Cyber Assurance Manager – Compliance
// Role Summary
Lead cyber compliance and assurance initiatives for BAE Systems, ensuring robust governance and audit readiness. This role offers a hybrid working model and the chance to shape a safer future through technology.
// Key Responsibilities
- Manage and deliver Group level Cyber compliance and certifications.
- Provide Subject Matter Expertise in tech, risk management, and stakeholder engagement.
- Support the development and implementation of the cyber compliance assurance framework.
- Engage with stakeholders across the business to embed best practices.
- Conduct independent L2 Control testing and Assurance.
// Role Specification
About the Role
Join BAE Systems as a Cyber Assurance Manager – Compliance, playing a pivotal role in the Group Compliance and Assurance team. You will be responsible for the management, oversight, and preparation for Group level Cyber compliances and certifications, ensuring overall audit readiness. This position requires a strong blend of technical and risk management skills, coupled with effective stakeholder management to meet demanding compliance certification requirements.
Core Duties
- Support the Head of Cyber Assurance in managing and delivering Compliance assurance initiatives.
- Manage and contribute to the GCSS, ensuring clarity on compliance requirements, auditing, and certification schedules.
- Directly engage with required stakeholders to facilitate compliance and certification efforts.
- Support the planning, agreement, and implementation of compliance standards to ensure audit readiness.
- Assist in the development and implementation of the cyber compliance assurance framework aligned with industry standards.
- Engage in significant stakeholder management to foster collaboration across BAE Systems and embed best practices.
- Provide Subject Matter Expertise on compliance standards, internal policies, and Secure by Design (SbD) principles.
- Develop and embed Assurance, Compliance, and Progress Reporting using tools like Excel and Tableau.
- Support the development and embedding of Assurance tooling.
- Perform independent L2 Control testing and Assurance, Continuous Control Monitoring, and Maturity Assessments.
- Oversee L1 assurance assessment and remediation programs, including Exception and Risk Acceptance Governance.
Essential Skills and Experience
- Knowledge in Cyber Security, Information Security, or Information Technology.
- Experience in a Governance, Risk, Compliance, and Assurance (GRC&A) role, preferably in a large or complex organisation.
- Specialist knowledge of MOD/DOD Compliance standards (e.g., DCC/MoD SAQs, SWIFT, Fin Assurance, CE+).
- Experience in managing and improving Risk Assurance frameworks.
- Proven experience in providing second-line Assurance oversight.
- Experience with cyber risk management and compliance with cyber security standards and certification requirements (e.g., NIST 800-53, SOC 2, CSM (UK MOD), ISO 27000).
- Experience working in sectors such as defence, government, banking, or utilities.
Location and Working Arrangements
This role is based in Preston or London, offering hybrid working arrangements. Travel to sites will be required as and when needed, ideally onsite at the contractual site once a week. Please discuss specific flexible working options with your recruiter.
Security Clearance
Please be aware that many roles at BAE Systems are subject to security and export control restrictions. Applicants must, as a minimum, achieve Baseline Personnel Security Standard (BPSS). Higher levels of National Security Vetting may be required, typically necessitating 5-10 years of continuous residency in the UK.