Cyber Requirements & Compliance Specialist (Sizewell C)

Job Category:  Other
Contract Partner Company:  Jobs Service
Employing Company:  Sizewell C

The Sizewell C Jobs Service supports local people into exciting, long-term careers across our Project.#SZCJobs

 

 

Cyber Requirements & Compliance Specialist
Sizewell C
 

Security Clearance: Active Security Clearance is required and must already be in place
Location: London, Leiston or Ipswich, with hybrid working and a minimum of 2 days per week on-site. Travel to other Sizewell C locations may be required.
Contract: Permanent, full-time
Salary: £66,866 – £68,000 depending on experience, plus benefits 
Benefits include: 
Annual Leave: 28 days per annum, increasing to 30 days after 5 years of service, plus bank holidays
Bonus: 5% annual bonus
Pension Contributions: Defined Contribution Pension Scheme with up to 7.5% employee contribution 15% employer contribution
Life Assurance: Up to 8 x salary
 

Closing Date: 30th September 2026
 

About the Role:


The Cyber Requirements & Compliance Specialist plays a key role in supporting Sizewell C's cyber security strategy, governance and compliance activities.
 

Reporting to the Cyber Requirements & Compliance Manager, you will help ensure cyber security requirements, policies and standards remain aligned to regulatory obligations, organisational objectives and evolving threats. You will support the development of the cyber security policy framework, maintain compliance documentation and evidence, and help monitor compliance against regulatory, contractual and organisational requirements.
 

Working closely with cyber security, digital, assurance and business stakeholders, you will contribute to a robust and effective cyber governance framework that supports the delivery of a secure and resilient organisation.


Key Responsibilities:


Cyber Security Strategy & Policy


Support the development and continual improvement of the Cyber Security Strategy.
Draft, maintain and enhance cyber security policies, standards and supporting documentation.
Coordinate policy reviews, updates and approvals in line with governance requirements.
Monitor alignment between cyber security strategy, organisational objectives and relevant regulatory expectations.
Track the delivery of strategic cyber security objectives and contribute to progress reporting.
Promote awareness and understanding of cyber security policies and requirements across the organisation.
 

Compliance Governance & Monitoring


Maintain a detailed understanding of cyber security compliance obligations applicable to Sizewell C.
Identify, interpret and document cyber security requirements arising from legislation, regulations and industry standards.
Maintain compliance registers, evidence repositories and supporting documentation.
Monitor compliance against regulatory, contractual and organisational requirements.
Identify compliance gaps and work with stakeholders to support remediation activities.
Support the development and operation of continuous compliance monitoring processes.
Work closely with assurance functions to ensure compliance activities are aligned with assurance programmes and audit requirements.
 

Requirements & Cross-Functional Support


Monitor developments in the cyber threat landscape, regulatory environment and industry best practice.
Translate regulatory, business and security requirements into clear and actionable documentation for technical and non-technical audiences.
Support the adoption of secure-by-design principles across the organisation.
Work with security architecture, risk and controls teams to ensure policies, requirements and controls remain aligned.
Contribute to the definition and maintenance of cyber security requirements that support organisational objectives and regulatory expectations.
Support continuous improvement initiatives across cyber governance, compliance and requirements management activities.
 

Governance, Audit & Reporting


Support governance forums by providing updates on compliance performance, regulatory readiness and emerging risks.
Assist with the preparation of compliance reports, regulatory submissions and briefing materials.
Produce audit-ready documentation and management information for governance and leadership audiences.
Contribute to assurance reviews, audits and evidence-gathering activities.
Support engagement with regulators and external stakeholders where required.
Track regulatory findings, recommendations and actions through to closure.
Assist with external certification activities, including ISO 27001 and Cyber Essentials Plus.
 

Knowledge & Skills:


Strong understanding of cyber security principles, governance frameworks and compliance management practices.
Knowledge of compliance monitoring processes, including evidence management, gap analysis, remediation tracking and audit readiness.
Ability to interpret regulatory requirements, industry standards and organisational needs, translating these into clear policies, standards and requirements.
Excellent written communication skills, with the ability to produce high-quality policies, procedures, reports and compliance documentation.
Strong organisational skills and attention to detail, with the ability to manage structured documentation and evidence to an auditable standard.
Understanding of policy lifecycle management, including drafting, review, approval and version control processes.
Strong stakeholder engagement and communication skills, with the ability to work effectively across technical and business functions.
 

