Hiring.Camp

Cyber Risk & Assurance Analyst

Southernwater

·

Jul 9, 2026

Location
Durrington Head Office, United Kingdom
Workplace
Hybrid
Clearance
Required
Closing date
Jul 23, 2026
Source
Workday

Description

Closing Date

2026-08-28

Job Title: Cyber Risk & Assurance Analyst

Location: Durrington / Hybrid

Contract Type: Permanent

Hours: 37 hours per week

Salary: from £55k

About the role

This is a fantastic opportunity to join Southern Water’s Cyber Risk & Assurance team, the organisation’s second line of defence within the wider Cyber Security function. As a Cyber Risk & Assurance Analyst, you’ll play a central role in helping the business understand, manage and reduce cyber risk across critical operations.

You’ll be responsible for developing and improving cyber risk insights in your area of specialism, driving process and tooling enhancements, and supporting stakeholders across Technology, Legal and the wider business. This is a role for someone who enjoys tackling complex problems, breaking them down into actionable solutions, and collaborating with a wide range of experts.

You’ll also act as a trusted advisor helping colleagues understand cyber threats, risks and controls, and supporting the wider team in embedding strong cyber risk management practices across Southern Water.

What you will be responsible for:

You will conduct complex cyber risk assessments, strengthen key controls, deliver clear risk insights, and drive improvements across cyber domains — all while building collaborative relationships across Technology, Security, Legal and the business.

Key Responsibilities

  • Maintain an up‑to‑date understanding of the cyber threat landscape, relevant regulations (including NIS1/NIS2 and GDPR), and emerging risks.
  • Lead, plan and perform complex cyber risk assessments aligned to industry‑recognised frameworks, testing the design and effectiveness of cyber controls.
  • Produce high‑quality risk assessment reports with clear, actionable conclusions that support timely risk‑based decision‑making.
  • Identify and deliver improvements across domains such as identity & access management, application security, endpoint security, and network security.
  • Work closely with stakeholders across Security, Technology, Legal, Internal Audit and the wider business to assess control gaps, prioritise remediation actions and track progress to completion.
  • Build strong working relationships across teams to influence, support and strengthen cyber risk management practices.
  • Drive process improvements and enhancements across the Cyber Risk & Assurance function.

Additional requirements specific to the role

  • Will work closely with both technical teams and non‑technical stakeholders, requiring an ability to communicate complex concepts clearly.
  • Must be comfortable operating in an environment with regulatory, operational and cyber security obligations.
  • Occasional engagement with internal or external audit teams may be required.

What you’ll bring to the role:

Essential

  • Degree‑level education or equivalent experience.
  • Strong knowledge of cyber security and information security control best practice.
  • Proven experience in cyber security, risk management or security assessment (5+ years, or advanced degree with 3+ years).
  • In‑depth understanding of key frameworks such as NIST (800‑37, 800‑30, 800‑53), ISO 27001/27005, SOC 2, PCI or MITRE ATT&CK.
  • Solid understanding of cloud models, application security, vulnerability and patch management.
  • Experience in regulated and/or unionised environments.
  • Excellent communication skills with the ability to simplify complex findings for senior management.
  • Strong attention to detail and a proactive, positive, innovative mindset.

Desirable

  • GRC or security certifications (e.g., CISSP, CISM, CRISC, CISA, GCFE, GSEC, CCSP).
  • Experience with cyber risk modelling (e.g., CyberCube, RMS, Cyence).
  • Hands‑on experience with frameworks such as ISO 27001, NIST CSF, NCSC CAF or CIS Controls.
  • Understanding of ICS/OT environments.

Southern Water is at the forefront of transforming Britain’s water industry, investing significantly to enhance resilience, sustainability, and service excellence. With £7.8bn planned investment for 2025-30, this is an unparalleled opportunity to join a business committed to delivering a generational shift in the way water services are managed. 

You will be joining at a time of significant change, working alongside a highly skilled leadership team with a clear vision for the future. We offer an environment where senior professionals can make a meaningful impact, influence major strategic decisions, and drive long-term value creation .

At Southern Water, we believe diverse perspectives drive innovation. If you’re passionate about making a positive impact and think you can bring value to our team, we’d love to hear from you—even if you don’t tick every box. Your unique skills and experiences could be exactly what we need.

If this role isn’t quite what you’re looking for but are keen to be contacted about opportunities at Southern Water, you can register your details here: Introduce Yourself (myworkdaysite.com- Introduce Yourself

Our Commitment to Diversity 

We welcome applicants from all backgrounds, identities, and experiences. We do not discriminate based on race, ethnicity, gender, sexual orientation, age, disability, religion, or any other protected characteristic. If you need reasonable adjustments during the recruitment process, please let us know. 

