Information Security GRC Lead

Good Energy Group

Chippenham

Hybrid

GBP 50,000 - 60,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Work from home allowance
Travel allowance
Development allowance
Annual bonus
Holiday entitlement
Ethical pension

Job summary

Good Energy Group is seeking an Information Security GRC Lead in Chippenham, Wiltshire. The role oversees information security governance, risk and compliance across IT security, resilience and control governance, coordinating with Technology Teams to implement and evidence controls.

The successful candidate will coordinate security activity, provide guidance, and track remediation without performing day-to-day technical administration. Hybrid work and growth opportunities are offered.

Qualifications

  • As per guidelines, strong knowledge of IT security risk and control management.
  • Experience coordinating IT security controls and vulnerability management.
  • Familiarity with ISO27001, Cyber Essentials, NCSC CAF and PCI-DSS.
  • Excellent verbal and written communication for non-technical audiences.
  • Detail-oriented with clear, evidence-based documentation.
  • Ability to translate complex security concepts into practical procedures.

Responsibilities

  • IT Security Governance: oversee risks, controls, policies and standards.
  • Security Control Assurance: evidence and remediate information security controls.
  • Information Security Risk and Compliance: interpret standards, translate to actions.
  • Security Incident Support: assist incident response and evidence collection.
  • IT Disaster Recovery and Resilience: coordinate DR plans and testing.
  • IT Change Management: support CAB and ensure secure actions.
  • PCI-DSS Compliance: coordinate activity, testing and remediation tracking.
  • Penetration Testing Coordination: coordinate testing and track findings with owners.
  • Technology Policy and Awareness: develop policies and guidance.

Skills

IT Security Governance
Risk Management
Compliance Coordination
Communication Skills
Attention to detail

Tools

ISO27001
CREST Testing

Job description

Information Security GRC Lead

Application Deadline: 4 October 2026

Department: Information Governance

Employment Type: Permanent - Full Time

Location: Chippenham, Wiltshire

Reporting To: Carrie Coles

Compensation: £50,000 - £60,000 / year

Description
No day will be the same - here are some of the highlights

Reporting into the Head of IGRC, this role provides information security GRC oversight, coordination and assurance across IT security, resilience and control governance, working closely with Technology Teams who retain ownership of technical implementation and day-to-day system administration.

We are seeking a practical and technically capable Information Security GRC Lead to help strengthen Good Energy’s security and control environment. This role will act as a key link between IGRC and Technology Teams; identifying security and compliance requirements, coordinating activity, providing guidance and challenge, evidencing controls, and tracking remediation. The role is not expected to perform day-to-day technical administration but will need sufficient technical understanding to work effectively with the Technology Teams who implement and operate the controls.

Key Responsibilities include:

  • IT Security Governance: Maintain oversight of IT security risks, controls, policies and standards, helping define what good control looks like and working with Technology Teams to ensure ownership, implementation and evidence are clear.
  • Security Control Assurance: Coordinate and evidence regular assurance over information technology security controls across people, process, premises and technology, working with Technology Teams to validate control operation, escalating gaps and track remediation.
  • Information Security Risk and Compliance: Support information security risk and compliance activity by interpreting relevant standards and good practice frameworks, translating requirements into practical actions, and working with Technology Teams to support proportionate implementation.
  • Security Incident Support: Support security incident response by helping assess governance, risk and compliance impacts, coordinating evidence, supporting root cause analysis and ensuring lessons learned are tracked with the relevant technical owners
  • IT Disaster Recovery and Resilience: Coordinate oversight and challenge of IT disaster recovery arrangements, working with Technology Teams to maintain plans, schedule testing, evidence outcomes, identify dependencies and track remediation of weaknesses.
  • IT Change Management: Support effective IT change governance, including chairing or supporting the Good Energy Change Advisory Board, and ensuring security and resilience impacts are considered and that technical owners complete agreed actions before implementation where required.
  • PCI-DSS Compliance: Coordinate and support PCI-DSS control activity, evidence gathering, control testing and remediation tracking where technology controls are in scope.
  • Penetration Testing and Vulnerability Management: Coordinate penetration testing and support vulnerability management oversight, working with Technology Teams and third parties to risk assess findings, agree ownership and monitor remediation without taking ownership of technical remediation activity.
  • Technology Policy and Awareness: Develop, review and maintain technology security policies, standards and guidance, supporting employee awareness of key security responsibilities.
What you'll need to succeed

As the Information Security GRC Lead, you will be a proactive, practical and technically aware individual who can work confidently between IGRC, Technology Teams and wider business teams.

