Cyber Risk Manager (Sizewell C)

Job Category:  Other
Contract Partner Company:  Jobs Service
Employing Company:  Sizewell C

The Sizewell C Jobs Service supports local people into exciting, long-term careers across our Project.#SZCJobs

 

 

Cyber Risk Manager
Sizewell C
 

Security Clearance: Active Security Clearance is required and must already be in place
Location: London, Leiston or Ipswich, with hybrid working and a minimum of 2 days per week on-site. Travel to other Sizewell C locations may be required.
Contract: Permanent, full-time
Salary: £86,000 - £89,000 depending on experience, plus benefits 
Benefits include: 
Annual Leave: 28 days per annum, increasing to 30 days after 5 years of service, plus bank holidays
Bonus: 10% annual bonus
Pension Contributions: Defined Contribution Pension Scheme with up to 7.5% employee contribution 15% employer contribution
Life Assurance: Up to 8 x salary


Closing Date: 30th September 2026
 

About the Role:


The Cyber Risk Manager plays a critical role in ensuring Sizewell C's cyber risks are identified, understood, prioritised and effectively managed.


Reporting directly to the Chief Information Security Officer (CISO), you will lead the organisation's cyber risk management framework, maintain oversight of the cyber risk landscape and ensure risks are managed in line with regulatory requirements and business objectives.


Operating at the intersection of technology, security and business risk, you will translate complex cyber threats into clear and actionable insights, enabling informed decision-making at all levels of the organisation. Working closely with cyber security, digital, assurance and business teams, you will help strengthen organisational resilience and ensure cyber risk remains a key consideration across strategic and operational activities.
 

Key Responsibilities:


Risk Register Management


Own and maintain the organisation's cyber risk register, ensuring risks are clearly documented, appropriately owned and kept audit ready.
Develop and maintain the cyber risk taxonomy, including risk categories, threat sources and impact domains aligned to critical business functions.
Define and maintain risk scoring methodologies, appetite thresholds and escalation criteria in collaboration with senior leadership.
Ensure cyber risks are assessed, prioritised and managed consistently across the organisation.
 

Risk Assessment Oversight


Establish and maintain processes for the identification, assessment and recording of cyber risks.
Ensure risk assessments are undertaken at appropriate trigger points, including new system deployments, major projects and significant business change.
Oversee the application of recognised risk assessment methodologies and good practice.
Provide guidance and support for complex cyber risk assessments where required.
Provide line management and leadership to the Cyber Risk Assessment Lead
 

Risk Treatment & Mitigation


Oversee the development and delivery of cyber risk treatment plans, ensuring clear ownership, realistic timescales and measurable outcomes.
Work closely with cyber security and technology teams to ensure controls are implemented, effective and aligned to identified risks.
Maintain traceability between identified risks, mitigating controls and remediation activities.
Ensure risk acceptance decisions, exceptions and associated approvals are appropriately governed and documented.
 

Risk Reporting & Governance


Prepare and present cyber risk reports, dashboards and insights for the CISO, senior leadership and governance forums.
Monitor risk trends, emerging threats and mitigation progress, highlighting areas requiring management action.
Escalate significant risks that exceed approved tolerance levels and provide recommendations for resolution.
Ensure cyber risks are appropriately reflected within the wider enterprise risk management framework.
Support regulatory submissions, audits and reviews by maintaining robust risk management records and evidence.
 

Stakeholder Engagement


Provide expert advice and guidance on cyber risk management across the organisation.
Collaborate with Security Operations, Digital and wider business teams to understand emerging threats and assess their potential impact.
Support threat modelling, business impact assessments and wider cyber resilience activities.
Promote a proactive and risk-informed culture across the organisation.
 

Knowledge & Skills:


Thorough understanding of cyber risk frameworks and assessment methodologies, including ISO 27005 and NIST Risk Management Framework.
Ability to develop and maintain cyber risk registers, taxonomies, risk scoring methodologies and risk appetite frameworks.
Strong understanding of how cyber risk integrates with enterprise risk management and wider organisational governance processes.
Ability to translate complex technical risks into clear and meaningful business language for non-technical audiences.
Strong analytical, stakeholder management and communication skills.
Experience presenting cyber risk information to senior leaders and governance forums.
Ability to influence decision-making and drive effective risk-based outcomes across multiple stakeholder groups.
 

Desirable


Understanding of the UK nuclear cyber security regulatory landscape, including ONR requirements, Security Assessment Principles (SyAPs), NISR and NIS Regulations.
Knowledge of threat intelligence processes and how cyber threat information supports ongoing risk assessment and decision-making.
Familiarity with assurance, audit and regulatory compliance activities within highly regulated environments.
 

