC policies and controls to reduce residual risk and attack surface. You’ll need to have:
Knowledge of cyber security and assurance of deployed controls. Established cyber security credentials. Good working knowledge of applicable international standards and information security frameworks (ISO
27001, CIS, NIST, GDPR, Cyber Essentials Plus). Aware of risk assessment methodologies including ISO
27005 and NIST. Familiar with cyber security tools such as defender for cloud, defender, purview and Intune.
Familiarity with process of vulnerability scanning and management together with penetration testing. Device deployment, management, patching, conditional access, isolation. Assurance of…
Position Requirements
10+ Years
work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×