Cyber Security Project Manager at Morson Edge, Multiple Locations, £Contract Rate

Contract Description

Cyber Security Project Manager – CMDB & Asset Management

Contract: 6 Months
Location: London/ 2 days on-site]
IR35: Outside IR35
Rate: £700 per day

About the Role

We are currently recruiting for an experienced Cyber Security Project Manager to lead the delivery of a major CMDB, enterprise asset inventory and information inventory capability across both Operational Technology (OT) and Information Technology (IT) environments.

Working within a critical infrastructure / electricity distribution environment, you will play a key role in improving visibility, ownership and control of technology assets, operational systems, applications, services and information supporting essential network operations.

This is a complex, multi-disciplinary project requiring someone who can operate confidently across cyber security, IT, OT, engineering, asset management and information governance.

Key Responsibilities

  • Lead the end-to-end delivery of the CMDB, enterprise asset inventory and information inventory programme.

  • Develop project scope, delivery plans, milestones, governance, budgets, resources and success measures.

  • Manage multiple technical and business workstreams covering discovery, data collection, tooling, integrations, governance and operating models.

  • Lead the implementation or enhancement of an enterprise CMDB, including configuration-item classes, attributes, relationships and data-quality requirements.

  • Establish relationships between business services, applications, infrastructure, OT systems, information assets and accountable owners.

  • Coordinate integration with asset-discovery, ITSM, vulnerability management, SIEM, network management, cloud and other enterprise platforms.

  • Oversee asset discovery and reconciliation across corporate, operational and field environments.

  • Develop safe and proportionate approaches to OT asset discovery, recognising the operational and safety constraints of critical infrastructure.

  • Establish asset ownership, criticality, lifecycle and support information.

  • Lead the development of an enterprise information inventory covering data repositories, information owners, classification, retention and critical business processes.

  • Establish data-quality standards and processes covering completeness, accuracy, consistency, timeliness and ownership.

  • Manage project risks, issues, dependencies, decisions and changes.

  • Coordinate internal technical teams, engineering functions, suppliers, systems integrators and specialist cyber security partners.

  • Provide clear reporting to senior stakeholders and project governance forums.

  • Support alignment with relevant cyber security, regulatory and critical-infrastructure requirements.

  • Ensure the resulting capability is successfully transitioned into business-as-usual operations.

Essential Experience

The successful candidate will have:

  • Significant experience delivering cyber security, CMDB, asset management, ITSM or information governance projects.

  • Demonstrable experience working across both OT and IT environments.

  • Experience within energy, utilities, electricity distribution or another critical-infrastructure environment.

  • Practical experience implementing or improving a CMDB or enterprise asset repository.

  • Strong knowledge of asset discovery, configuration management, service mapping and data reconciliation.

  • Understanding of OT/ICS environments, including SCADA, control systems, substations, field assets and operational telecommunications.

  • Understanding of the differences between OT and IT, particularly around safety, availability, lifecycle and change management.

  • Experience establishing asset ownership, governance and data-quality controls.

  • Experience managing complex integrations between enterprise systems and technical data sources.

  • Strong project planning, governance, risk and stakeholder-management experience.

  • Experience managing technology suppliers, systems integrators or specialist consultancies.

  • Ability to communicate complex technical and data-related issues clearly to both technical and senior non-technical stakeholders.

Desirable Experience

  • Previous experience with a UK Distribution Network Operator (DNO) or Distribution System Operator (DSO).

  • Experience with enterprise CMDB / ITSM platforms.

  • Experience with OT asset-discovery or industrial cyber-monitoring technologies.

  • Experience integrating CMDB, vulnerability-management, SIEM and enterprise architecture platforms.

  • Knowledge of the NCSC Cyber Assessment Framework, IEC 62443, ISO 27001, ISO 55001 or ITIL.

  • Experience developing information asset registers, data catalogues or information inventories.

  • Experience supporting regulatory assessments, audits or cyber security maturity programmes.

  • Understanding of smart grids, distributed energy resources or electricity-network digitalisation.

Qualifications

Relevant qualifications may include:

  • PRINCE2, APM, PMP or equivalent project management qualification.

  • ITIL certification.

  • CISSP, CISM, CRISC or equivalent cyber security certification.

  • OT cyber security / IEC 62443 certification.

  • Relevant qualifications in configuration management, data management or information governance.

Key Skills

  • Cyber Security Project Management

  • CMDB & Configuration Management

  • Enterprise Asset Management

  • OT & IT Asset Discovery

  • Information Governance

  • Service Mapping

  • Data Quality & Reconciliation

  • Cyber Risk & Operational Resilience

  • Stakeholder & Supplier Management

  • Project Governance & Delivery

  • Critical Infrastructure / Utilities

  • OT / ICS / SCADA environments

Why Apply?

This is an opportunity to take ownership of a high-profile cyber security and asset-management programme within critical national infrastructure, working across OT, IT, engineering and cyber security functions.

You will have a key role in establishing an authoritative view of the organisation's assets, services and information, helping to strengthen cyber risk management, vulnerability management, incident response, operational resilience and regulatory assurance.