VP Cyber Security Advisory and Validation in Bristol

VP Cyber Security Advisory and Validation in Bristol

Bristol Full-Time 70000 - 80000 £ / year (est.) Home office (partial)
Rolls-Royce plc

At a Glance

  • Tasks: Lead cyber security initiatives and ensure secure design across projects.
  • Company: Join Rolls-Royce, a leader in innovation and technology.
  • Benefits: Generous leave, retirement savings, life assurance, and share ownership opportunities.
  • Other info: Flexible work environment with continuous learning and career development.
  • Why this job: Make a real impact on global security while shaping the future of technology.
  • Qualifications: Strong experience in cyber security and knowledge of Secure by Design principles.

The predicted salary is between 70000 - 80000 £ per year.

Full Time – Hybrid

Location - Bristol, Derby or London

Why join Rolls‐Royce?

At Rolls‐Royce we are proud to be a business that has truly helped to shape the modern world and are committed to always being a force for progress; powering, protecting and connecting people everywhere. By joining Rolls‐Royce, you'll have the opportunity to work on world-class solutions, supported by a culture that believes individuality is our greatest strength, and all perspectives, experiences and backgrounds help us innovate and enable our high-performance culture.

The VP Cyber Security Advisory & Validation champions Secure by Design across Rolls Royce and provides strategic and operational cyber security leadership to IT and OT platforms, applications, projects and programmes including assurance reviews as required by risk profile. Working closely with architecture, engineering, risk, and operational security teams, this role ensures a consistent, risk-based approach to cyber security across the organisation while supporting business agility and innovation. The role operates across multiple jurisdictions, including the UK, USA and Germany, ensuring that security approaches support regional legal, regulatory and customer requirements while maintaining our global standards.

Key Accountabilities

  • Lead the adoption of Secure by Design so that cyber security is embedded from concept through delivery, transition and live operation and establish clear security entry/exit criteria for each lifecycle phase.
  • Lead a team of consulting and assurance cyber security professionals.
  • Work in close partnership with other cyber security colleagues, especially the security architecture function, to ensure designs, patterns, standards and assurance activities are aligned and reducing risk.
  • Collaborate across the wider Digital and IT function, including engineering, infrastructure, operations, data and delivery teams, to ensure security requirements are practical, understood and embedded into ways of working.
  • Define and lead application security requirements across the software development lifecycle, including secure design, threat modelling, secure coding expectations, code review, testing, vulnerability management and remediation.
  • Lead the security approach for our move to cloud, ensuring cloud security requirements are defined and implemented.
  • Define and assess cyber security risks, ensuring clear ownership, effective treatment plans, and timely escalation where exposure exceeds agreed risk appetite and handover to the GRC team.
  • Drive information assurance activities, including security assessments, control validation, risk reporting and support for governance and sign-off decisions.
  • Ensure security policies, control frameworks and assurance approaches can operate effectively across global business units, with particular consideration for local legal, regulatory and customer expectations.
  • Provide clear reporting to senior leaders on programme risk posture, delivery risks, exceptions, control effectiveness and areas requiring investment or intervention.
  • Deputise for the Group CISO as required.

Key Experiences and Qualifications

  • Strong experience leading cyber security across complex change portfolios, technology programmes and enterprise platforms.
  • Demonstrable knowledge of Secure by Design, security architecture, risk management and assurance practices across the system lifecycle covering IT and OT.
  • Strong understanding of application security, including secure development lifecycle practices, common software vulnerabilities, threat modelling, security testing and remediation.
  • Experience supporting cloud adoption and cloud security, including shared responsibility models, secure configuration, identity and access management, monitoring, resilience and assurance in cloud environment.
  • Experience applying recognised frameworks and standards.
  • Good understanding of the practical implications of operating across multiple jurisdictions, including differing regulatory, privacy and assurance expectations in the UK, USA and Germany.
  • Ability to work effectively across a wider Digital and IT function, influencing multidisciplinary teams and suppliers.
  • Ability to translate technical security issues into business risk, delivery impact and practical decisions for senior stakeholders.
  • Understanding of information assurance, control testing, governance processes and evidence-based decision making.
  • Strong judgement in balancing security, usability, resilience, cost and delivery pace.

Leadership behaviours

  • Sets clear direction and expectations for secure delivery.
  • Builds strong, trusted relationships across cyber security, especially with the architecture function, and across the wider Digital and IT organisation.
  • Challenges constructively and supports teams to solve problems pragmatically.
  • Drives accountability, transparency and timely decision making.
  • Promotes a culture of continuous assurance, collaboration, learning and improvement.

Desirable Qualifications:

  • Degree or MSc in Information Security (or equivalent).
  • CISSP/CISM (or equivalent).
  • Experience in Microsoft Azure (or equivalent cloud platforms).
  • Secure by Design experience in a large and complex organisation.
  • Experience in working with senior leadership stakeholders.

Regional Benefits

  • Generous Annual Leave.
  • Retirement Savings through the Rolls‐Royce Retirement Savings Trust.
  • Group Life Assurance provides for a lump sum benefit if you die whilst employed by Rolls‐Royce.
  • Group Income Protection provides an income in the event that you are unable to work due to illness or injury.
  • Your Shares: Matched is a simple way to own Rolls‐Royce shares and invest in our future, together. Buy one share, get one free!

Our vision is to ensure that the excellence and ingenuity that shaped our history continues into our future. Our multi-year transformation programme aims to turn Rolls‐Royce into a high-performing, competitive, resilient and growing company. Join us, and it can be your future vision too.

Rolls‐Royce are committed to being a respectful, inclusive, and non-discriminatory workplace where individuality is valued, diverse perspectives fuel innovation, and everyone can thrive.

As part of our selection process, candidates in certain locations may be asked to complete an online assessment, which can include cognitive and behavioural aptitude testing relevant to the role. If required, full instructions for the next steps will be provided.

VP Cyber Security Advisory and Validation in Bristol employer: Rolls-Royce plc

Rolls-Royce is an exceptional employer, offering a dynamic work environment in Bristol that fosters innovation and collaboration. With a strong commitment to employee growth through continuous learning and tailored career pathways, the company values individuality and diverse perspectives, ensuring that all employees can thrive. Additionally, the generous benefits package, including flexible rewards and retirement savings, reflects Rolls-Royce's dedication to supporting its workforce both personally and professionally.

Rolls-Royce plc

Contact Details:

Rolls-Royce plc Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land VP Cyber Security Advisory and Validation in Bristol

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Rolls-Royce plc, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Rolls-Royce plc

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Rolls-Royce plc. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace VP Cyber Security Advisory and Validation in Bristol

Cyber Security Leadership
Secure by Design
Risk Management
Application Security
Cloud Security
Threat Modelling
Vulnerability Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Rolls-Royce plc insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Rolls-Royce plc that you’re committed to staying ahead in the game.

How to prepare for a job interview at Rolls-Royce plc

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Rolls-Royce plc to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Rolls-Royce plc.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.