Overview
Octopus Energy started with a bold idea: to build Britain’s first truly digital energy supplier. By combining world-class tech with people who care about customers and driving the renewables transition, we became Britain’s largest energy supplier. We’re scaling fast and building the next generation of products to accelerate the green energy transition. We’re enabling our global businesses to roll out learnings, products and experiences from the UK worldwide.
At Octopus Tech, you’ll have real ownership, variety, and the chance to shape products that make a tangible difference in people’s lives – lowering bills, enabling greener living, and delivering experiences customers genuinely love. You’ll work side by side with teams across marketing, operations and data, and see the impact of your work in the real world, fast.
We are expanding our Cyber and Information Security team at Octopus Energy Group. We are looking for an ambitious, knowledgeable, and experienced Information Security Lead to join our team, grow with the company, and help ensure we continue to do so in a secure and safe way.
You will be a key partner in defining what Security is at Octopus Energy Group. We will shape this team to provide a world-class support service to our employees, building our way out of problems and undertaking transformational organisational change.
You’ll be primarily supporting our Octopus Energy Group services, while working with various Group Subsidiaries to expand our capabilities and develop creative solutions to business challenges and opportunities to continually improve our services.
What you’ll do
- Have ownership of a functional team within the Cyber Security Team, working closely with the Head of Cyber Security to define strategic objectives and team direction
- Manage team priorities and ensure initiatives are completed within deadlines
- Collaborate regularly and effectively with the rest of the Cyber Security Team to deliver outcomes
- Lead delivery of major initiatives on clear timelines
- Build a strong culture of open communication where teammates can ask questions without fear, promoting a positive and inclusive team environment
- Line-manage a team of Information Security Analysts in the same or similar timezone
- Set performance expectations and goals for team members
- Regularly review individual and team performance, offering actionable insights and constructive feedback to support and grow team members
- Support team delivery and promote the automation of manual process wherever sensible/feasible
- Support the implementation of security processes and requirements
- Stay abreast of emerging security threats, technologies, and industry trends to continuously enhance the organisation’s security strategy
- Lead maintaining and improving our Information Security Management System (ISMS) by taking a tech-first approach and using automation where possible
- Promote a positive security culture and raise awareness through training and other initiatives
- Provide security advice and guidance to the wider technical team
- Liaise with stakeholders in relation to security issues and providing remediation/improvement recommendations
What you’ll have
- Proven experience in a leadership role within Information Security or closely related field
- A passion for security, a drive to make things better by harnessing technology
- Experience in, or knowledge of, automating GRC and other security processes to reduce manual work (policy as code, low/no code tools or GRC tooling)
- Excellent communication, with a focus on doing this asynchronously
- Experience of mentoring and coaching a team to perform at a high level
- Strong analytical and problem-solving skills, with the ability to identify and mitigate security risks
- A good understanding of information security principles and the ability to communicate this to non-experts
- Experience producing or supporting the delivery of security awareness programs in different business environments
- The ability to demonstrate the relevance and importance of security controls and how they drive real business value
- Knowledge of industry and regulatory security standards, such as ISO 27001, SOC2, and GDPR
Ideally, you will have experience in multiple areas mentioned (or others), but we’re not expecting you to be an expert in all areas!
What will help
- The ability to challenge and expand our thinking around GRC engineering
- Security certifications (any of the famous abbreviations)
- Security qualifications (e.g. apprenticeships or degrees)
- Experience working in organisations that maintain ISO 27001 and/or SOC 1 and SOC 2 type II certifications
- Experience working in a global organisation and managing security requirements in multiple regions
- A wider understanding of technology, especially AWS (or other CSPs) and SaaS services
- A background in a technical role or technical knowledge through education or training
- Knowledge of the MITRE ATT&CK framework
Benefits
- Salary: discussed on call with recruiters to align with experience
- Unique culture with autonomy and co-owners; recognised as a great place to work
- UK perks hub: Octopus Employee Benefits
We offer flexible hybrid working. Don’t let location discourage you from applying if you can’t make it to an office! …
