Information Security Officer (Operational Technology)

ENWL
Preston
2 weeks ago
Create job alert

We’re champions of the North West and we’re proud that it’s our electricity network that connects communities and helps keep the electricity flowing every minute of every day, from when you wake up to when you fall asleep and all the hours in between.

A key part of the UK’s journey to net zero carbon is the revolution of our electricity industry to enable clean, green economic growth. As the North West’s electricity network operator, it’s our responsibility to lead the way, help the region decarbonise and pave the way for the growth of renewable energy and a sustainable energy future for all.

We’re proud that in December 2024 we were named Utility of the Year by Utility Week magazine who said we punched above our weight and used innovation to solve some of the industry’s most difficult challenges. Come and be part of our team and make a difference.

Together we have the energy to transform our communities. We are switched on. We are adaptable. We take pride.

Our Information Security team has a great opportunity for an Information Security Officer Operational Technology to join them in Preston.

Our role

The primary purpose of the role is to ensure the Operational Technology (OT) area of business is compliant against security policy.

As the Information Security Officer, you will act as advisory, collaborating with stakeholders and management to improve security posture, review policies, and assist with incident, security reviews and ensure business processes comply with ENWL cyber security policy frameworks.

What we’re looking for

  • Proven experience of IT/OT experience, with demonstrable experience in an information security officer role or similar risk/ security audit type role.

Certifications:

  • Certification in Information Security Management (ISC2 CISSP, CRISK/ COMPTIA Security+ Network+);
  • NIST, IEC 62443 experience required;
  • ISO27001 audit experience preferred

The Information Security Officer must have the following:

  • The ability to communicate and build strong relationships with business functions across ENWL, work effectively with external partners, and manage stakeholder risk engagement sessions;
  • Confirmed background in an information security type role with real-world experience of reviewing policies and acting as advisory to the business on a day-to-day basis monitoring security compliance across diverse business functions, specifically focused and exposure to Operational Technology, (OT) environments;
  • Experience of using a centralised application risk management platform, and business applications;
  • Capacity to assist in incidents and support business and HR investigations into data breaches or misuse, ensuring lessons learnt are captured and adopted;
  • Experience of assessing vulnerability management platform data, and interpreting attack scenarios;
  • Experience of maintaining policies, procedures, standards, and guidelines
  • Capability to become policy subject matter expert, and provide advice and guidance across the organisation in support of security compliance against policies;
  • Ability to articulate security risk simply and effectively with business managers and business stakeholders;
  • An appreciation of business drivers, security tools, technologies, and security best practice;
  • Understanding of information security related law and regulations such as GDPR and NIS Regulations;
  • Previous experience of working within a regulated organisation, preferably Utilities, Energy sectors;
  • Exposure to cyber security frameworks and standards. I.e. NCSC CAF, NIST, ISO 2700x series, CIS;
  • Understanding of different security testing strategies, with ability to support.

What we’re offering

As a vital team member and in return for your expertise, inclusive approach and commitment, we'll provide a favourable salary and the chance to join a passionate and welcoming team. We are committed to ensuring our people are supported and are proud of our reward and benefits offer, which includes:

  • An annual bonus scheme
  • 25 days annual leave increasing with length of service
  • Private Healthcare
  • An employee rewards portal offering discounts on several well-known brands
  • A market-leading contributory pension scheme
  • Employee assistance programme
  • Opportunity for professional development through our L&D function.

Our people are important to us and we’re passionate about creating a great place to work where we can all be ourselves, reach our full potential and build long lasting careers. We’re striving to increase diversity of thought and talent in our people and to recruit highly skilled workforce that’s representative of the communities we serve. For us, embracing our differences is what makes us stronger.

Should you require any additional support with your application, or any adjustments please contact our Recruitment team at or on (option 2)

Any offer made will remain conditional until pre-employment checks are complete to a level deemed satisfactory by Electricity North West. Due to the of this role, the following pre-employment checks will be required; references from previous employers, BS7858 checks and a Drug & Alcohol test.

We reserve the right to close this vacancy early.

We don't accept speculative CVs from agencies. Any received we will assert ownership of the candidate and no fee will be payable.

Related Jobs

View all jobs

Information Security Officer (Operational Technology)

IT Security Officer

Senior Information Security Officer - DV

Chief Information Security Officer

Virtual Chief Information Security Officer (vCISO)

Virtual Chief Information Security Officer (vCISO)

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Tips for Staying Inspired: How Cyber Security Pros Fuel Creativity and Innovation

Cyber security professionals face a rapidly changing digital landscape, where new threats emerge almost daily and the stakes—protecting critical data, safeguarding personal privacy, and defending entire infrastructures—could not be higher. It’s easy to be consumed by vulnerability scans, incident response workflows, and endless compliance checks. Yet, thriving in this high-pressure environment demands more than just technical know-how. It also requires creativity and innovation, which enable you to stay one step ahead of potential attackers. So how do cyber security experts remain inspired and agile, even when the challenges can feel relentless? Below, we’ll explore ten actionable strategies to help security analysts, threat hunters, penetration testers, and security engineers maintain fresh perspectives and keep innovating. If you’re looking to sharpen your problem-solving skills and rediscover the spark that drew you to cyber security in the first place, these tips can guide you toward a more fulfilling and impactful career.

Top 10 Cyber Security Career Myths Debunked: Key Facts for Aspiring Professionals

In a hyper-connected world, cyber security is no longer an afterthought—it’s a core component of modern business, government, and everyday life. From stopping ransomware attacks to safeguarding personal data, cyber security professionals shoulder a vital responsibility: keeping digital systems, networks, and data safe. Unsurprisingly, the demand for skilled cyber security talent continues to surge, offering robust and often lucrative career paths. Yet, despite the industry’s prominence, myths and misconceptions about cyber security careers abound. Is it really just about hacking? Do you need to be a superhuman coder with years of experience? Or is cyber security just a niche field, reserved for tech giants? At CyberSecurityJobs.tech, we see firsthand how these myths deter capable individuals from entering or advancing in one of the most dynamic fields in tech. This article aims to bust the top 10 cyber security career myths—providing clear, evidence-based insights into what it really takes to thrive in this ever-evolving domain. Whether you’re a recent graduate exploring the field, a mid-career professional seeking a pivot, or simply curious about the prospects, read on to discover the true breadth and promise of cyber security careers.

Global vs. Local: Comparing the UK Cyber Security Job Market to International Landscapes

Understanding opportunities, salaries, and work culture in cyber security across the UK, the US, Europe, and Asia Cyber security has rapidly ascended from a back-office concern to a strategic priority for every industry. As data breaches, ransomware, and nation-state attacks increase in frequency and sophistication, organisations worldwide are racing to fortify their digital defences. This ongoing surge in cyber threats fuels an unprecedented demand for skilled security professionals—ranging from penetration testers and threat intelligence analysts to cloud security architects and CISOs. In this article, we’ll explore how the UK cyber security job market compares to major international hubs in the United States, Europe, and Asia. We’ll discuss job opportunities, salary bands, work culture, and provide guidance for those who might be contemplating remote or overseas positions. By understanding the nuances of each region’s cyber security ecosystem, you can make a more informed decision about where and how to advance your career in this high-impact, fast-evolving sector. Whether you’re a seasoned expert with years of experience or a career-changer eager to break into cyber security, this overview will help you navigate the global landscape. By the end, you’ll have a clearer perspective on each region’s advantages and challenges—along with practical insights for seizing the best opportunities in a field that has become mission-critical for every modern organisation.