Additional information: 

In line with Southern Water’s security requirements, successful candidates will be required to provide evidence of their identity, eligibility to work in the UK, criminal record check (DBS) and verification of their employment and/or education history for the past three years.  

Appointment to this role is subject to the successful completion of all preemployment checks, including security vetting.  

Please note that if a candidate does not meet the required security standards or fails to pass the vetting process, Southern Water reserves the right to withdraw the offer of employment. Some positions may also require higher levels of security vetting, which may involve providing additional documentation. 

#LI-HM2

#LI-Hybrid 

Skills

SOCRisk ManagementSOC 2GDPRISO 27001CISSP

Similar Jobs

30

Lead, Third Party Cyber Risk & Analysis

Capitalone · McLean, VA, United States of America +1

Yesterday

Security Cyber Risk & Compliance Specialist - on-site Hampshire

DXC Technology · UK841 - GBR Client Site (UK841), United Kingdom · Onsite

Yesterday

Manager, Digital Risk & Cyber

Baringa · London, United Kingdom

2 days ago

OT Cyber Risk Specialist III

Jabil · USA - Remote, United States of America · Remote

2 days ago

Associate, Cyber Risk

Kroll · United Kingdom, GB

3 days ago

Underwriting Territory Manager – Cyber Risk

Great American Insurance Group · NJ Work at Home, United States of America +22 · Remote

3 days ago

Senior Associate, Cyber Risk & Analysis| Retail Bank

Capitalone · McLean, VA, United States of America +1

3 days ago

Senior Associate - Cyber Risk & Analysis, Technology Audit

Capitalone · McLean, VA, United States of America +4

3 days ago

Consultant - Cyber Risk Consulting

Mmc · Sydney - Barangaroo, Australia +1 · Hybrid

3 days ago

IT and Cyber Risk Auditor Principal

GDIT · USA MD La Plata - Customer Proprietary (MDC055), United States of America

5 days ago

IT and Cyber Risk Auditor Principal

Gdit · USA MD La Plata - Customer Proprietary (MDC055), United States of America

5 days ago

Senior Manager, Digital Risk & Cyber

Baringa · London, United Kingdom

1 week ago

Risk Cyber Internal Audit Manager

Grant Thornton · New York, NY, United States, US

1 week ago

Risk Cyber Internal Audit Senior Associate

Grant Thornton · New York, NY, United States, US

1 week ago

Client Manager – Executive Risk & Cyber

Mmc · Chesterfield - Maryville, United States of America · Hybrid

1 week ago

Client Executive – Executive Risk & Cyber

Mmc · Chesterfield - Maryville, United States of America · Hybrid

1 week ago

 VP - Tech Risk & Cyber

Barclays · Pune, Gera Commerzone SEZ, India

1 week ago

Senior Consultant, Digital Risk & Cyber Security

Baringa · London, United Kingdom

1 week ago

Senior Cyber Risk and Assurance Analyst

Bank of England Job Board - · London, United Kingdom, GB

1 week ago

Junior Cyber Risk and Assurance Analyst

Bank of England Job Board - · London, United Kingdom, GB

1 week ago

Junior Cyber Risk and Assurance Analyst (12m FTC)

Bank of England Job Board - · London, United Kingdom, GB

1 week ago

OT Security Engineer, Cyber Risk

Kroll · Bangalore, India · Hybrid

1 week ago

Manager, Cyber Risk & Analysis (International and Regulatory Risk)

Capitalone · McLean, VA, United States of America +2

1 week ago

Technology & Cyber Risk Group Manager, India Lead - Senior Vice President

citibank · Mumbai, MH,IN, IN

2 weeks ago

Technology & Cyber Risk Manager

zerohash · US · Remote

2 weeks ago

Technology & Cyber Risk Group Manager, India Lead - Senior Vice President

Citi Bank · NIRLON KNOWLEDGE PARK BLOCK B6, India · Hybrid

2 weeks ago

AI Cyber Risk and Credible Challenge Associate Director

Depository Trust Company · Tampa, FL, United States, US

2 weeks ago

Werkstudent Cyber Risk & Compliance (m/w/d)

Neptune · Remote, Bayern +1 · Remote

2 weeks ago

Cyber Risk Quantification Product Manager

Mastercard · Besiktas, Istanbul Turkey, Türkiye +2

2 weeks ago

Vice President, Information Security - Identity, Governance, and Cyber Risk

Pg · CINCINNATI GENERAL OFFICES, United States of America

2 weeks ago