You will be able to translate technical security concepts into clear business language, provide proportionate guidance and challenge, and coordinate practical security activity without needing to be the person who directly configures or administers the underlying technology.

You will be comfortable working independently, influencing across teams and maintaining focus on practical risk reduction, strong evidence and continuous improvement.

Essential

  • Good understanding of information technology security, information security risk and control management.
  • Experience supporting, coordinating or assuring IT security controls, vulnerability management, incident response, IT disaster recovery or IT change governance, ideally while working alongside technical teams who own implementation.
  • Awareness of recognised security standards or frameworks such as ISO27001, Cyber Essentials, NCSC CAF and PCI-DSS.
  • Strong verbal and written communication skills, with the ability to explain technical matters clearly to non-technical audiences.
  • Demonstrable attention to detail and ability to produce clear, evidence-based documentation.
  • Ability to interpret technical workflows, risks and controls and translate them into practical procedures, policies, or assurance activity and clear actions for technical owners.
  • Confident working with stakeholders across technology, governance and business teams to agree actions and track remediation.

Desirable

  • Experience working in a regulated sector, ideally energy, with exposure to Smart Metering security obligations, governance or assurance requirements.
  • Experience coordinating CREST-accredited penetration testing, reviewing findings, agreeing remediation plans and tracking closure with technical owners.
  • Relevant qualification or certification such as ISO2701 Foundation or Implementer, CISMP, SSCP, Security+, CISA or equivalent experience.
  • Working knowledge of data protection requirements where they intersect with technology security controls.

Hybrid working explained: When and where you’ll be in the office

Our office is based in Chippenham, Wiltshire. For this role, we're looking for candidates who can come in to our Chippenham office, once a week.

We offer both formal and informal flexible working options. Full-time hours are 37.5 per week, Monday to Friday.

The office is fully accessible, allowing everyone to participate fully in their working lives regardless of any mobility challenges. We promote work-life balance and flexibility through hybrid working, which combines both remote and office work.

Benefits you can rely on

Great allowances for hybrid working:

£500 work from home allowance - an annual allowance paid monthly alongside your salary to support with working from home costs.

£500 travel allowance - an annual allowance paid monthly alongside your salary to support with travelling to work costs.

£500 annual development allowance: to spend on your chosen development area, whether that’s in your current role, or future roles.

15% annual bonus: company-wide bonus scheme designed to reward collective teamwork and delivery of results across the whole business.

Holiday: 25 days annual leave, a day off for your birthday, additional days leave for long service, plus bank holidays. You’ll also have the option to buy additional leave, allowing for a better work-life balance.

Ethical Pension with Aviva: Good Energy offers an ethical pension plan provided by Aviva, with employer-matched contributions up to 7.5% of your base salary.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Legal Counsel
Legal Counsel

Good Energy Group • Chippenham

On-site
GBP 65,000 - 80,000
Work from home allowance
Travel allowance
Development allowance
+3
Legal Counsel
Legal Counsel

Good Energy • Chippenham

Hybrid
GBP 70,000 - 100,000
WFH allowance
Travel allowance
Development allowance
+3
SHEQ Advisor
SHEQ Advisor

Greenergy • Manchester

Hybrid
GBP 40,000 - 60,000
Competitive salary
Private medical insurance
Enhanced company pension
+7
Regulatory Cyber Assurance Principal
Regulatory Cyber Assurance Principal

Ofgem • Glasgow, Cardiff, Greater London

Hybrid
GBP 60,000 - 67,000
Civil Service Pension
Hybrid working
Training and development opportunities
Application Security Engineer
Application Security Engineer

Centrica • Clewer Village

Hybrid
GBP 70,000 - 100,000
Market salary
Energy allowance 15%
Pension plan
+3
Cyber Security Manager
Cyber Security Manager

Elexon • Greater London

Hybrid
GBP 68,000 - 92,000
Bonus
Private medical insurance
Generous pension scheme
SSES Cyber Security Lead
SSES Cyber Security Lead

Elexon Ltd • Greater London

Hybrid
GBP 72,000 - 88,000
Bonus
Private medical insurance
Generous pension scheme
+1
Lead DCO Project Manager
Lead DCO Project Manager

National Grid plc • Hemington

Hybrid
GBP 62,000 - 77,000
Company car
Bonus
Pension with 12% company contribution
+5
Process and Controls Analyst
Process and Controls Analyst

Greenergy • Manchester

On-site
GBP 45,000 - 60,000
Competitive compensation
Private medical insurance
Enhanced company pension
+7
Information Governance Coordinator
Information Governance Coordinator

Somerset Bridge • West of England

On-site
GBP 26,000 - 29,000
Hybrid working
25 days annual leave
Discretionary annual bonus
+4