Cyber Programme Manager (CNI / CAF)
Utilities
90% remote: light travel to Warwick, Plymouth, Bristol
12 months
£800 - £850 per day
In short: As a utilities business, we need to fulfil on CAF by December 2027 and we need a strong, classic Cyber Programme Manager with CNI or Utilities experience to deliver this heavily-regulated programme of work. This is a senior role with regular engagement with the CISO.
In full:
About the Role
We are seeking an experienced Cyber Programme Manager to lead the delivery of a complex portfolio of cyber security initiatives supporting our electricity distribution business.
The successful candidate will establish, govern and coordinate an integrated cyber transformation programme comprising both existing projects and new initiatives. Operating across Group Security, the role is responsible for ensuring projects are delivered in accordance with governance, financial, security and delivery standards while supporting regulatory obligations and cyber resilience objectives.
The Cyber Programme Manager will act as the central coordination point between the CISO, delivery teams, Group Security, project managers, technical delivery leads and executive stakeholders. They will provide programme leadership, delivery assurance, financial oversight, risk management and executive reporting to ensure successful achievement of cyber regulatory commitments and Enhanced Profile transformation objectives.
What we’re trying to Achieve
We’re undertaking a significant cyber transformation programme to strengthen cyber resilience, improve governance and risk management capabilities, and achieve compliance with the Enhanced Profile requirements associated with the Network and Information Systems (NIS) Regulations and the Cyber Assessment Framework (CAF). This programme spans both IT and Operational Technology (OT) environments and includes the delivery of cyber capabilities, process improvements, technical controls, risk reduction initiatives and regulatory commitments.
The programme manager will play a critical role in ensuring:
- Delivery of cyber regulatory commitments.
- Progression towards Enhanced Profile and CAF maturity objectives.
- Effective governance and assurance of cyber investments.
- Integration between business and Group Security services and capabilities where applicable.
- Management of delivery risks, dependencies and financial performance.
- Transparent reporting to executive leadership and governance boards.
Key Responsibilities
Programme Leadership
- Establish and maintain an integrated cyber programme roadmap covering all cyber initiatives.
- Coordinate projects across IT, OT and Group Security delivery teams.
- Manage interdependencies, priorities and resource requirements across multiple workstreams. Ensure delivery plans align with strategic objectives, regulatory requirements and organisational priorities.
Governance & Assurance
- Ensure adherence to project governance frameworks, investment processes and delivery methodologies.
- Operate and support programme governance forums, steering committees and executive review boards. Develop and maintain programme-level reporting and performance dashboards.
- Maintain programme-level risk, issue, dependency and decision management processes.
- Provide independent challenge and delivery assurance across project workstreams.
- Ensure compliance with internal policies, cyber standards and regulatory expectations.
Regulatory & Cyber Compliance
- Support journey towards Enhanced Profile compliance and improved CAF maturity.
- Coordinate activities required to address regulatory findings and assurance recommendations.
- Support preparation of regulatory reporting and evidence submissions.
Financial & Commercial Management
- Manage programme budgets, forecasts and financial performance. Ensure effective financial control, forecasting accuracy and value delivery.
- Track expenditure against approved business cases and investment approvals.
- Support preparation of investment papers, sanction requests and governance submissions.
Stakeholder Management
- Build strong working relationships across the business, Group Security and wider functions. Act as a trusted advisor to the CISO and senior leadership teams.
- Coordinate delivery activities across project managers, technical leads, architects and operational teams.
- Engage suppliers, partners and third-party delivery organisations where required.
- Influence stakeholders at all levels to drive delivery outcomes.
- Present programme updates to executive stakeholders, programme boards and governance forums.
Essential Experience
- Proven experience leading large-scale cyber security, technology or transformation programmes.
- Experience delivering complex portfolios comprising multiple concurrent projects.
- Strong programme governance and portfolio management experience.
- Experience managing senior stakeholders and executive-level reporting.
- Strong financial management, forecasting and business case development skills.
- Track record of managing risks, dependencies and delivery assurance.
- Experience working within highly regulated environments.
- Excellent communication, stakeholder engagement and leadership skills.
Desirable Experience
- Cyber Security programme delivery experience.
- Understanding of NIS Regulations, Cyber Assessment Framework (CAF) and Critical National Infrastructure (CNI) environments.
- Previous experience within utilities, energy, OT or operational environments.
- Familiarity with cyber technologies such as IAM, PAM, Vulnerability Management, Security Operations, GRC, Network Security and OT Security solutions.
- Programme or project management qualifications (MSP, PRINCE2, PMP, Agile or equivalent).
Key Behaviours
- Drives accountability and delivery.
- Strong programme leadership and coordination skills.
- Comfortable operating in a complex stakeholder environment.
- Influences through collaboration rather than authority.
- Strategic thinker with strong attention to detail.
- Data-driven and outcome-focused.
- Demonstrates integrity, transparency and sound judgement.
Candidates will ideally show evidence of the above in their CV in order to be considered.
Please be advised if you haven't heard from us within 48 hours then unfortunately your application has not been successful on this occasion, we may however keep your details on file for any suitable future vacancies and contact you accordingly. Pontoon is an employment consultancy and operates as an equal opportunities employer.
We use generative AI tools to support our candidate screening process. This helps us ensure a fair, consistent, and efficient experience for all applicants. Rest assured, all final decisions are made by our hiring team, and your application will be reviewed with care and attention.