About the Role
OVO is seeking an experienced GRC Principal to provide leadership, compliance continuity, and strategic assurance. Reporting to the CISO, you will balance day-to-day compliance and assurance stability with continuous improvement of our risk levels and risk management practices. As an Operator of Essential Services under NIS regulations, OVO requires a seasoned GRC professional capable of managing a complex regulatory landscape while providing hands-on guidance to a newly formed security GRC team.
Responsibilities
- Provide day-to-day leadership to the security GRC function, ensuring clear direction and role clarity.
- Develop and manage strong stakeholder relationships and reporting.
- Be a thought leader connecting security teams to wider issues of risk.
- Deliver GRC vision and people management.
- Manage and track security risks within the corporate GRC framework.
- Manage a complex regulatory environment.
- Provide continuity and continuous improvement for our Information Security Management System (ISMS), streamlining and simplifying existing processes.
- Navigate shifting external risks and a complex regulatory landscape.
- Lead solution design and delivery of enterprise compliance initiatives collaborating with Security Architecture and Assurance and the broader Security teams.
- Collaborate with GRC Security Architecture and Assurance to enable and track risk-reduction, focused security control improvement through automation and assurance.
- Lead the preparation for board level risk updates, translating technical risk into executive-level insights.
- Review the "Three Lines of Defence" model to ensure clear delineation between 1st-line operations and 2nd-line oversight.
- Collaborate and consult with risk management, compliance and DPO functions to ensure alignment.
- Act as a compliance, controls and audit partner to business.
- Act as a legal and regulatory partner to business.
- Deliver policies and standards (top level/ISMS).
- Deliver communications and engagement.
- Deliver third party risk management (compliance/legal/contractual).
- Deliver security assurance and audit-readiness against controls.
- Deliver horizon scanning legal, regulatory and compliance.
Requirements
- Proven experience as a Security GRC or Risk Manager within UK regulated sectors (e.g., Utilities, Financial Services, or Critical National Infrastructure).
- Understanding of NIS regulations, GDPR, and Ofgem requirements, as well as the forthcoming Cyber Security and Resilience Bill.
- Practical experience operating within a Three Lines of Defence model.
- Ability to engage confidently with Board-level stakeholders regarding risk appetites and strategic trade-offs.
- A "player-coach" mindset—equally comfortable in strategic boardrooms and technical operational reviews.
- Ability to navigate shifting regulatory landscapes and provide a steady structure for the team.
- Experience managing or restructuring security functions during organisational change (Desirable).
- Experience with mergers and acquisitions (Desirable).
- Experience managing risk within agile cloud-native technology estates (Desirable).
Skills
- Leadership
- Communication
- Resilience
- Strategic thinking
- Pragmatism
- Stakeholder relationship building
- Clarity and simplicity
- Comfort with ambiguity
- Experience in fast-evolving businesses
- Working with agile, Tech-driven teams
- Coaching and training
- Developing common control frameworks
- Managing security GRC teams and risk through mergers and acquisitions
- Bringing cohesion and purpose to newly integrated teams
- Explaining complex technical risk to non-technical audiences
- Building impactful narratives
- Thinking in frameworks and processes
- GRC Platforms
- Learning Management Systems (LMS)
- Collaboration and Workflow tools
- Reporting Tools
Location
- Hub Based - Hybrid
Work Type
- Full-Time
- Hybrid
Experience Level
- Expert
Salary/Compensations
- On-target bonus of 15%
- 9% Flex Pay on top of salary (4% auto-enrolled into pension, 5% flexible)
Benefits
- 34 days of holiday (including bank holidays)
- Healthcare cash plan or private medical insurance
- Critical illness cover
- Life assurance
- Health assessments
- Gym membership
- Travel insurance
- Workplace ISA
- Will writing services
- Dental insurance
- Extra holiday buying
- Discount dining
- Home & tech loans
- Give-as-you-earn donations
- Up to £400 towards any OVO Energy plan
- Discounts on solar, smart thermostats and EV chargers
- Ultra-low emission car leasing deals
- Cycle to work scheme
- Public transport season ticket loans
- Belonging Networks
About the Company
- OVO is on a mission to solve one of humanity's biggest challenges, the climate crisis.
- Everyone belongs at OVO.
- We need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us.
- Everything we do here spins around Plan Zero.
Equal Opportunity
- We need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us.
- We’d be thrilled if you tick off all our boxes, yet we also believe it’s just as important we tick off all of yours. And if you think you have most of what we’re looking for but not every single thing, go ahead and hit apply. We’d still love to hear from you!
- If you have any additional requirements, there’s a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