Desirable


Familiarity with ISO 27001/27002, NIST Cyber Security Framework (CSF) 2.0 and the NCSC Cyber Assessment Framework (CAF).
Understanding of the UK regulatory landscape for cyber security, including ONR Security Assessment Principles (SyAPs) and the NIS Regulations.
Experience using compliance management platforms, document management systems or evidence repositories.
Awareness of security architecture principles and their relationship to governance and policy frameworks.
 

Qualifications & Experience:


Degree qualified, or equivalent, in Cyber Security, Information Security, Computer Science, Business or a related discipline.
Experience within cyber security, information security, governance, compliance or risk management.
Demonstrable involvement in mapping organisational controls, processes or documentation to recognised frameworks, standards or regulatory requirements.
Contribution to compliance assessments against recognised standards such as ISO 27001, Cyber Essentials Plus, NCSC CAF or equivalent frameworks.
Participation in audits, assurance activities, regulatory inspections or evidence-based compliance programmes.
Drafting and maintaining cyber security policies, standards, procedures, reports or governance documentation.
Management of policy libraries, document repositories or structured compliance evidence.
Experience supporting governance forums, risk management activities or compliance initiatives.
 

Desirable


Professional certification such as ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, CISSP, CISM, CRISC or CompTIA Security+.
Experience within a highly regulated sector such as nuclear, energy, utilities, healthcare, financial services or the public sector.
Involvement in cyber security strategy development, security transformation programmes or assurance activities.
Familiarity with requirements management methodologies or tools within cyber security or technology environments.
 

Why Join us?


Be part of one of the most important low-carbon energy projects in the UK.
Work in a mission-driven environment that values innovation, integrity, and long-term sustainability.
Competitive salary, comprehensive benefits, and opportunities for career development.
Flexible and hybrid working options. 

 

 

 

For this role you must have evidence of right to work in the UK. As a project, we do not discriminate on the grounds of age, gender, race, colour, religion, disability or sexual orientation, and we welcome applications from all sections of the community.

The Sizewell C Jobs Service supports local people into exciting, long-term careers across our Project.#SZCJobs

 

 

Cyber Requirements & Compliance Specialist
Sizewell C
 

Security Clearance: Active Security Clearance is required and must already be in place
Location: London, Leiston or Ipswich, with hybrid working and a minimum of 2 days per week on-site. Travel to other Sizewell C locations may be required.
Contract: Permanent, full-time
Salary: £66,866 – £68,000 depending on experience, plus benefits 
Benefits include: 
Annual Leave: 28 days per annum, increasing to 30 days after 5 years of service, plus bank holidays
Bonus: 5% annual bonus
Pension Contributions: Defined Contribution Pension Scheme with up to 7.5% employee contribution 15% employer contribution
Life Assurance: Up to 8 x salary
 

Closing Date: 30th September 2026
 

About the Role:


The Cyber Requirements & Compliance Specialist plays a key role in supporting Sizewell C's cyber security strategy, governance and compliance activities.
 

Reporting to the Cyber Requirements & Compliance Manager, you will help ensure cyber security requirements, policies and standards remain aligned to regulatory obligations, organisational objectives and evolving threats. You will support the development of the cyber security policy framework, maintain compliance documentation and evidence, and help monitor compliance against regulatory, contractual and organisational requirements.
 

Working closely with cyber security, digital, assurance and business stakeholders, you will contribute to a robust and effective cyber governance framework that supports the delivery of a secure and resilient organisation.


Key Responsibilities:


Cyber Security Strategy & Policy


Support the development and continual improvement of the Cyber Security Strategy.
Draft, maintain and enhance cyber security policies, standards and supporting documentation.
Coordinate policy reviews, updates and approvals in line with governance requirements.
Monitor alignment between cyber security strategy, organisational objectives and relevant regulatory expectations.
Track the delivery of strategic cyber security objectives and contribute to progress reporting.
Promote awareness and understanding of cyber security policies and requirements across the organisation.
 

Compliance Governance & Monitoring


Maintain a detailed understanding of cyber security compliance obligations applicable to Sizewell C.
Identify, interpret and document cyber security requirements arising from legislation, regulations and industry standards.
Maintain compliance registers, evidence repositories and supporting documentation.
Monitor compliance against regulatory, contractual and organisational requirements.
Identify compliance gaps and work with stakeholders to support remediation activities.
Support the development and operation of continuous compliance monitoring processes.
Work closely with assurance functions to ensure compliance activities are aligned with assurance programmes and audit requirements.
 

Requirements & Cross-Functional Support


Monitor developments in the cyber threat landscape, regulatory environment and industry best practice.
Translate regulatory, business and security requirements into clear and actionable documentation for technical and non-technical audiences.
Support the adoption of secure-by-design principles across the organisation.
Work with security architecture, risk and controls teams to ensure policies, requirements and controls remain aligned.
Contribute to the definition and maintenance of cyber security requirements that support organisational objectives and regulatory expectations.
Support continuous improvement initiatives across cyber governance, compliance and requirements management activities.
 

