Information Assurance Specialist

Information Assurance Specialist

Full-Time 45000 - 55000 € / year (est.) Home office (partial)
Rolls-royce

At a Glance

  • Tasks: Support cyber security initiatives and develop information security policies for IT product teams.
  • Company: Join Rolls-Royce, a leader in innovation and technology.
  • Benefits: Generous annual leave, retirement savings, and matched shares programme.
  • Other info: Inclusive workplace that values diverse perspectives and promotes career growth.
  • Why this job: Make a real impact on cyber security and work with cutting-edge technologies.
  • Qualifications: Strong understanding of information security principles and relevant professional certifications.

The predicted salary is between 45000 - 55000 € per year.

Location: Derby. Days per week: 3. Employment type: Full time.

We have an excellent opportunity for an Information Assurance Specialist to join our Cyber Security, Risk and Compliance team. In this role you will be providing Information Assurance through the application of policy, standards, and best practice to support the IT product teams. You will also be required to work with other IA specialists to ensure a common approach to cyber security issues is developed and documented.

What you will be doing:

  • Support the development and continual improvement of Information Security policies, standards, and procedures in line with ISO/IEC 27000, promoting a secure-by-design culture informed by business impact assessments, risk appetite, and regulatory requirements.
  • Serve as the Cyber Security representative on major programmes and product teams, providing authoritative guidance and approvals to ensure secure design, build and operation across IT, OT and AI-enabled systems.
  • Represent Cyber Security across strategic initiatives—including research collaborations, joint ventures, and supply‑chain engagements—ensuring security requirements and secure‑by‑design principles are embedded from concept through delivery.
  • Assess organisational and technical compliance with security policies and standards, conduct configuration and architecture reviews, and evaluate adherence to legal, regulatory and industry obligations.
  • Prioritise remediation using business impact assessments.
  • Provide expert advice on the selection, implementation, and assurance of security controls, ensuring alignment with NIS2, aerospace standards, export controls and emerging AI regulatory expectations.
  • Advise stakeholders on risk reduction strategies, promote secure behaviours and support security awareness initiatives to strengthen secure‑by‑design engineering and decision‑making.
  • Identify, assess and manage cyber security risks and concessions, ensuring decisions are guided by business impact assessments and integrated into enterprise risk and operational safety processes.
  • Contribute to broader cyber security initiatives and capability uplifts, including OT security maturity, AI assurance, supply‑chain resilience and secure development lifecycle improvements.
  • Apply and oversee security controls required by policy, risk assessment, and regulatory drivers, ensuring the confidentiality, integrity and availability of business systems, including ICT, connected manufacturing platforms and AI‑supported operational systems.

Position qualifications:

  • Strong overall understanding of information systems, their applications and lifecycle practices, with solid grounding in information security principles and governance.
  • Proven ability to interpret and apply IT security compliance requirements while maintaining a pragmatic, risk‑based approach to standards implementation.
  • Effective communicator with the ability to influence stakeholders and build consensus in formal and cross‑functional environments.
  • Broad knowledge of cyber and information security, supported by relevant professional qualifications (e.g., CISSP, CISM, ISO 27001 Lead Implementer/Lead Auditor).
  • Experience or strong awareness of enterprise cloud technologies, architectures and capabilities (e.g., Azure, AWS, GCP).
  • Demonstrated willingness to learn and champion broader compliance domains, including Product Safety, Data Privacy, Export Control and other regulatory frameworks.
  • Awareness or experience of Artificial Intelligence technologies (e.g., Large Language Models, Machine Learning) or engineering disciplines is beneficial but not essential.
  • Understanding of Operational Technology (OT) environments and the unique security considerations associated with industrial control systems.
  • Experience with Governance, Risk and Compliance (GRC) tooling (e.g., Zen, Archer, ServiceNow GRC, OneTrust, MetricStream), including managing risk registers, control frameworks, and compliance workflows at scale.

Preferred requirements:

  • Degree or master's qualification in Information Security, Cyber Security, or a related discipline (or equivalent experience).
  • Industry‑recognised professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Lead Auditor (or equivalent).
  • Cloud security or architecture certifications for Microsoft Azure or other major cloud platforms (e.g., AWS, GCP).

Regional Benefits:

  • Generous Annual Leave
  • Retirement Savings through the Rolls‑Royce Retirement Savings Trust
  • Group Life Assurance provides for a lump sum benefit if you die whilst employed by Rolls‑Royce
  • Group Income Protection provides an income in the event that you are unable to work due to illness or injury
  • Your Shares: Matched is a simple way to own Rolls‑Royce shares and invest in our future, together. Buy one share, get one free!
  • Digital GP provides a convenient way for you to access GP consultations

Rolls‑Royce are committed to being a respectful, inclusive, and non‑discriminatory workplace where individuality is valued, diverse perspectives fuel innovation, and everyone can thrive.

Information Assurance Specialist employer: Rolls-royce

Rolls-Royce offers an exceptional work environment for Information Assurance Specialists in Derby, where innovation and security are at the forefront of our mission. With a commitment to employee growth, we provide generous annual leave, retirement savings plans, and unique share ownership opportunities, fostering a culture of inclusivity and respect. Join us to be part of a team that values diverse perspectives and champions secure-by-design principles across cutting-edge technologies.

Rolls-royce

Contact Detail:

Rolls-royce Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Assurance Specialist

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their approach to cyber security and think about how your skills align with their needs. This will help you stand out as a candidate who truly gets what they’re about.

Tip Number 3

Practice your responses to common interview questions, especially those related to information assurance and compliance. Use the STAR method (Situation, Task, Action, Result) to structure your answers and showcase your experience effectively.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Rolls-Royce.

We think you need these skills to ace Information Assurance Specialist

Information Security Principles
ISO/IEC 27000
Cyber Security Compliance
Risk Assessment
Stakeholder Communication
CISSP
CISM

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Information Assurance Specialist role. Highlight your relevant experience and skills that align with the job description, especially around cyber security and compliance.

Showcase Your Qualifications:Don’t forget to mention any professional certifications you have, like CISSP or CISM. These are key in our field, and we want to see how your qualifications make you a great fit for the team.

Be Clear and Concise:When writing your application, keep it straightforward. Use clear language and avoid jargon unless it's relevant. We appreciate a well-structured application that gets straight to the point!

Apply Through Our Website:We encourage you to submit your application through our website. It’s the best way to ensure it reaches us directly and allows you to easily track your application status. Plus, it’s super simple!

How to prepare for a job interview at Rolls-royce

Know Your Stuff

Make sure you have a solid understanding of information security principles and governance. Brush up on ISO/IEC 27000 standards and be ready to discuss how you've applied these in past roles. This will show that you're not just familiar with the theory but can also implement it practically.

Showcase Your Communication Skills

As an Information Assurance Specialist, you'll need to influence stakeholders and build consensus. Prepare examples of how you've effectively communicated complex security concepts to non-technical audiences. This will demonstrate your ability to bridge the gap between technical and business teams.

Be Ready for Scenario Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about past experiences where you had to assess compliance or manage cyber security risks. Be prepared to explain your thought process and the outcomes of your decisions.

Stay Current with Trends

Cyber security is always evolving, especially with the rise of AI and cloud technologies. Familiarise yourself with the latest trends and challenges in the industry. Mention any relevant certifications or training you've pursued recently to show your commitment to continuous learning.