At a Glance
- Tasks: Conduct IT security audits and create action plans to enhance cyber security.
- Company: Join Rolls-Royce, a leader in innovative power solutions for over a century.
- Benefits: Enjoy hybrid work, competitive salary, bonuses, and employee discounts.
- Other info: We embrace diversity and welcome applicants from all backgrounds.
- Why this job: Be part of a culture that values innovation, inclusivity, and personal growth.
- Qualifications: Knowledge of information systems, cyber security frameworks, and strong communication skills required.
The predicted salary is between 36000 - 60000 £ per year.
Derby - D Site - Sinfin D Site (UK-IC), United Kingdom
Rolls-Royce offers an excellent opportunity for an IT Security Auditor to join our Cyber Security, Risk and Compliance team. In this role you will be undertaking assessment activities to identify weaknesses and policy violations in our IT systems (and/or applications) and create action plans to correct any problems in order to prevent future cyber security breaches. You will be working with other Security Auditors and Information Assurance Specialists to ensure a common approach to Security Audit across Rolls-Royce.
What we offer: We offer excellent development opportunities, a competitive salary, and exceptional benefits. These include bonus, employee support assistance, and employee discounts.
What you will be doing:
- Support the Head of Cyber Security Policy & Compliance in identifying and planning cyber security audits across the IT Function, within business areas, of our IT supply chain, and 3rd party suppliers into the business.
- Undertaking those audits and providing timely reports.
- Creating corrective action plans, in conjunction with the target system owner, in order to improve the cyber security posture of that system.
- Analysis of the audit output to identify trends to inform the improvement of policy, process, procedure or technology.
- Presenting findings to a wider audience including senior management.
- Undertaking other tasks to support the wider cyber security team, such as work on the cyber culture programme.
- Assist the wider team in developing and defining Information Security policies, standards, guidelines, and procedure to an agreed framework (ISO27000).
Who we’re looking for:
At Rolls-Royce we put safety first, do the right thing, keep it simple and make a difference. These principles form the behaviours that guide us and are an essential component of our assessment process. They are the fundamental qualities that we seek for all roles. For this role you will need to demonstrate understanding of the applicable health and safety standards and we are looking for someone who is/has:
- Good overall knowledge of information systems practices and applications.
- Thorough understanding of Rolls-Royce management processes and practical knowledge of the principles of information security.
- Understanding of Cyber Security frameworks and benchmarks to which we have to demonstrate compliance to (for example ISO27000, NIST & CIS).
- Communicates well and has the skill to influence through persuasion in a formal context.
- Broad knowledge of IT security demonstrated by attainment of appropriate qualifications.
- Experience / awareness of cloud technologies and capabilities in an enterprise environment.
- Willingness to learn and promote wider compliance requirements such as Product Safety, Data Privacy and Export Control.
We are an equal opportunities employer. We’re committed to developing a diverse workforce and an inclusive working environment. We believe that people from different backgrounds and cultures give us different perspectives. And the more perspectives we have, the more successful we’ll be. By building a culture of respect and appreciation, we give everyone who works here the opportunity to realise their full potential.
IT Security Auditor @ Rolls-Royce in Derby employer: Cyber Crime
Rolls-Royce is an exceptional employer, offering a dynamic and inclusive work environment in Derby where innovation thrives. As an IT Security Auditor, you will benefit from excellent development opportunities, a competitive salary, and a comprehensive benefits package, all while contributing to cutting-edge technologies that ensure safety and reliability. Join us to grow your career in a culture that values diversity and empowers you to make a meaningful impact.
StudySmarter Expert Advice🤫
We think this is how you could land IT Security Auditor @ Rolls-Royce in Derby
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Cyber Crime, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Cyber Crime
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Cyber Crime. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace IT Security Auditor @ Rolls-Royce in Derby
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Cyber Crime insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Cyber Crime that you’re committed to staying ahead in the game.
How to prepare for a job interview at Cyber Crime
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Cyber Crime to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Cyber Crime.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.