Governance, Audit & Reporting


Support governance forums by providing updates on compliance performance, regulatory readiness and emerging risks.
Assist with the preparation of compliance reports, regulatory submissions and briefing materials.
Produce audit-ready documentation and management information for governance and leadership audiences.
Contribute to assurance reviews, audits and evidence-gathering activities.
Support engagement with regulators and external stakeholders where required.
Track regulatory findings, recommendations and actions through to closure.
Assist with external certification activities, including ISO 27001 and Cyber Essentials Plus.
 

Knowledge & Skills:


Strong understanding of cyber security principles, governance frameworks and compliance management practices.
Knowledge of compliance monitoring processes, including evidence management, gap analysis, remediation tracking and audit readiness.
Ability to interpret regulatory requirements, industry standards and organisational needs, translating these into clear policies, standards and requirements.
Excellent written communication skills, with the ability to produce high-quality policies, procedures, reports and compliance documentation.
Strong organisational skills and attention to detail, with the ability to manage structured documentation and evidence to an auditable standard.
Understanding of policy lifecycle management, including drafting, review, approval and version control processes.
Strong stakeholder engagement and communication skills, with the ability to work effectively across technical and business functions.
 

Desirable


Familiarity with ISO 27001/27002, NIST Cyber Security Framework (CSF) 2.0 and the NCSC Cyber Assessment Framework (CAF).
Understanding of the UK regulatory landscape for cyber security, including ONR Security Assessment Principles (SyAPs) and the NIS Regulations.
Experience using compliance management platforms, document management systems or evidence repositories.
Awareness of security architecture principles and their relationship to governance and policy frameworks.
 

Qualifications & Experience:


Degree qualified, or equivalent, in Cyber Security, Information Security, Computer Science, Business or a related discipline.
Experience within cyber security, information security, governance, compliance or risk management.
Demonstrable involvement in mapping organisational controls, processes or documentation to recognised frameworks, standards or regulatory requirements.
Contribution to compliance assessments against recognised standards such as ISO 27001, Cyber Essentials Plus, NCSC CAF or equivalent frameworks.
Participation in audits, assurance activities, regulatory inspections or evidence-based compliance programmes.
Drafting and maintaining cyber security policies, standards, procedures, reports or governance documentation.
Management of policy libraries, document repositories or structured compliance evidence.
Experience supporting governance forums, risk management activities or compliance initiatives.
 

Desirable


Professional certification such as ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, CISSP, CISM, CRISC or CompTIA Security+.
Experience within a highly regulated sector such as nuclear, energy, utilities, healthcare, financial services or the public sector.
Involvement in cyber security strategy development, security transformation programmes or assurance activities.
Familiarity with requirements management methodologies or tools within cyber security or technology environments.
 

Why Join us?


Be part of one of the most important low-carbon energy projects in the UK.
Work in a mission-driven environment that values innovation, integrity, and long-term sustainability.
Competitive salary, comprehensive benefits, and opportunities for career development.
Flexible and hybrid working options. 

 

 

 

For this role you must have evidence of right to work in the UK. As a project, we do not discriminate on the grounds of age, gender, race, colour, religion, disability or sexual orientation, and we welcome applications from all sections of the community.

Why Join Us?

For more than 60 years, nuclear power stations in the UK have been quietly keeping Britain fuelled with massive amounts of home-grown energy.

Our teams up and down the country are proudly continuing to serve the nation – but they also have an eye on the future.

EDF is leading the UK's nuclear renaissance with the construction of a new nuclear power station at Hinkley Point C and plans for a new power station at Sizewell C in Suffolk.

Nuclear power is the most reliable, low-carbon energy source currently available to the UK. EDF is playing a key role in the development of nuclear sites, while Hinkley Point C will provide low-carbon electricity to meet 7% of the UK demand. The project is already making a positive impact on the local and national economy as well as boosting skills and education.

We’re not just building new nuclear power stations. We’re developing careers, upskilling generations and creating thousands of employment and apprenticeship opportunities across a variety of skills areas.

It takes a special kind of person to work in the nuclear energy industry and although we have thousands of them there’s always a need for more.

Our industry has a mind-boggling range of opportunities and more jobs, and in more places, than you might think. But it’s also an industry which is changing.

We’re a responsible business and proud to be Britain’s biggest generator of zero carbon electricity. With size, age and experience, we believe we can do even more.