This is a Permanent, Full Time vacancy that will close in {x} days at {xx:xx} BST.
The Vacancy
Job Summary / Role Purpose
ElectraLink manages complex technology for both external stakeholders and for managing its business operations, enabling staff to collaborate effectively. In addition, ElectraLink has accountability for the responsible management of large data sets on behalf of the energy market, including data covered by legislation such as the UK GDPR. The security of data and information is therefore a key business priority for ElectraLink.
This is a strategic and hands-on work role where you will act as Information Security SME and support the Head of Compliance & Data Privacy driving the Information Security strategy. They will identify, develop, implement and maintain security processes and identify and implement security related technology tools across the organisation to reduce risks, respond to incidents, and limit exposure to liability in all areas of information and data security.
What you will do
Develop Information Security policies, standards and procedures and continually monitor the information security controls, KRIs/KPIs and technical landscape.
Identify information security risks and maintain a risk register, advising on risk mitigation and remediation efforts, working with internal and external stakeholders.
Identify security gaps and advise on risk mitigation and remediation efforts.
Work closely with IT and wider stakeholders to promote and adopt security best practices and maintain the organisation’s security posture.
Oversee the implementation and maintenance of security controls across the organisation to protect our valuable assets.
Engaging with external third parties who provide services to ElectraLink and working closely with the Supply Chain Management Team to ensure appropriate and contracted levels of security are met.
Work closely with IT and third parties that manage our customer solutions to ensure that critical security controls are in place.
Act as the information security lead on relevant projects and initiatives undertaken by ElectraLink, providing information security subject matter expertise and working closely with associated SMEs to ensure projects are delivered in compliance with policies and standards.
Conduct security assessments (internal and external with relevant suppliers) and ensure compliance and best practice is adhered to.
Support the Head of Compliance & Data Privacy driving the Information Security strategy.
Develop and coordinate incident response plans, lead on investigating suspected and actual security incidents, produce reports with recommendations and ensure any remedial action is taken, and lead post-incident evaluations to improve future security.
Work with Head of Compliance and Data Privacy to investigate suspected and actual data breaches in accordance with the Data Breach Procedure, produce recommendations and ensure any remedial action is taken.
Maintain knowledge of emerging information security trends, risks, new guidance, or standards (internal and external), and security enhancing technologies, communicate and manage current and emerging security threats.
Advise on and manage implementation of security controls against industry standards such as the NIST Cyber Security Framework, ISO27001/2, SOC2, etc.
Work with Business Improvement and IT to maintain appropriate information security certifications, including Cyber Essentials Plus and ISO27001.
Deliver security awareness training.
Your Key Relationships in this role
Person / Team
Nature of Relationship
Head of Compliance and Data Privacy
Line manager. Working together to drive the Information Security Strategy.
IT Team
Work in partnership with team members to manage security posture, but also ensuring that this team work to the required security standards.
Key third party suppliers
Work in partnership with team members to manage security posture, but also ensuring that this team work to the required security standards.
ElectraLink employees
Providing technical security expertise in a collaborative manner with all staff. Education and training on security and being able to objectively assess compliance with policies by staff, including conducting confidential investigations into potential policy breaches.
Skills & Knowledge, you will need.
3 years+ proven experience as an Information Security Manager
Industry certifications such as CISSP, CISA, CISM or ISO 27001 Lead Implementer are highly valued.
Strong experience and understanding of information security frameworks and policies such as ISO 27001
Clear communicator, in person and written, with the ability to clearly articulate ideas to both technical and non-technical audiences.
Must be capable of working pragmatically and efficiently in both a team and alone.
Experience developing information security policy documentation, working in line with best practice principles for information security.
Experience of conducting information security based investigations and the management of such inquiries.
Experience of working within or alongside an MSSP or SOC provider.
Self-motivated, highly proactive, and an ability to lead on the end-to-end delivery of projects.
Effective prioritisation and organisational skills, ability to manage multiple competing priorities in a fast-paced environment.
Maintain and constantly enriching knowledge of information security and cyber risks as they develop.
Experience with security technologies, including firewalls, intrusion detection systems (IDS/IPS), security information and event management (SIEM), endpoint detection and response (EDR), and data loss prevention (DLP)
What’s in it for you:
💻 Hybrid/ Flexible working including a 4 day week!
🩺 Private healthcare you and for family which includes pre-existing conditions·
❤ Employee Assistance Programme and Mental Health Cover·
💷 Company bonus and annual pay reviews·
📚 Annual training budget and quarterly reviews to support your professional development·
🚗 Electric vehicle salary sacrifice scheme·
🏋️ 50% off Fitness First·
💃 Monthly social events organised by our Social Committee
Why we work for ElectraLink:
🤝🏻 Open lines of communication throughout the business- your voice matters!
