BT Group
Cyber Security Governance & Assurance Specialist

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Title: Cyber Security Governance & Assurance Specialist
Req ID: 59973
Job Function: Cyber Security
Posting Start Date: 24/08/2026
Posting End Date: 26/08/2026
Division: Digital
Job Location: GBR-London-BTHQ One Braham, GBR-Manchester-New Bailey
Advertised Salary: Competitive + Benefits
Location
This role can be based out of our New Bailey Manchester office, or our One Braham London office. We have a hybrid working model of 3 days together and 2 days wherever.
Due to the nature of the work, you will need to be eligible for security clearance+.
About The Role
BT Business provides large scale multi-year contracts to government departments. The Secure Engineering team, Digital is accountable for ensuring the development, connectivity, and maintenance of multiple Service Management Platforms to recover revenue of more than £400m per annum.
This role supports the delivery and assurance of cyber security controls for UK Government customers, ensuring the protection of sensitive data and systems is embedded as a core principle within solution design. You will ensure that security requirements, risk considerations, and compliance obligations are integrated into architecture and design decisions from the outset, aligned to relevant government and industry security standards.
As a Cyber Security Governance & Assurance Specialist, you will be responsible for establishing, maintaining, and assuring the effectiveness of security governance frameworks, risk management processes, and control environments across customer platforms. This includes defining and enforcing security policies, standards, and baselines aligned to recognised frameworks such as ISO27001, NIST, and CIS.
You will lead risk identification and assessment activities, perform control validation and assurance testing, and support internal and external audit processes. Working closely with infrastructure, cloud, and engineering teams, you will ensure security controls are embedded by design across architectures and delivery pipelines, with clear traceability to risk and compliance requirements.
You will also act as a key interface between technical teams and business stakeholders, translating complex security risks into measurable business impact, and driving remediation through structured governance forums. Your focus will be on continuous improvement of the control landscape, ensuring security posture is measurable, auditable, and aligned to both regulatory obligations and customer expectations.
What You’ll Be Doing
- Identifies, evaluates and reports on cyber security risks in a manner that meets the Group's internal, regulatory and other compliance requirements.
- Collaborates with internal departments and organisations to implement practices that meet the Group's defined policies and standards for information risk management.
- Delivers the rigorous assessment of internal compliance, informing and advising on data protection obligations, providing advice regarding Data Protection Impact Assessments, acting as a contact point for data subjects.
- Contributes to the ongoing development and management of frameworks pertaining to Information Governance (IG), Cyber Security and Data Protection.
- Ensures the adherence to policies and procedures to support requirements to enable the group to meet its legal, contractual and statutory obligations while reducing the cyber security and information risk exposure.
- Executes activities in support of cyber security owned programs and related teams including security policies, vendor risk and compliance management, regulatory audits and compliance management, metrics, risk and performance indicators, executive and board reporting, security awareness and training, security integration and assessment of M&A and related ventures.
- Supports lines of business to perform security assessments and ensures timely execution of projects and programs while mitigating any security risks.
- Executes the evaluation of cyber security controls to ensure effectiveness, compliance and adherence to key controls and policies and drive its remediation efforts.
- Implements analysis of key GRC (governance, risk and compliance) risk information, including the cyber risk register, policy exceptions, audit findings and data security reviews and the preparation of reporting and dashboards as necessary to satisfy the Group's cyber reporting requirements at both a management and executive level.
- Monitors cyber compliance portals and acts as the liaison with communication groups driving awareness and adoption of cyber policies and standards across the BT Group.
- Leads liaison for cyber audits and maturity assessments assisting with reviews and providing artefacts as needed.
- Mentors other Cyber Security Governance & Assurance professionals, helping to improve the team's abilities by acting as a technical resource.
- Champions, continuously develops and shares with team knowledge on emerging trends and changes in Cyber Security Governance & Assurance.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Essential Skills / Experience
- Security Assurance & Governance Experience (e.g. assurance reviews, control testing, audit support, governance forums)
- Governance, Risk Management, Compliance & GRC Tooling (e.g. risk assessments, remediation activities, compliance reporting, governance platforms/GRC tools)
- Policy, Standards & Control Framework Design (e.g. ISO27001, NIST, CIS)
Desirable Skills / Experience


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- Certifications relevant to cyber security, governance, or risk management (e.g. CISSP, CISM, CRISC, ISO27001 Lead Implementer/Auditor or equivalent)
- Experience in regulated industries (e.g. telecoms, finance, public sector)
- Exposure to audit management and external certification processes
- Knowledge of cloud security governance and modern security practises (DevSecOps, Zero Trust)
- Experience influencing security culture and driving awareness across teams
- Familiarity with BT or similar large-scale enterprise environments
Our Package
Tailored benefits make a real difference. That’s why we offer a comprehensive range to support your growth, wellbeing, and everyday life.
You can design the package to suit you and your lifestyle.
Your core benefits include:
- 10% on target annual bonus
- Access to an online private GP 24/7 for you and your immediate family
- Market-leading paid carers leave with up to 2 weeks off
- Equalized maternity, paternity, and adoption leave – 18 weeks’ full pay and 8 weeks’ half pay
- Discounted EE and BT products, including mobile and broadband
- Market leading Pension scheme – 5% from you and 10% from us
- Holiday purchase scheme
You can select additional benefits, including healthcare, dental, gym memberships and more when you’re ready.
Ready to connect for good and help shape the future? Apply now.
BT Group is the UK’s leading communications group and the holding company behind some of the country’s most recognised brands – including BT, EE, Openreach and Plusnet. Our purpose is as simple as it is ambitious: we connect for good. Our customers include consumers, small, medium and large businesses, public sector organisations and other communications providers.
BT Group’s role is about setting direction, unlocking value and creating the conditions for our brands and businesses to thrive.
Having come through the most capital-intensive phase of our fibre investment, our focus now is on what comes next – simplifying how we operate, using technology and AI to work smarter, and organising ourselves to serve customers better and grow sustainably. Group teams shape strategy, policy, brand, capital allocation and transformation, helping the whole organisation perform at its best.
We have a singular culture that unites all our people: we are customer-first challengers, who are committed, clear and connected. These behaviours unite us as one team to deliver for our colleagues, our customers, our stakeholders and the country. Joining BT Group means working at the heart of a business that matters to the UK, with the opportunity to shape decisions, influence outcomes and help set the future course of one of the country’s most important companies.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location