Qualifications & Experience:


Degree qualified in Cyber Security, Information Security, Computer Science, Risk Management or a related discipline, or equivalent professional experience.
Minimum of five years' experience within cyber security or information security, including at least three years with significant responsibility for cyber risk management.
Proven track record of conducting or overseeing cyber risk assessments using recognised methodologies such as ISO 27005, NIST RMF, FAIR or OCTAVE.
Experience developing, maintaining and governing cyber risk registers within complex organisations.
Establishing or facilitating risk governance forums involving senior stakeholders and risk-based decision-making.
Management of cyber risk treatment activities across multiple teams and competing priorities.
Production of cyber risk reporting for executive and board-level audiences.
Experience working within, or closely alongside, Critical National Infrastructure sectors such as nuclear, defence, energy, transport, water or telecommunications.
Relevant professional certification such as CISSP, CISM, CRISC or equivalent.
 

Desirable


Background within the nuclear sector or other highly regulated industries.
Familiarity with environments subject to external cyber security audits, regulatory inspections or formal assurance activities.
Previous people management, mentoring or technical leadership experience within a cyber security or risk management function.
 

Why Join us?


Be part of one of the most important low-carbon energy projects in the UK.
Work in a mission-driven environment that values innovation, integrity, and long-term sustainability.
Competitive salary, comprehensive benefits, and opportunities for career development.
Flexible and hybrid working options. 

 

 

 

For this role you must have evidence of right to work in the UK. As a project, we do not discriminate on the grounds of age, gender, race, colour, religion, disability or sexual orientation, and we welcome applications from all sections of the community.

The Sizewell C Jobs Service supports local people into exciting, long-term careers across our Project.#SZCJobs

 

 

Cyber Risk Manager
Sizewell C
 

Security Clearance: Active Security Clearance is required and must already be in place
Location: London, Leiston or Ipswich, with hybrid working and a minimum of 2 days per week on-site. Travel to other Sizewell C locations may be required.
Contract: Permanent, full-time
Salary: £86,000 - £89,000 depending on experience, plus benefits 
Benefits include: 
Annual Leave: 28 days per annum, increasing to 30 days after 5 years of service, plus bank holidays
Bonus: 10% annual bonus
Pension Contributions: Defined Contribution Pension Scheme with up to 7.5% employee contribution 15% employer contribution
Life Assurance: Up to 8 x salary


Closing Date: 30th September 2026
 

About the Role:


The Cyber Risk Manager plays a critical role in ensuring Sizewell C's cyber risks are identified, understood, prioritised and effectively managed.


Reporting directly to the Chief Information Security Officer (CISO), you will lead the organisation's cyber risk management framework, maintain oversight of the cyber risk landscape and ensure risks are managed in line with regulatory requirements and business objectives.


Operating at the intersection of technology, security and business risk, you will translate complex cyber threats into clear and actionable insights, enabling informed decision-making at all levels of the organisation. Working closely with cyber security, digital, assurance and business teams, you will help strengthen organisational resilience and ensure cyber risk remains a key consideration across strategic and operational activities.
 

Key Responsibilities:


Risk Register Management


Own and maintain the organisation's cyber risk register, ensuring risks are clearly documented, appropriately owned and kept audit ready.
Develop and maintain the cyber risk taxonomy, including risk categories, threat sources and impact domains aligned to critical business functions.
Define and maintain risk scoring methodologies, appetite thresholds and escalation criteria in collaboration with senior leadership.
Ensure cyber risks are assessed, prioritised and managed consistently across the organisation.
 

Risk Assessment Oversight


Establish and maintain processes for the identification, assessment and recording of cyber risks.
Ensure risk assessments are undertaken at appropriate trigger points, including new system deployments, major projects and significant business change.
Oversee the application of recognised risk assessment methodologies and good practice.
Provide guidance and support for complex cyber risk assessments where required.
Provide line management and leadership to the Cyber Risk Assessment Lead
 

Risk Treatment & Mitigation


Oversee the development and delivery of cyber risk treatment plans, ensuring clear ownership, realistic timescales and measurable outcomes.
Work closely with cyber security and technology teams to ensure controls are implemented, effective and aligned to identified risks.
Maintain traceability between identified risks, mitigating controls and remediation activities.
Ensure risk acceptance decisions, exceptions and associated approvals are appropriately governed and documented.
 