🙌🏻 Regular Employee Forum meetings to gather suggestions from the business on making ElectraLink an even better place to work!·
🌍 Innovative and open to new ideas to support our net-zero status·
📈 Exciting, innovative and fast moving company which is growing·
👏 High challenge, high support working environment.
If this sounds like the role for you, we would love for you to get in touch, however we cannot provide sponsorship.
ElectraLink is a growing company, operating at the heart of the UK energy market with unrivalled insight into the challenges and opportunities faced by the industry.
Our data hub supports the development of a more efficient energy market that is accommodating the transition to local generation and balancing.
Our position at the heart of the UK energy industry also gives us a unique capability to provide other services crucial to the gas and electricity markets including:
· Unique market insight through analysis of the DTS market data that we process in our central industry role.
· Partnering in the implementation and change management of energy industry Governance arrangements.
· Development of more efficient market processes at a time of rapid energy industry change.
All of this means we can actively contribute to the energy industry as a thought leader, innovator, and service provider.
We are highly regarded in the energy market, winning Data Vendor of the year and a two-star accreditation from Best Companies in 2023 and Best Place to work in Data 2024. As you would expect from a business with ambitious growth plans, we are continually evolving and looking to the future, with investment in the business, its people, and your career.
The Company
The Company has experienced unprecedented growth over the past few years. We have a vast number of employees, and provide support to clients from all over the country.
Documents
Alternatively, please sign in with...
Published
Not Published
Closing
in X days
{Expiry}
Share Vacancy
Click on any of the buttons below to share this page!
You Have already applied for this vacancy, please go to your account to see your progress.
Privacy Policy
Recruitment Privacy Notice (compliant with GDPR) As part of our recruitment process ElectraLink Ltd collects and processes personal data relating to applicants and potential employees. We are committed to being transparent about how we collect, use and store data, as well as meeting our data protection obligations under the GDPR.
As defined by the General Data Protection Regulation (GDPR) Electralink Limited is the Data Controller and ultimately responsible for ensuring the data you provide is kept secure, processed correctly and that you understand your legal rights in relation to the data you provide.
The recruitment software we use via this website is supplied by IRIS Software Group Limited and they are defined as a Data Processor under the GDPR. They will only process your data in accordance with our instructions.
IRIS can be contacted at: 4th Floor Heathrow Approach, 470 London Road, Slough, England, SL3 8QY
For Data Protection enquiries, please contact the Help Desk at support@networxrecruitment.com
What data does ElectraLink Ltd collect?
ElectraLink Ltd collects a range of data and information about you, including:
your name, address and contact details (including email address and telephone numbers);
details of your qualifications, skills, experience and employment history;
information about your salary expectations (including current salary and benefit entitlements);
whether or not you have a disability for which the organisation needs to make reasonable adjustments during the recruitment process and potential employment; and
information about your entitlement to work in the UK.
ElectraLink Ltd may collect this information in a number of ways. For example, data may be contained within application forms, CVs, obtained from your passport or other identity documents, or collected through interviews or other forms of assessment.
We may also collect personal data about you from relevant third parties, such as references supplied by former employers or from LinkedIn. We will seek information from former employers only once a job offer has been made to you and will inform you that we are doing so in advance.
Data may also be stored in a number of different places, including on your application record, in HR management systems and on other IT systems (including email).
Why does ElectraLink Ltd process personal data?
ElectraLink Ltd needs to process data when progressing your application prior to entering into a contract with you. This may also be required to enable a contract to be entered into. In some cases, we need to process data to ensure that we are complying with our legal obligations, such as mandatory checks of a successful applicant’s eligibility to work in the UK prior to commencing employment.
We have a legitimate interest in processing personal data during the recruitment process and for keeping records of the process. Processing applicant data allows us to manage the recruitment process, to assess and confirm applicant suitability for each role, ultimately deciding to whom we offer employment. We may also need to process data from job applicants to respond to and defend against legal claims.
ElectraLink Ltd may process special categories of data, such as information about gender, ethnicity, sexual orientation, religion or belief in order to monitor recruitment statistics. We may also collect information about applicant disabilities to ensure that we can make reasonable adjustments for candidates who do have a disability; such information is processed to carry out our legal obligations and to exercise specific employment rights.
If your application is unsuccessful ElectraLink Ltd may keep your personal data on file in case there are future employment opportunities for which you may be suitable. We will ask for your consent before your data is retained for this purpose and you are free to withdraw your consent at any time.
