Job Description
Provide technical leadership and delivery assurance across the Cyber and Security portfolio.
Act as the senior technical authority and delivery lead for agreed cyber initiatives.
Ensure cyber programmes and projects are securely designed, effectively mobilised, governed and delivered in line with Portsmouth Water’s risk appetite and regulatory expectations.
Support AMP8 cyber initiatives by providing technical direction across design, build, delivery, and transition into business-as-usual operations.
Lead and coordinate CAF and eCAF readiness activity across the cyber portfolio.
Interpret and map CAF/eCAF control requirements, define remediation activity and establish an evidence-led assurance approach.
- Support the development of a clear technical view of CAF/eCAF target state, control gaps, priority remediation items, and assurance expectations.
- Provide technical input into the AMP8 cyber roadmap, including sequencing, high-risk dependencies, critical milestones, and delivery priorities.
- Work in partnership with project management and transformation teams to shape delivery sequencing, manage dependencies and support controlled delivery.
- Ensure cyber initiatives are technically designed and implemented in line with governance, risk, and compliance, as well as regulatory obligations.
- Embed required controls into solution design, delivery activity, and operational handover.
- Provide technical oversight of suppliers and third parties supporting cyber initiatives.
- Support supplier mobilisation, validate technical deliverables and acceptance criteria, and ensure assurance and security obligations are met.
- Act as a senior technical point of coordination across IT Transformation, Architecture, Operations, and business stakeholders.
- Align technical priorities, manage trade-offs, and escalate design, delivery, or assurance decisions when required.
- Provide technical input on portfolio-level risks, dependencies, and constraints, highlighting cyber, resilience, and regulatory impacts.
- Support senior decision-making by providing clear, concise, and credible advice on cyber priorities, trade-offs, delivery risk, and investment decisions.
- Support structured transition of cyber capabilities into operational teams, ensuring ownership, support models and processes are clearly defined.
- Contribute to effective change management and adoption, ensuring cyber initiatives are understood, adopted, and embedded across technology, process, and people.
- Maintain appropriate documentation and evidence-based assurance mechanisms across the cyber portfolio.
- Work independently as a subject matter expert, determining the day-to-day approach, stakeholder engagement and delivery rhythm required to achieve agreed outcomes.
Qualifications
- Relevant education or industry-recognised certifications in cybersecurity, information security, technology delivery, risk management, programme delivery, or a related discipline.
- Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, NCSC CAF-related experience, Security+, CySA+, PRINCE2, MSP, Agile or equivalent professional experience.
- Experience in regulated sectors, water, utilities, CNI or operationally critical environments would be highly beneficial.
Essential Skills
- Strong experience leading or assuring cyber delivery across complex portfolios, programmes, or transformation environments.
- Strong understanding of cyber governance, risk, compliance, and assurance in regulated environments.
- Practical knowledge of CAF and/or eCAF readiness, control interpretation, evidence management, and remediation planning.
- Ability to provide technical leadership across cyber initiatives from mobilisation through to transition into BAU.
- Ability to define and validate cyber scope, priorities, dependencies, risks, and control expectations.
- Strong understanding of security architecture, technical assurance, and cyber control implementation.
- Ability to translate regulatory and risk requirements into practical delivery activities and measurable outcomes.
- Experience providing technical input into cyber roadmaps, delivery plans, milestone sequencing, and portfolio-level decision-making.
- Strong supplier and third-party oversight experience, including mobilisation, deliverable review, dependency management, and acceptance criteria.
- Ability to work with architecture, operations, transformation, project management, and senior leadership teams.
- Strong stakeholder management skills, including the ability to influence senior stakeholders and manage trade-offs.
- Ability to produce clear written outputs, technical assurance material, executive briefings, and decision papers.
- Strong delivery discipline, with the ability to work independently and progress outcomes without day-to-day supervision.
- Ability to support sustainable transition into business-as-usual operations, including ownership, support models, process definition, and operational readiness.
Experience
- Proven experience in a senior cyber delivery, cyber assurance, cyber programme leadership, or cyber technical authority role.
- Experience supporting cyber portfolios or transformation programmes in regulated or operationally critical environments.
- Experience with CAF, eCAF, NIS, ISO 27001, NIST CSF or equivalent cybersecurity frameworks.
- Experience in defining technical priorities, roadmaps, control gaps, and remediation activities.
- Experience supporting regulatory, audit or assurance readiness activity.
- Experience working with senior IT, cyber, architecture, operations, and transformation stakeholders.
- Experience managing cyber risks, dependencies, constraints and delivery trade-offs at portfolio or programme level.
- Experience overseeing suppliers, third parties or delivery partners in the implementation of cyber capabilities.
- Experience supporting transition into BAU, including operating models, handover planning, support arrangements, and service ownership.
- Experience in the water sector, utilities, CNI or AMP8-related environments would be advantageous.
- Desirable Skills and Experience:
- Experience working with UK water sector regulatory expectations, including CAF/eCAF or NIS-aligned assurance.
- Experience supporting AMP8-related cyber, digital, IT or resilience programmes.
- Experience operating as a senior technical partner to CIO, Head of Cyber, Head of IT Transformation or equivalent leadership roles.
- Experience developing cyber portfolio views, technical roadmaps, assurance dashboards, or executive-level cyber reporting.
- Experience supporting cyber capability development, supplier contract mobilisation, or strategic security platform implementation.
- Experience embedding evidence-led assurance mechanisms across cyber delivery.
- Experience supporting organisational change, adoption, and cyber capability transition.
- Experience working in Microsoft Teams and Microsoft Office environments for secure collaboration, reporting, and evidence management.
- Experience handling confidential or sensitive client information in line with client security, data protection, and NDA requirements.
Thank you for your interest in this role. Please also share your CV at Vedika@lsarecruit.co.uk and if suitable, we will get in touch with you to discuss further.