OVO Energy

Principal GRC (H/F)

Rejoignez OVO Energy comme GRC Principal à Glasgow, Bristol ou Londres. Dirigez la gouvernance sécurité, gérez la conformité réglementaire et améliorez la gestion des risques. Profitez d’un salaire flexible, 34 jours de congés et d’avantages verts pour votre bien-être et style de vie.
OVO Energy
OVO Energy
Hybride Temps plein UTC+01:00

OVO Energy

Présentation de l'entreprise

Nom

OVO Energy

Siège social

Bristol, Royaume-Uni

Fondé

2009

Taille

Environ 4 500 employés (source : ovo.com).

Ce qu'ils font

OVO Energy se concentre sur la gestion intelligente de l'énergie et propose une gamme de produits et services incluant l'approvisionnement en électricité et en gaz traditionnel, des solutions de recharge pour véhicules électriques (VE), des panneaux solaires, des pompes à chaleur et des compteurs intelligents. L'entreprise s'engage à accroître l'intégration des sources d'énergie renouvelable dans ses offres, s'adressant principalement aux clients résidentiels à travers le Royaume-Uni. Avec une base de clients d'environ quatre millions de foyers, OVO propose des tarifs énergétiques qui incluent des options vertes et renouvelables, ainsi que des programmes innovants comme Charge Anytime, qui permet aux clients de réaliser des économies significatives sur leurs coûts de recharge de VE (source : ovoenergy.com).

Projets et antécédents

OVO Energy a réalisé des avancées significatives dans le secteur de l'énergie, notamment l'installation du premier chargeur domestique pour véhicules électriques à retour sur le réseau au monde en 2018. L'acquisition de SSE Energy Services en janvier 2020 a été un moment clé, intégrant 8 000 employés et des millions de clients dans les opérations d'OVO. D'ici 2025, l'entreprise vise à avoir installé plus de 1 000 pompes à chaleur et 500 systèmes solaires dans les foyers britanniques, démontrant son engagement envers des solutions énergétiques durables (source : ovo.com).

Développements récents

Début 2025, OVO Energy a annoncé le déménagement de son siège social vers Crescent à Temple Quay à Bristol, un changement visant à améliorer la durabilité en évitant 3 200 tonnes d'émissions de CO2e. De plus, des rapports de juin 2025 ont indiqué qu'OVO est en pourparlers d'exploration pour une fusion avec Iberdrola, le propriétaire de Scottish Power, ce qui pourrait redéfinir davantage le paysage concurrentiel du marché de l'énergie au Royaume-Uni (source : wikipedia.org).

Travailler là-bas

OVO Energy propose une variété de postes dans différents départements, y compris l'approvisionnement en énergie, le service client, l'ingénierie, la technologie et la durabilité. Avec une main-d'œuvre d'environ 4 500 employés, l'entreprise a une forte présence à Bristol, Londres et Glasgow. La culture chez OVO met l'accent sur la collaboration et l'innovation, comme en témoigne la contribution des employés dans la conception de leur nouveau bureau à Bristol. L'entreprise a été reconnue par le passé pour son environnement de travail, se classant comme le 20ème meilleur employeur du Royaume-Uni dans le classement 2017 du Sunday Times (source : ovoenergy.com).


Dernière mise à jour le févr. 23, 2026 | Signaler un problème

Job Description

OVO is seeking an experienced GRC Principal to provide leadership, compliance continuity, and strategic assurance. Reporting CISO you will balance day-to-day compliance and assurance stability, with continuous improvement of our risk levels and risk management practices.

As an Operator of Essential Services under NIS regulations, OVO requires a seasoned GRC professional capable of managing a complex regulatory landscape while providing hands-on guidance to a newly formed security GRC team.

You will:

  • Provide day-to-day leadership to the security GRC function, ensuring clear direction and role clarity.
  • Develop and manage strong stakeholder relationships (business) and reporting.
  • Be a thought leader connecting security teams to wider issues of risk.
  • Deliver GRC vision and people management.
  • Manage and track security risks within the corporate GRC framework.
  • Manage a complex regulatory environment.
  • Provide continuity and continuous improvement for our Information Security Management System (ISMS), streamlining and simplifying existing processes.
  • Focus is on the now, but consider the horizon: navigating shifting external risks and a complex regulatory landscape.
  • Lead solution design and delivery of enterprise compliance initiatives collaborating with Security Architecture and Assurance and the broader Security teams (ISO 27001 certification and Cybersecurity Assessment Framework).
  • Collaborate with GRC Security Architecture and Assurance to enable and track risk-reduction, focused security control improvement through automation and assurance.
  • Lead the preparation for board level risk updates, translating technical risk into executive-level insights.
  • Review the "Three Lines of Defence" model to ensure clear delineation between 1st-line operations and 2nd-line oversight.
  • Collaborate and consult with risk management, compliance and DPO functions to ensure alignment.
  • Act as:
    -Compliance, controls and audit partner to business.
    -Legal and regulatory partner to business.