Risk Reporting & Governance


Prepare and present cyber risk reports, dashboards and insights for the CISO, senior leadership and governance forums.
Monitor risk trends, emerging threats and mitigation progress, highlighting areas requiring management action.
Escalate significant risks that exceed approved tolerance levels and provide recommendations for resolution.
Ensure cyber risks are appropriately reflected within the wider enterprise risk management framework.
Support regulatory submissions, audits and reviews by maintaining robust risk management records and evidence.
 

Stakeholder Engagement


Provide expert advice and guidance on cyber risk management across the organisation.
Collaborate with Security Operations, Digital and wider business teams to understand emerging threats and assess their potential impact.
Support threat modelling, business impact assessments and wider cyber resilience activities.
Promote a proactive and risk-informed culture across the organisation.
 

Knowledge & Skills:


Thorough understanding of cyber risk frameworks and assessment methodologies, including ISO 27005 and NIST Risk Management Framework.
Ability to develop and maintain cyber risk registers, taxonomies, risk scoring methodologies and risk appetite frameworks.
Strong understanding of how cyber risk integrates with enterprise risk management and wider organisational governance processes.
Ability to translate complex technical risks into clear and meaningful business language for non-technical audiences.
Strong analytical, stakeholder management and communication skills.
Experience presenting cyber risk information to senior leaders and governance forums.
Ability to influence decision-making and drive effective risk-based outcomes across multiple stakeholder groups.
 

Desirable


Understanding of the UK nuclear cyber security regulatory landscape, including ONR requirements, Security Assessment Principles (SyAPs), NISR and NIS Regulations.
Knowledge of threat intelligence processes and how cyber threat information supports ongoing risk assessment and decision-making.
Familiarity with assurance, audit and regulatory compliance activities within highly regulated environments.
 

Qualifications & Experience:


Degree qualified in Cyber Security, Information Security, Computer Science, Risk Management or a related discipline, or equivalent professional experience.
Minimum of five years' experience within cyber security or information security, including at least three years with significant responsibility for cyber risk management.
Proven track record of conducting or overseeing cyber risk assessments using recognised methodologies such as ISO 27005, NIST RMF, FAIR or OCTAVE.
Experience developing, maintaining and governing cyber risk registers within complex organisations.
Establishing or facilitating risk governance forums involving senior stakeholders and risk-based decision-making.
Management of cyber risk treatment activities across multiple teams and competing priorities.
Production of cyber risk reporting for executive and board-level audiences.
Experience working within, or closely alongside, Critical National Infrastructure sectors such as nuclear, defence, energy, transport, water or telecommunications.
Relevant professional certification such as CISSP, CISM, CRISC or equivalent.
 

Desirable


Background within the nuclear sector or other highly regulated industries.
Familiarity with environments subject to external cyber security audits, regulatory inspections or formal assurance activities.
Previous people management, mentoring or technical leadership experience within a cyber security or risk management function.
 

Why Join us?


Be part of one of the most important low-carbon energy projects in the UK.
Work in a mission-driven environment that values innovation, integrity, and long-term sustainability.
Competitive salary, comprehensive benefits, and opportunities for career development.
Flexible and hybrid working options. 

 

 

 

For this role you must have evidence of right to work in the UK. As a project, we do not discriminate on the grounds of age, gender, race, colour, religion, disability or sexual orientation, and we welcome applications from all sections of the community.

Why Join Us?

For more than 60 years, nuclear power stations in the UK have been quietly keeping Britain fuelled with massive amounts of home-grown energy.

Our teams up and down the country are proudly continuing to serve the nation – but they also have an eye on the future.

EDF is leading the UK's nuclear renaissance with the construction of a new nuclear power station at Hinkley Point C and plans for a new power station at Sizewell C in Suffolk.

Nuclear power is the most reliable, low-carbon energy source currently available to the UK. EDF is playing a key role in the development of nuclear sites, while Hinkley Point C will provide low-carbon electricity to meet 7% of the UK demand. The project is already making a positive impact on the local and national economy as well as boosting skills and education.

We’re not just building new nuclear power stations. We’re developing careers, upskilling generations and creating thousands of employment and apprenticeship opportunities across a variety of skills areas.

It takes a special kind of person to work in the nuclear energy industry and although we have thousands of them there’s always a need for more.

Our industry has a mind-boggling range of opportunities and more jobs, and in more places, than you might think. But it’s also an industry which is changing.

We’re a responsible business and proud to be Britain’s biggest generator of zero carbon electricity. With size, age and experience, we believe we can do even more.