Rodeo
Get started

Good Energy

Information Security GRC Lead

Chippenham
£50k – £60k/yr
Posted about 20 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Information Security GRC Lead

Application Deadline: 4 October 2026
Department: Information Governance
Employment Type: Permanent - Full Time
Location: Chippenham, Wiltshire
Reporting To: Carrie Coles
Compensation: £50,000 - £60,000 / year

Description

No day will be the same - here are some of the highlights

Reporting into the Head of IGRC, this role provides information security GRC oversight, coordination and assurance across IT security, resilience and control governance, working closely with Technology Teams who retain ownership of technical implementation and day-to-day system administration.

We are seeking a practical and technically capable Information Security GRC Lead to help strengthen Good Energy’s security and control environment. This role will act as a key link between IGRC and Technology Teams; identifying security and compliance requirements, coordinating activity, providing guidance and challenge, evidencing controls, and tracking remediation. The role is not expected to perform day-to-day technical administration but will need sufficient technical understanding to work effectively with the Technology Teams who implement and operate the controls.

Key Responsibilities

  • IT Security Governance: Maintain oversight of IT security risks, controls, policies and standards, helping define what good control looks like and working with Technology Teams to ensure ownership, implementation and evidence are clear.
  • Security Control Assurance: Coordinate and evidence regular assurance over information technology security controls across people, process, premises and technology, working with Technology Teams to validate control operation, escalate gaps and track remediation.
  • Information Security Risk and Compliance: Support information security risk and compliance activity by interpreting relevant standards and good practice frameworks, translating requirements into practical actions, and working with Technology Teams to support proportionate implementation.
  • Security Incident Support: Support security incident response by helping assess governance, risk and compliance impacts, coordinating evidence, supporting root cause analysis and ensuring lessons learned are tracked with the relevant technical owners.
  • IT Disaster Recovery and Resilience: Coordinate oversight and challenge of IT disaster recovery arrangements, working with Technology Teams to maintain plans, schedule testing, evidence outcomes, identify dependencies and track remediation of weaknesses.
  • IT Change Management: Support effective IT change governance, including chairing or supporting the Good Energy Change Advisory Board, and ensuring security and resilience impacts are considered and that technical owners complete agreed actions before implementation where required.
  • PCI-DSS Compliance: Coordinate and support PCI-DSS control activity, evidence gathering, control testing and remediation tracking where technology controls are in scope.
  • Penetration Testing and Vulnerability Management: Coordinate penetration testing and support vulnerability management oversight, working with Technology Teams and third parties to risk assess findings, agree ownership and monitor remediation without taking ownership of technical remediation activity.
  • Technology Policy and Awareness: Develop, review and maintain technology security policies, standards and guidance, supporting employee awareness of key security responsibilities.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What you'll need to succeed

As the Information Security GRC Lead, you will be a proactive, practical and technically aware individual who can work confidently between IGRC, Technology Teams and wider business teams.

You will be able to translate technical security concepts into clear business language, provide proportionate guidance and challenge, and coordinate practical security activity without needing to be the person who directly configures or administers the underlying technology.

You will be comfortable working independently, influencing across teams and maintaining focus on practical risk reduction, strong evidence and continuous improvement.

Essential

  • Good understanding of information technology security, information security risk and control management.
  • Experience supporting, coordinating or assuring IT security controls, vulnerability management, incident response, IT disaster recovery or IT change governance, ideally while working alongside technical teams who own implementation.
  • Awareness of recognised security standards or frameworks such as ISO27001, Cyber Essentials, NCSC CAF and PCI-DSS.
  • Strong verbal and written communication skills, with the ability to explain technical matters clearly to non-technical audiences.
  • Demonstrable attention to detail and ability to produce clear, evidence-based documentation.
  • Ability to interpret technical workflows, risks and controls and translate them into practical procedures, policies, or assurance activity and clear actions for technical owners.
  • Confident working with stakeholders across technology, governance and business teams to agree actions and track remediation.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Desirable

  • Experience working in a regulated sector, ideally energy, with exposure to Smart Metering security obligations, governance or assurance requirements.
  • Experience coordinating CREST-accredited penetration testing, reviewing findings, agreeing remediation plans and tracking closure with technical owners.
  • Relevant qualification or certification such as ISO27001 Foundation or Implementer, CISMP, SSCP, Security+, CISA or equivalent experience.
  • Working knowledge of data protection requirements where they intersect with technology security controls.

Hybrid working explained: When and where you’ll be in the office

Our office is based in Chippenham, Wiltshire. For this role, we're looking for candidates who can come in to our Chippenham office, once a week.

We offer both formal and informal flexible working options. Full-time hours are 37.5 per week, Monday to Friday.

The office is fully accessible, allowing everyone to participate fully in their working lives regardless of any mobility challenges. We promote work-life balance and flexibility through hybrid working, which combines both remote and office work.

Benefits you can rely on

  • Great allowances for hybrid working:
    • 🏡 £500 work from home allowance - an annual allowance paid monthly alongside your salary to support with working from home costs.
    • 🚆 £500 travel allowance - an annual allowance paid monthly alongside your salary to support with travelling to work costs.
    • 📖 £500 annual development allowance: to spend on your chosen development area, whether that’s in your current role, or future roles.
    • 🎁 15% annual bonus: company-wide bonus scheme designed to reward collective teamwork and delivery of results across the whole business.
  • Holiday: 25 days annual leave, a day off for your birthday, additional days leave for long service, plus bank holidays. You’ll also have the option to buy additional leave, allowing for a better work-life balance.
  • 💸 Ethical Pension with Aviva: Good Energy offers an ethical pension plan provided by Aviva, with employer-matched contributions up to 7.5% of your base salary.
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

Chippenham, England, United Kingdom

Sign up to applySee more jobs like this