Cyber Assurance Manager (Compliance and Regulatory Management)
// Role Summary
Lead cyber assurance and compliance efforts for a leading defence company, ensuring adherence to industry standards and robust risk management practices.
// Key Responsibilities
- Manage and deliver cyber security compliance assurance across business units.
- Oversight of audit readiness and control testing.
- Develop and implement cyber compliance assurance framework.
- Significant stakeholder management across the business.
- Provide SME support on compliance standards and Secure by Design principles.
- Experience with MOD/DOD compliance standards and cyber risk management.
// Role Specification
About the Role
Join BAE Systems as a Cyber Assurance Manager – Compliance and play a pivotal role in pioneering progress and protecting what matters most. You will be trusted to deliver advanced, technology-led defence, aerospace, and security solutions, shaping a safer future.
As a Cyber Assurance Manager – Compliance, you will support the Head of Cyber Assurance to manage and deliver compliance assurance across all Business Units. This involves maturing and performing independent L2 Control testing and Assurance, Continuous Control Monitoring, and Maturity Assessments. You will also oversee L1 assurance assessment and remediation programs, including Exception and Risk Acceptance Governance, to ensure audit readiness.
Core Duties
- Support the Head of Cyber Assurance in managing and delivering Compliance assurance.
- Manage and contribute to the GCSS, providing clarity on compliance requirements, auditing, and certification schedules, and engaging with stakeholders.
- Support certification engagement in planning, agreement, and implementation of compliance standards, ensuring audit readiness.
- Assist in the build and implementation of the cyber compliance assurance framework in line with industry standards.
- Engage in significant stakeholder management to collaboratively develop, maintain, and embed best practices across BAE Systems.
- Provide SME support on compliance standards, internal standards, policies, and Secure by Design (SbD) principles.
- Develop and embed Assurance, Compliance, and Progress Reporting using tools like Excel and Tableau.
- Support the development and embedding of Assurance tooling.
Essential Skills and Experience
- Knowledge in Cyber Security, Information Security, or Information Technology.
- Experience in a Governance, Risk, Compliance, and Assurance (GRC&A) role, ideally within a large or complex organisation.
- Specialist knowledge of MOD/DOD Compliance standards such as DCC/MoD SAQs, SWIFT, Fin Assurance, CE+, etc.
- Experience in managing and improving Risk Assurance frameworks.
- Providing second-line Assurance oversight, independent of operational management.
- Experience with cyber risk management and compliance with cyber security standards and certification requirements like NIST 800-53, SOC 2, CSM (UK MOD), ISO 27000, etc.
- Experience in sectors such as defence, government, banking, or utilities.
Location and Working Arrangements
This role is based in Preston or London with a hybrid working model. Travel to sites will be required as and when needed, ideally onsite at their contractual site once a week. BAE Systems offers a range of hybrid and flexible working arrangements.
Security and Vetting
Please be aware that many roles at BAE Systems are subject to security and export control restrictions. Factors such as your nationality, previous nationalities, and place of birth can impact eligibility. Applicants must achieve Baseline Personnel Security Standard. Many roles require higher levels of National Security Vetting, often requiring 5 to 10 years of continuous residency in the UK.