Job Description
Job Title:  Cyber Security Governance & Assurance Specialist
Req ID:  59973
Job Function:  Cyber Security
Posting Start Date:  24/08/2026
Posting End Date:  26/08/2026
Division:  Digital
Job Location:  GBR-London-BTHQ One Braham, GBR-Manchester-New Bailey
Advertised Salary:  Competitive + Benefits

Location

This role can be based out of our New Bailey Manchester office, or our One Braham London office. We have a hybrid working model of 3 days together and 2 days wherever.

 

Due to the nature of the work, you will need to be elegible for security clearance+.

About the role

BT Business provides large scale multi-year contracts to government departments. The Secure Engineering team, Digital is accountable for ensuring the development, connectivity, and maintenance of multiple Service Management Platforms to recover revenue of more than £400m per annum.


This role supports the delivery and assurance of cyber security controls for UK Government customers, ensuring the protection of sensitive data and systems is embedded as a core principle within solution design. You will ensure that security requirements, risk considerations, and compliance obligations are integrated into architecture and design decisions from the outset, aligned to relevant government and industry security standards.


As a Cyber Security Governance & Assurance Specialist, you will be responsible for establishing, maintaining, and assuring the effectiveness of security governance frameworks, risk management processes, and control environments across customer platforms. This includes defining and enforcing security policies, standards, and baselines aligned to recognised frameworks such as ISO27001, NIST, and CIS.


You will lead risk identification and assessment activities, perform control validation and assurance testing, and support internal and external audit processes. Working closely with infrastructure, cloud, and engineering teams, you will ensure security controls are embedded by design across architectures and delivery pipelines, with clear traceability to risk and compliance requirements.


You will also act as a key interface between technical teams and business stakeholders, translating complex security risks into measurable business impact, and driving remediation through structured governance forums. Your focus will be on continuous improvement of the control landscape, ensuring security posture is measurable, auditable, and aligned to both regulatory obligations and customer expectations.

What you’ll be doing

1. Identifies, evaluates and reports on cyber security risks in a manner that meets the Group's internal, regulatory and other compliance requirements.
2. Collaborates with internal departments and organisations to implement practices that meet the Group's defined policies and standards for information risk management.
3. Delivers the rigorous assessment of internal compliance, informing and advising on data protection obligations, providing advice regarding Data Protection Impact Assessments, acting as a contact point for data subjects.
4. Contributes to the ongoing development and management of frameworks pertaining to Information Governance (IG), Cyber Security and Data Protection.
5. Ensures the adherence to policies and procedures to support requirements to enable the group to meet its legal, contractual and statutory obligations while reducing the cyber security and information risk exposure.
6. Executes activities in support of cyber security owned programs and related teams including security policies, vendor risk and compliance management, regulatory audits and compliance management, metrics, risk and performance indicators, executive and board reporting, security awareness and training, security integration and assessment of M&A and related ventures.
7. Supports lines of business to perform security assessments and ensures timely execution of projects and programs while mitigating any security risks.
8. Executes the evaluation of cyber security controls to ensure effectiveness, compliance and adherence to key controls and policies and drive its remediation efforts.
9. Implements analysis of key GRC (governance, risk and compliance) risk information, including the cyber risk register, policy exceptions, audit findings and data security reviews and the preparation of reporting and dashboards as necessary to satisfy the Group's cyber reporting requirements at both a management and executive level.
10. Monitors cyber compliance portals and acts as the liaison with communication groups driving awareness and adoption of cyber policies and standards across the BT Group.
11. Leads liaison for cyber audits and maturity assessments assisting with reviews and providing artefacts as needed.
12. Mentors other Cyber Security Governance & Assurance professionals, helping to improve the team's abilities by acting as a technical resource.
13. Champions, continuously develops and shares with team knowledge on emerging trends and changes in Cyber Security Governance & Assurance.

Essential Skills / Experience

  • Security Assurance & Governance Experience (e.g. assurance reviews, control testing, audit support, governance forums)
  • Governance, Risk Management, Compliance & GRC Tooling (e.g. risk assessments, remediation activities, compliance reporting, governance platforms/GRC tools)
  • Policy, Standards & Control Framework Design (e.g. ISO27001, NIST, CIS)

Desirable Skills / Experience

  • Certifications relevant to cyber security, governance, or risk management (e.g. CISSP, CISM, CRISC, ISO27001 Lead Implementer/Auditor or equivalent)
  • Experience in regulated industries (e.g. telecoms, finance, public sector)
  • Exposure to audit management and external certification processes
  • Knowledge of cloud security governance and modern security practises (DevSecOps, Zero Trust)
  • Experience influencing security culture and driving awareness across teams
  • Familiarity with BT or similar large-scale enterprise environments

Our Package

Tailored benefits make a real difference. That’s why we offer a comprehensive range to support your growth, wellbeing, and everyday life. 


You can design the package to suit you and your lifestyle.

 

Your core benefits include:
• 10% on target annual bonus
• Access to an online private GP 24/7 for you and your immediate family 
• Market-leading paid carers leave with up to 2 weeks off 
• Equalized maternity, paternity, and adoption leave – 18 weeks’ full pay and 8 weeks’ half pay
• Discounted EE and BT products, including mobile and broadband
• Market leading Pension scheme – 5% from you and 10% from us
• Holiday purchase scheme


You can select additional benefits, including healthcare, dental, gym memberships and more when you’re ready.


Ready to connect for good and help shape the future? Apply now.

BT Group is the UK’s leading communications group and the holding company behind some of the country’s most recognised brands – including BT, EE, Openreach and Plusnet. Our purpose is as simple as it is ambitious: we connect for good.  Our customers include consumers, small, medium and large businesses, public sector organisations and other communications providers. 

BT Group’s role is about setting direction, unlocking value and creating the conditions for our brands and businesses to thrive.

Having come through the most capital-intensive phase of our fibre investment, our focus now is on what comes next – simplifying how we operate, using technology and AI to work smarter, and organising ourselves to serve customers better and grow sustainably. Group teams shape strategy, policy, brand, capital allocation and transformation, helping the whole organisation perform at its best.

We have a singular culture that unites all our people: we are customer-first challengers, who are committed, clear and connected. These behaviours unite us as one team to deliver for our colleagues, our customers, our stakeholders and the country.   Joining BT Group means working at the heart of a business that matters to the UK, with the opportunity to shape decisions, influence outcomes and help set the future course of one of the country’s most important companies.