Your team will collaborate with business, Tech and security to deliver:

  • Policies and standards (top level/ISMS).
  • Communications and engagement.
  • Third party risk management (compliance/legal/contractual).
  • Security assurance and audit-readiness against controls.
  • Horizon scanning legal, regulatory and compliance.

Your key outcomes will be

  • Unified governance: ownership of a living, breathing ISMS that satisfies multiple regulatory requirements without redundant effort.
  • Strategic reporting: delivering clear risk reporting to leadership that enables fast, informed business decisions.
  • Cultural transformation: engaged stakeholders and a measurable reduction in "human-factor" risk, moving beyond "tick-box" training to a high-engagement security awareness program.
  • Cross-functional partnerships: seamless collaboration with other teams such as Risk, Business Continuity, and Fraud to ensure a straightforward experience for OVO regarding compliance.

Systems

  • GRC Platforms: for centralising the risk register and Common Control Framework (CCF).
  • Learning Management Systems (LMS): to drive and track the awareness program.
  • Collaboration and Workflow: management and task tracking.
  • Reporting Tools: to visualise KRIs and compliance health tracking.

You'll be successful in this role if you...

  • Can think strategically as well as pragmatically.
  • Can communicate effectively across different levels and areas of a business (business, risk, Tech, security).
  • Are adept at building stakeholder relationships.
  • Can cut through complexity to bring clarity and simplicity.
  • Are comfortable with and bring clarity to ambiguity.
  • Have experience working in a fast-evolving business.
  • Are in your element and comfortable working alongside agile, Tech-driven teams.
  • Able to coach and train others in identifying and delivering on security risk and regulatory requirements.
  • Developed common control frameworks that consider multiple compliance and regulatory requirements.
  • Have experience with managing security GRC teams and risk through mergers and acquisitions.
  • Brought cohesion and purpose to newly integrated teams.
  • You understand that security can break a business if done ineffectively and seek the middle-ground between compliance that protects OVO while enabling it to move fast and continue to grow.
  • You can explain a complex technical risk to a non-technical audience in a way that makes them understand it and how they can help fix it.
  • You build impactful narratives that make employees care and see their place in the security culture.
  • You think in frameworks and processes, you don't just solve a problem once, you assist in building the systems that prevent it from reoccurring.

Essential

  • Regulated Environments: Proven experience as a Security GRC or Risk Manager within UK regulated sectors (e.g., Utilities, Financial Services, or Critical National Infrastructure).
  • Regulatory Fluency: Understanding of NIS regulations, GDPR, and Ofgem requirements, as well as the forthcoming Cyber Security and Resilience Bill.
  • Framework Expertise: Practical experience operating within a Three Lines of Defence model.
  • Executive Presence: The ability to engage confidently with Board-level stakeholders regarding risk appetites and strategic trade-offs.
  • Agility: A "player-coach" mindset-equally comfortable in strategic boardrooms and technical operational reviews.
  • Comfortable with Ambiguity: you can navigate shifting regulatory landscapes and provide a steady structure for the team.

Desirable

  • Experience managing or restructuring security functions during organisational change.
  • Experience with mergers and acquisitions.
  • Experience managing risk within agile cloud-native technology estates.

Let's talk about what's in it for you

We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission.

You'll be eligible for an on-target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal.

We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO...and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash.

Here's a taster of what's on offer:

For starters, you'll get 34 days of holiday (including bank holidays).

For your health
With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more

For your wellbeing
With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more

For your lifestyle
With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give-as-you-earn donations

For your home
Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers

For your commute
Nab a great deal on ultra-low emission car leasing, plus our cycle to work scheme and public transport season ticket loans

Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know.

For your Belonging

To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you.

Oh, and one last thing...

We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you!

If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.

Postuler maintenant

Offre d’emploi expirée ?

Dites à OVO Energy que vous avez trouvé cet emploi sur Rejobs. Cela nous aide à grandir et à attirer plus de talents dans les énergies renouvelables !

À propos du rôle

29 juillet 2026

29 juillet 2026

Temps plein

Hybride

Entreprise

Énergie solaire, Infrastructure de recharge pour véhicules électriques, Réseaux intelligents

OVO Energy

company.ovo.com

  •  Glasgow, Écosse, Royaume-Uni
  •  Bristol, Royaume-Uni
  •  Londres, Royaume-Uni

Expert

UTC+01:00