Cyber Controls Specialist (Sizewell C)
The Sizewell C Jobs Service supports local people into exciting, long-term careers across our Project.#SZCJobs
Cyber Controls Specialist
Sizewell C
Security Clearance: Active Security Clearance is required and must already be in place
Location: London, Leiston or Ipswich, with hybrid working and a minimum of 2 days per week on-site. Travel to other Sizewell C locations may be required.
Contract: Permanent, full-time
Salary: £66,866 - £68,000 depending on experience, plus benefits
Benefits include:
Annual Leave: 28 days per annum, increasing to 30 days after 5 years of service, plus bank holidays
Bonus: 5% annual bonus
Pension Contributions: Defined Contribution Pension Scheme with up to 7.5% employee contribution 15% employer contribution
Life Assurance: Up to 8 x salary
Closing Date: 30th September 2026
About the Role:
The Cyber Controls Specialist plays an important role in maintaining and improving Sizewell C's cyber security controls environment.
Reporting to the Cyber Controls Manager, you will be responsible for the day-to-day management of the cyber security controls library, ensuring controls are accurately documented, supported by appropriate evidence and aligned to organisational risks and regulatory requirements. Working closely with cyber security, digital and risk management teams, you will help ensure controls remain effective, auditable and fit for purpose.
This is an excellent opportunity for a cyber security professional with experience in controls governance, risk management or security assurance to contribute to the protection of critical national infrastructure.
Key Responsibilities:
Controls Library Management
Maintain the cyber security controls library, ensuring records remain accurate, complete and up to date.
Process additions, amendments and retirements of controls through established governance and change management processes.
Conduct regular reviews of controls documentation, identifying gaps, inconsistencies, duplicate records or missing evidence.
Support the ongoing development and maintenance of the control’s taxonomy, ensuring controls are correctly classified and aligned to organisational standards.
Maintain clear audit trails and documentation standards across all control records.
Risk & Controls Integration
Maintain the relationship between the cyber risk register and the cyber controls library, ensuring mappings remain accurate and current.
Support the identification of gaps in control coverage and work with stakeholders to address discrepancies between risk treatments and implemented controls.
Assist in the evaluation of risk treatment options and provide input into risk-based decision-making activities.
Support the assessment of control effectiveness and identify opportunities for improvement.
Contribute to the enhancement of processes, governance arrangements and working practices.
Controls Monitoring & Assurance
Support ongoing monitoring activities by gathering evidence of control operation and coordinating testing activities with control owners.
Assist in the preparation of evidence packs, audit materials and supporting documentation for regulatory inspections, compliance reviews and assurance activities.
Monitor remediation activities and highlight overdue actions for escalation.
Track outcomes from control testing, audits and reviews, ensuring findings are appropriately recorded and addressed.
Keep up to date with emerging cyber threats, regulatory developments and industry good practice, assessing their potential impact on existing controls.
Governance & Stakeholder Engagement
Attend governance forums and provide accurate updates on control status, remediation activities and risk-related controls.
Prepare reports, dashboards and status updates for cyber security governance activities.
Record and track actions arising from governance meetings through to completion.
Build effective relationships with control owners, risk specialists and technical teams to ensure controls information remains accurate and aligned.
Support the Cyber Controls Manager in maintaining an effective and auditable controls framework.
Knowledge & Skills:
Good understanding of cyber security controls and the principles of control design, implementation and governance.
Working knowledge of recognised cyber security frameworks such as ISO 27001.
Understanding of the relationship between cyber risks, risk treatments and security controls.
Strong attention to detail, with the ability to maintain structured documentation to a consistent and auditable standard.
Good written and verbal communication skills, with the ability to prepare reports and contribute effectively to governance discussions.
Understanding of audit requirements and evidence management practices.
Collaborative approach with the ability to engage effectively with technical teams, control owners and stakeholders across the business.
Desirable
Familiarity with Governance, Risk and Compliance (GRC) tools or risk and controls management platforms.
Understanding of cloud security concepts within Microsoft Azure and Microsoft 365 environments.
Knowledge of cyber security governance, assurance and compliance activities within regulated environments.
Qualifications & Experience:
Degree qualified, or equivalent, in Cyber Security, Information Security, Information Technology, Computer Science or a related discipline.
Minimum of three years' experience within cyber security, information security, controls governance or risk management.
Experience contributing to a cyber security controls framework, controls library or equivalent governance structure.
Working within formal risk management processes and supporting risk register activities.
Collection, maintenance and organisation of evidence used to demonstrate control effectiveness.
Participation in governance, assurance or compliance activities.
Production of reports, status updates and management information for technical or non-technical audiences.
Recognised certification such as CompTIA Security+, SSCP, ISO 27001 Foundation, or progress towards CISSP, CISM, CISA or CRISC.
Desirable
Experience within the nuclear sector or another highly regulated Critical National Infrastructure environment, such as defence, energy, transport or water.
Supporting governance committees, assurance reviews or regulatory activities in a technical or advisory capacity.
Why Join us?
Be part of one of the most important low-carbon energy projects in the UK.
Work in a mission-driven environment that values innovation, integrity, and long-term sustainability.
Competitive salary, comprehensive benefits, and opportunities for career development.
Flexible and hybrid working options.
For this role you must have evidence of right to work in the UK. As a project, we do not discriminate on the grounds of age, gender, race, colour, religion, disability or sexual orientation, and we welcome applications from all sections of the community.
