About the job
Sword Group stands as a premier provider of business technology solutions across the Energy, Public, and Finance sectors, facilitating transformative change for our clients. Our commitment to leveraging proven technology, skilled teams, and industry expertise enables us to establish robust technical foundations across platforms, data, and business applications. Our passion lies in harnessing technology to address business challenges, collaborating closely with our clients to help them realize their objectives.
About the Role:
As a Cyber Security Governance Analyst, you will play a pivotal role within a significant energy network program, focusing on the design and implementation of cyber security governance across the organization. This position deviates from traditional audit-centric GRC roles; you will adopt a proactive stance in shaping the application of security frameworks into tangible, operational processes within the business—particularly in configuration management, secure configuration standards, and change governance.
You will collaborate closely with security, technology, and business teams to define policies, establish governance structures, and ensure effective adoption. This role requires an individual capable of transcending theoretical knowledge, bringing clarity to complex security requirements, and assisting teams in practical application.
Key Responsibilities:
- Develop and document a Configuration Management Plan that aligns with recognized frameworks such as NIST.
- Define and implement secure configuration principles, translating technical requirements into clear, actionable policies.
- Design and document governance processes, outlining roles and responsibilities across the Second Line of Defence.
- Facilitate the implementation and acceptance of governance frameworks, working closely with business change and communication teams.
- Enhance change management processes, contributing to Change Advisory Board (CAB) inputs and governance controls.
- Coordinate with stakeholders to integrate security standards into daily operations across technology and business teams.
- Collect and analyze configuration compliance data to support governance and assurance activities.
- Simplify complex security concepts into practical guidance for non-technical stakeholders.
- Maintain high-quality documentation to support audit, compliance, and continuous improvement efforts.
Qualifications:
- Proven experience in cyber security governance, risk, or security controls roles.
- Strong understanding of security frameworks such as ISO 27001, NIST, or similar.
- Experience in developing or contributing to security policies, standards, or governance frameworks.
- Ability to translate security requirements into practical processes and guidance for business teams.
- Experience working in regulated environments such as energy, utilities, or financial sectors.

