- Company Name
- Great British Nuclear
- Job Title
- Information Security Manager
- Job Description
-
Job title: Information Security Manager
Role Summary: Lead the planning, implementation, and oversight of information security across the Small Modular Reactor (SMR) project, ensuring compliance with nuclear, cyber‑security standards and international user collaboration. Manage risk, policy, and incident response while coordinating with engineering, IT, regulatory, and operational technology teams.
Expactations: • Deliver comprehensive security strategy and framework for SMR digital assets. • Maintain adherence to ISO/IEC 27001, NIS‑UK, NCSC, NIST SP 800, AI Cybersecurity Codes, and ONR Security Assessment Principles. • Enable secure data exchange within a global user community. • Foster continuous improvement through risk assessment, threat modelling, and cyber‑resilience testing. • Guide and mentor security staff, promote security culture, and interface with external stakeholders.
Key Responsibilities:
- Develop and execute information security strategy and Information Assurance Framework for the SMR lifecycle.
- Conduct risk assessments, threat modelling, vulnerability analysis, and maintain risk register.
- Design, implement, and test incident response plans and cyber‑resilience exercises.
- Lead continuous improvement of security policies, procedures, and controls aligned with nuclear and cyber regulations.
- Partner with engineering, IT, OT, and regulatory teams to embed security into system design and delivery.
- Manage relationships with vendors, regulators, and external security bodies (NCSC, ONR).
- Oversee internal security stakeholder coordination and external partnership tracking.
- Facilitate design‑review meetings focused on information security.
- Provide expert advice on security matters to project leadership and stakeholders.
Required Skills:
- Expert knowledge of ISO/IEC 27001, NIS‑UK, NCSC guidance, NIST SP 800 series, AI Cybersecurity Codes, ONR Security Assessment Principles.
- Proven experience in risk management, threat modeling, vulnerability assessment, and incident response.
- Strong understanding of nuclear industry security standards and compliance requirements.
- Ability to manage and mentor security teams in a large, multidisciplinary environment.
- Excellent stakeholder management, communication, and facilitation skills.
- Experience with international user communities and cross‑border information exchange.
- Knowledge of IT‑OT convergence and cyber resilience testing practices.
- Proficiency in security policy development, compliance audits, and audit readiness.
- Ability to integrate security into system engineering and regulatory review processes.
Required Education & Certifications:
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Assurance, or related field.
- Minimum of 5–10 years of progressive Information Security management experience in high‑risk or critical infrastructure sectors.
- Professional certifications: ISO/IEC 27001 Lead Implementer or Lead Auditor, CISSP, CISM, or equivalent.
- Additional certifications in nuclear safety/security preferred.
Warrington, United kingdom
Hybrid
03-12-2025