The Sizewell C Jobs Service supports local people into exciting, long-term careers across our Project.#SZCJobs
Cyber Controls Specialist
Sizewell C
Security Clearance: Active Security Clearance is required and must already be in place
Location: London, Leiston or Ipswich, with hybrid working and a minimum of 2 days per week on-site. Travel to other Sizewell C locations may be required.
Contract: Permanent, full-time
Salary: £66,866 - £68,000 depending on experience, plus benefits
Benefits include:
Annual Leave: 28 days per annum, increasing to 30 days after 5 years of service, plus bank holidays
Bonus: 5% annual bonus
Pension Contributions: Defined Contribution Pension Scheme with up to 7.5% employee contribution 15% employer contribution
Life Assurance: Up to 8 x salary
Closing Date: 30th September 2026
About the Role:
The Cyber Controls Specialist plays an important role in maintaining and improving Sizewell C's cyber security controls environment.
Reporting to the Cyber Controls Manager, you will be responsible for the day-to-day management of the cyber security controls library, ensuring controls are accurately documented, supported by appropriate evidence and aligned to organisational risks and regulatory requirements. Working closely with cyber security, digital and risk management teams, you will help ensure controls remain effective, auditable and fit for purpose.
This is an excellent opportunity for a cyber security professional with experience in controls governance, risk management or security assurance to contribute to the protection of critical national infrastructure.
Key Responsibilities:
Controls Library Management
Maintain the cyber security controls library, ensuring records remain accurate, complete and up to date.
Process additions, amendments and retirements of controls through established governance and change management processes.
Conduct regular reviews of controls documentation, identifying gaps, inconsistencies, duplicate records or missing evidence.
Support the ongoing development and maintenance of the control’s taxonomy, ensuring controls are correctly classified and aligned to organisational standards.
Maintain clear audit trails and documentation standards across all control records.
Risk & Controls Integration
Maintain the relationship between the cyber risk register and the cyber controls library, ensuring mappings remain accurate and current.
Support the identification of gaps in control coverage and work with stakeholders to address discrepancies between risk treatments and implemented controls.
Assist in the evaluation of risk treatment options and provide input into risk-based decision-making activities.
Support the assessment of control effectiveness and identify opportunities for improvement.
Contribute to the enhancement of processes, governance arrangements and working practices.
Controls Monitoring & Assurance
Support ongoing monitoring activities by gathering evidence of control operation and coordinating testing activities with control owners.
Assist in the preparation of evidence packs, audit materials and supporting documentation for regulatory inspections, compliance reviews and assurance activities.
Monitor remediation activities and highlight overdue actions for escalation.
Track outcomes from control testing, audits and reviews, ensuring findings are appropriately recorded and addressed.
Keep up to date with emerging cyber threats, regulatory developments and industry good practice, assessing their potential impact on existing controls.
Governance & Stakeholder Engagement
Attend governance forums and provide accurate updates on control status, remediation activities and risk-related controls.
Prepare reports, dashboards and status updates for cyber security governance activities.
Record and track actions arising from governance meetings through to completion.
Build effective relationships with control owners, risk specialists and technical teams to ensure controls information remains accurate and aligned.
Support the Cyber Controls Manager in maintaining an effective and auditable controls framework.
Knowledge & Skills:
Good understanding of cyber security controls and the principles of control design, implementation and governance.
Working knowledge of recognised cyber security frameworks such as ISO 27001.
Understanding of the relationship between cyber risks, risk treatments and security controls.
Strong attention to detail, with the ability to maintain structured documentation to a consistent and auditable standard.
Good written and verbal communication skills, with the ability to prepare reports and contribute effectively to governance discussions.
Understanding of audit requirements and evidence management practices.
Collaborative approach with the ability to engage effectively with technical teams, control owners and stakeholders across the business.
Desirable
Familiarity with Governance, Risk and Compliance (GRC) tools or risk and controls management platforms.
Understanding of cloud security concepts within Microsoft Azure and Microsoft 365 environments.
Knowledge of cyber security governance, assurance and compliance activities within regulated environments.
Qualifications & Experience:
Degree qualified, or equivalent, in Cyber Security, Information Security, Information Technology, Computer Science or a related discipline.
Minimum of three years' experience within cyber security, information security, controls governance or risk management.
Experience contributing to a cyber security controls framework, controls library or equivalent governance structure.
Working within formal risk management processes and supporting risk register activities.
Collection, maintenance and organisation of evidence used to demonstrate control effectiveness.
Participation in governance, assurance or compliance activities.
Production of reports, status updates and management information for technical or non-technical audiences.
Recognised certification such as CompTIA Security+, SSCP, ISO 27001 Foundation, or progress towards CISSP, CISM, CISA or CRISC.
Desirable
Experience within the nuclear sector or another highly regulated Critical National Infrastructure environment, such as defence, energy, transport or water.
Supporting governance committees, assurance reviews or regulatory activities in a technical or advisory capacity.
Why Join us?
Be part of one of the most important low-carbon energy projects in the UK.
Work in a mission-driven environment that values innovation, integrity, and long-term sustainability.
Competitive salary, comprehensive benefits, and opportunities for career development.
Flexible and hybrid working options.
For this role you must have evidence of right to work in the UK. As a project, we do not discriminate on the grounds of age, gender, race, colour, religion, disability or sexual orientation, and we welcome applications from all sections of the community.