
Security and Risk Management Lead - (Outside IR35) at Sword Group. Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving real transformation change within our clients. We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data and business applications. We have a passion for using technology to solve business problems, working in partnership with our clients to help in achieving their goals.. About the role:. We’re supporting the delivery of a critical infrastructure transformation programme designed to establish secure, resilient platforms across converged IT and Operational Technology (OT) environments. This multi-year programme is governed by the highest standards of cyber assurance and regulatory scrutiny.. As the . Security & Risk Management Lead, . you willact as the programme’s senior security authority. You will define and own the security vision, risk posture and regulatory compliance strategy, embedding a Secure by Design approach across every lifecycle phase — from architecture through to retirement.. Operating at board level, you’ll ensure security considerations shape delivery scope, inform design decisions, and meet evolving regulatory expectations. Your work will be integral to establishing a compliant, assured, and future-ready cyber operating model.. As the Security & Risk Management Lead, you will:. . Serve as the executive security owner for the programme, accountable for cyber posture, risk exposure, and regulatory alignment. . Lead the adoption and enforcement of a . Secure by Design (SbD). framework across architecture, build, operations, and decommissioning. . Influence the Programme Board, shaping strategic delivery, scope, and assurance outcomes. . Ensure alignment with key regulatory and cyber governance frameworks, including:. . . NCSC CAF (Enhanced Profile). . Ofgem NIS CAF Overlay. . NIS Regulations (UK). . ISA/IEC 62443 series. . ISO/IEC 27001, 31010, and NIST CSF. . . Represent the organisation in regulatory discussions, audits, and cybersecurity working groups. . Define and govern the security architecture using ISA/IEC 62443 zones and conduits methodology. . Provide assurance of technical controls across Security Levels SL1 to SL4, validating patterns such as segmentation, RBAC, and incident containment. . Lead cyber risk management activities including threat modelling and formal risk analysis (Bow-Tie, Attack Trees, Swiss Cheese, HAZOPs). . Own the delivery of the Cybersecurity Requirements Specification (CRS) for all programme systems. . Oversee end-to-end cyber risk posture management across the service lifecycle, from assessment and design to decommissioning. . Collaborate with ITIL-aligned service functions and ensure the Target Operating Model integrates cybersecurity as a pillar of reliability and resilience. . . Extensive experience in a senior cyber leadership role (CISO, SRO, or equivalent), ideally within regulated or Critical National Infrastructure (CNI) sectors. . Deep knowledge of regulatory and assurance frameworks such as ISA/IEC 62443, NCSC CAF, NIS Regulations, NIST CSF, and ISO/IEC 27001. . Proven track record of leading secure digital transformation across complex IT/OT environments. . Strong understanding of enterprise security architecture, Secure by Design practices, and lifecycle risk management. . Exceptional communication and stakeholder engagement skills, with confidence navigating regulatory, technical, and executive domains. . It would be great if you also had:. . CISSP, CISM, CRISC or equivalent. . TOGAF or SABSA enterprise architecture credentials. . IEC 62443 Cybersecurity Expert or Practitioner certification. . Familiarity with ITIL, ISO 27019, and NCSC guidance for OT & ICS. . Company Location: United Kingdom.