We will store your application data for 6 months after the vacancy has closed. After this period, it will be fully anonymised.
How does ElectraLink Ltd protect data?
We take our data protection obligations very seriously at ElectraLink Ltd. We have internal policies and controls in place to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed by parties other than our employees in the proper performance of their roles.
For how long does ElectraLink Ltd keep data?
If your application for employment is unsuccessful at any stage in the process, we will hold your data on file for 6 (six) months after the end of the relevant recruitment process. If you agree to us keeping your personal data on file, we will hold your data on file for a further 6 (six) months for consideration of future employment opportunities. At the end of this period, or once your consent has been withdrawn if sooner, your data is deleted or destroyed.
You will be asked when you submit your CV whether you give us consent to store your data for the full 12 months in order to be considered for alternative positions. If your application for employment is successful, personal data gathered during the recruitment process will be transferred to your HR file (electronic and paper based) and retained throughout the course of your employment. The periods for which your data will be held thereafter are in accordance with the GDPR.
Who has access to data?
Your information may, from time to time, be shared internally for the purposes of our recruitment process.
This may include members of the HR and recruitment team, interviewers, managers in the relevant business area and IT staff if access to the data is necessary for the performance of their respective roles.
Your data will not be shared with third parties unless you are a successful applicant and we make you an offer of employment. In this case, we will then share your data with former employers in order to obtain references for you and employment background check providers to conduct necessary background checks.
What if you do not provide personal data?
You are under no statutory or contractual obligation to provide personal data to ElectraLink Ltd during the recruitment process. However, if you choose not to provide the information requested, we may not be able to process your application properly or at all.
We use some automated screening tools as part of this application process. The answers you provide to one or more of the questions (excluding any special categories/equal opportunity questions) may result in your application being automatically declined. This technology is used to help us manage the high volume of applications we receive and can assure applicants the same outcome would occur if we manually reviewed your application. The reason for the decline will be made available to you in your candidate account.
Your rights
As a data subject, you have a number of enforceable rights:
to access and obtain a copy of your personal data on request;
to require ElectraLink Ltd to change incorrect or incomplete data;
to require ElectraLink Ltd to delete or stop processing your data, for example where the data is no longer necessary for the intended purposes of processing; and
to object to the processing of your data where ElectraLink Ltd is relying on its legitimate interests as the legal ground for processing.
If you would like to exercise any of your rights as above, please contact us on privacymanager@electralink.co.uk
If you do not consider that ElectraLink Ltd has complied with your relevant data protection rights, you can also make a complains to the Information Commissioner’s Office (ICO).
Social Login
To continue creating your account, please read the privacy policy and tick the box below
To complete creating your profile with , please read and agree with the privacy policy.
The email used for your profile is not a valid company domain name. In order to
continue to create your profile with you will need to select a profile which uses a company authorised email address.
Cookie Preference Centre
Learn more about what each cookie category does and choose your settings
Cookie policy
Strictly Necessary
Name
__RequestVerificationToken
Duration
Session
Description
Anti-forgery Token
Name
ASP.NET_SessionId
Duration
Session
Description
General purpose platform session cookie, used by sites written with Miscrosoft .NET based technologies. Usually used to maintain an anonymised user session by the server.
Name
NTX_Cookie_Preferences_Live
Duration
6 Months
Description
Your cookie preferences
Performance / Analytics
Name
_ga
Duration
2 Years
Description
This cookie name is associated with Google Universal Analytics - which is a significant update to Google's more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session and campaign data for the sites analytics reports. By default it is set to expire after 2 years, although this is customisable by website owners.
Name
_gat
Duration
A few seconds
Description
This is a pattern type cookie set by Google Analytics, where the pattern element on the name contains the unique identity number of the account or website it relates to. It appears to be a variation of the _gat cookie which is used to limit the amount of data recorded by Google on high traffic volume websites.
Name
_gid
Duration
1 Day
Description
This cookie name is asssociated with Google Universal Analytics. This appears to be a new cookie and as of Spring 2017 no information is available from Google. It appears to store and update a unique value for each page visited.
Name
NetworxTracking_AdvertClick
Duration
90 Days
Description
Used for tracking if the candidate has already clicked the advert - used for analytics
Name
NetworxTracking_AdvertLoad
Duration
90 Days
Description
Used for tracking if the candidate has already loaded the advert - used for analytics
Functional Cookies
Name
ApplicationIntroductionID
Duration
90 Days
Description
Check to see if the candidate has already read the introduction for the Application
Name
FavouriteVacancies
Duration
30 Days
Description
Store any jobs the candidate has flagged as a favourite