eCAF/NIS Principal Engineer

Morson Group · Not specified, Glasgow

eCAF/NIS Principal Engineer at Morson Group, based in Not specified, Glasgow, paying £650 - £700 per day. This is a contract role.

Salary
£650 - £700 per day
Location
Not specified, Glasgow
Contract
Contract
Posted
1 week ago
Closes
24 Aug 2026
Sector
Security

About 57% above the going rate for security

Reference https://www.morson.com/jobs/renewable-energy/contract/glasgow/ecafnis-principal-

About the role

Job title: Principal Engineer Location: SPHQ, Glasgow City Centre Duration: 12 months inital contract Rate: Negotiable, inside IR35, PAYE or UMBCyber security is one of the defining topics of our age, and cyber risk represents one of the most significant strategic risks to the UK's critical national infrastructure. At Scottish Power Energy Networks (SPEN) you will have the opportunity to approach this risk head on. SPEN have invested significantly in an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations and deliver a cyber resilient business.The Cyber Assessment Framework (CAF) / NIS Programme will enhance cyber resilience, compliance and assurance across the organisation's IT applications estate in line with NIS Regulations and the UK Cyber Assessment Framework (CAF).Reporting into the Programme Manager, the Principal Engineer role is a critical Technical Leadership role in ensuring delivery against the strategic security vision and development and maintenance of associated security standards and documentation across COE owned applications. The role will ensure that applications are protected, resilient and prepared against cyber incidents.The position requires the ability to identify opportunities to use technology to deliver secure services that are more effective. To do this, the role holder must be able to influence and communicate successfully with the relevant parties inside and outside of the company while remaining accountable for the outcomes. The role holder will work closely across all Infrastructure, Telecommunications, Security and Business IT teams and with wider Corporate Security in order to achieve key goals.Accountability Statements The Principal Engineer works closely with project managers, business analysts, end users and external vendors to ensure that applications meet the functional and non-functional requirements of the business while also ensuring that we continue to support and develop our applications with minimal impact on business as usual.Key accountabilities include: - Inputs to the CoE Cyber Programme Plan and development of associated roadmaps, identifying new security capabilities to support overall NIS compliance. - Defines and drives alignment between security architecture frameworks and standards with overall business strategy. - Ensure that security architecture supports each stage of the delivery of new projects as indicated by the 'Secure by Design' process. - Leads the creation of security design documents and architecture artefacts - Leads relevant Design Authorities, providing security guidance at all times. - Sets direction and drives the adoption of secure designs, patterns and best practices. - Keeps abreast of the latest intelligence from sources of cyber threat information and briefs stakeholders with actionable information. - Contribute to security investment governance processes.Skills, Knowledge & ExperienceRequired: - Demonstrated experience in managing relationships with key stakeholders - Information risk assessment and risk management - Protective security and understanding of threats to IT and OT - Identification, prioritisation and leadership of key security technology opportunities - Experience of understanding and managing aspects of cyber risk, including the assessment, analysis, and reporting of cyber risk in a business context - Knowledge and experience of delivering application architecture and design - Experience in defining and/or implementing security controls across multiple layers of the IT architecture stack - Motivational skills for team management. - Ability to analyse problems, identify core issues and recommend appropriate solutions - Recognised cyber security qualifications desirable (e.g. CISSP, CISM, NCSC CCP, M.Inst IISP, etc.) - Contribute to security investment governance processes.Minimum Criteria (Mandatory)Experience of Secure by Design Solutions Application Design and architecture Experience of cyber security, monitoring and reporting tools and solutions Experience of understanding and managing aspects of cyber risk, including the assessment, analysis, and reporting of cyber risk in a business context

Reference: https://www.morson.com/jobs/renewable-energy/contract/glasgow/ecafnis-principal- · Posted 1 week ago · Closes 24 Aug 2026 · Listed via Morson Group

Know someone who'd be great for this? Get a shareable card

Apply for this job

This role is listed via Morson Group. Applications are handled on the employer's site.

Apply on employer site

Opens the employer's website in a new tab.

Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.

Report this job
Salary £650 - £700 per day
Apply now