About this role
Role OVO-View
Team: Enterprise Security, Governance, Risk & Compliance (GRC)
*Location:***Hub Based - Hybrid for all
Experience: Expert
*Working pattern:***Full-Time
*Reporting to:*Chief Information Security Officer
Sponsorship: Unfortunately we are unable to offer sponsorship for this role.
*This role in 3 words:*Engaging. Visionary. Enabler.
Top 3 qualities for this role: Leadership. Communication. Resilience.
Where you'll work
Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person.
You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life.
Everyone belongs at OVO
At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us.
Teamworking for the planet
Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how:
Reporting to the CISO this role is part of the Enterprise Security management team where you'll deliver risk-led security focused on what matters most to the business.
We are hiring innovators, people with the vision to cut through complexity, to streamline, and deliver simplicity. We encourage collaboration, and want to instill a sense of ownership and pride in our Enterprise Security and GRC teams, as well as the stakeholders they engage with. This role is about leading change, reducing risk, and continuous improvement.
This role in a nutshell
OVO is seeking an experienced GRC Principal to provide leadership, compliance continuity, and strategic assurance. Reporting CISO you will balance day-to-day compliance and assurance stability, with continuous improvement of our risk levels and risk management practices.
As an Operator of Essential Services under NIS regulations, OVO requires a seasoned GRC professional capable of managing a complex regulatory landscape while providing hands-on guidance to a newly formed security GRC team.
You will
- Provide day-to-day leadership to the security GRC function, ensuring clear direction and role clarity.
- Develop and manage strong stakeholder relationships (business) and reporting.
- Be a thought leader connecting security teams to wider issues of risk.
- Deliver GRC vision and people management.
- Manage and track security risks within the corporate GRC framework.
- Manage a complex regulatory environment.
- Provide continuity and continuous improvement for our Information Security Management System (ISMS), streamlining and simplifying existing processes.
- Focus is on the now, but consider the horizon: navigating shifting external risks and a complex regulatory landscape.
- Lead solution design and delivery of enterprise compliance initiatives collaborating with Security Architecture and Assurance and the broader Security teams (ISO 27001 certification and Cybersecurity Assessment Framework).
- Collaborate with GRC Security Architecture and Assurance to enable and track risk-reduction, focused security control improvement through automation and assurance.
- Lead the preparation for board level risk updates, translating technical risk into executive-level insights.
- Review the "Three Lines of Defence" model to ensure clear delineation between 1st-line operations and 2nd-line oversight.
- Collaborate and consult with risk management, compliance and DPO functions to ensure alignment.
- Act as:
- Compliance, controls and audit partner to business.
- Legal and regulatory partner to business.
Your team will collaborate with business, Tech and security to deliver:
- Policies and standards (top level/ISMS).
- Communications and engagement.
- Third party risk management (compliance/legal/contractual).
- Security assurance and audit-readiness against controls.
- Horizon scanning legal, regulatory and compliance.
Your key outcomes will be
- Unified governance: ownership of a living, breathing ISMS that satisfies multiple regulatory requirements without redundant effort.
- Strategic reporting: delivering clear risk reporting to leadership that enables fast, informed business decisions.
- Cultural transformation: engaged stakeholders and a measurable reduction in "human-factor" risk, moving beyond "tick-box" training to a high-engagement security awareness program.
- Cross-functional partnerships: seamless collaboration with other teams such as Risk, Business Continuity, and Fraud to ensure a straightforward experience for OVO regarding compliance.
Systems
- GRC Platforms: for centralising the risk register and Common Control Framework (CCF).
- Learning Management Systems (LMS): to drive and track the awareness program.
- Collaboration and Workflow: management and task tracking.
- Reporting Tools: to visualise KRIs and compliance health tracking.
You'll be successful in this role if you…
- Can think strategically as well as pragmatically.
- Can communicate effectively across different levels and areas of a business (business, risk, Tech, security).
- Are adept at building stakeholder relationships.
- Can cut through complexity to bring clarity and simplicity.
- Are comfortable with and bring clarity to ambiguity.
- Have experience working in a fast-evolving business.
- Are in your element and comfortable working alongside agile, Tech-driven teams.
- Able to coach and train others in identifying and delivering on security risk and regulatory requirements.
- Developed common control frameworks that consider multiple compliance and regulatory requirements.
- Have experience with managing security GRC teams and risk through mergers and acquisitions.
- Brought cohesion and purpose to newly integrated teams.
- You understand that security can break a business if done ineffectively and seek the middle-ground between compliance that protects OVO while enabling it to move fast and continue to grow.
- You can explain a complex technical risk to a non-technical audience in a way that makes them understand it and how they can help fix it.
- You build impactful narratives that make employees care and see their place in the security culture.
- You think in frameworks and processes, you don't just solve a problem once, you assist in building the systems that prevent it from reoccurring.
Essential
- Regulated Environments: Proven experience as a Security GRC or Risk Manager within UK regulated sectors (e.g., Utilities, Financial Services, or Critical National Infrastructure).
- Regulatory Fluency: Understanding of NIS regulations, GDPR, and Ofgem requirements, as well as the forthcoming Cyber Security and Resilience Bill.
- Framework Expertise: Practical experience operating within a Three Lines of Defence model.
- Executive Presence: The ability to engage confidently with Board-level stakeholders regarding risk appetites and strategic trade-offs.
- Agility: A "player-coach" mindset—equally comfortable in strategic boardrooms and technical operational reviews.
- Comfortable with Ambiguity: you can navigate shifting regulatory landscapes and provide a steady structure for the team.
Desirable
- Experience managing or restructuring security functions during organisational change.
- Experience with mergers and acquisitions.
- Experience managing risk within agile cloud-native technology estates.
Let's talk about what's in it for you
We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission.
You'll be eligible for an on-target bonus of 15%.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background — match score 90/100
- Financial crime & fraud
- Incident command & response
- Risk & threat assessment
- Working to legislation & regulation
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |