Rodeo
Get started

Rolls-Royce

Policy and Compliance Manager (D&IT)

Derby
Posted 1 day ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Job Description

Job Title: Policy and Compliance Manager (D&IT)
Working Pattern: Full Time
Working Location: Derby

About the Role

The Global Policy and Compliance Manager is responsible for developing, implementing, and overseeing Digital & IT policies, standards, and compliance frameworks. To support this activity, you will maintain a comprehensive inventory of compliance requirements, working closely with General Counsel to understand jurisdiction-specific obligations, regulatory timelines, and evolving legal expectations.

Supporting the VP Digital Risk & Compliance, this role focuses on establishing a pragmatic set of Digital & IT policies and standards that delivery teams can readily apply to embed appropriate security. It collaborates with key stakeholders—including General Counsel and cyber and technology leads—while incorporating leading cross-jurisdictional guidance (e.g., NCSC, CISA) to keep standards current, practical, and aligned to regulatory expectations. This role delivers significant value by reducing regulatory, cybersecurity, and operational risks through robust policy frameworks and controls, while ensuring adherence to global regulatory obligations. It drives consistency and standardisation of Digital and IT practices across regions and supports the VP Digital Risk & Compliance by providing oversight, guidance, and training related to the Information Security Management System (ISMS). The role also enhances audit readiness, improves control maturity, and increases operational efficiency through the application of automation and industry best practices.

Why Rolls-Royce?

Rolls-Royce is one of the most enduring and iconic brands in the world and has been at the forefront of innovation for over a century. We design, build, and service systems that provide critical power to customers where safety and reliability are paramount.

We are proud to be a force for progress, powering, protecting, and connecting people everywhere.

We want to ensure that the excellence and ingenuity that has shaped our history continues into our future and we need people like you to come and join us on this journey.

We’ll provide an environment of caring and belonging where you can be yourself. An inclusive, innovative culture that invests in you, gives you access to an incredible breadth and depth of opportunities where you can grow your career and make a difference.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What We Offer

  • Excellent development opportunities
  • Competitive salary
  • Exceptional benefits (bonus, employee support assistance, and employee discounts)
  • Hybrid working arrangement (minimum three days per week in the workplace)

What You Will Be Doing

  • Lead the development, implementation, and ongoing management of global policies, standards, and procedures, ensuring alignment with regulatory requirements, industry standards, and organisational strategy.
  • Establish and maintain robust governance frameworks to oversee the full policy lifecycle, including creation, approval, communication, implementation, and periodic review.
  • Provide clear, actionable guidance to business stakeholders on regulatory obligations, associated risks, and required remediation actions to maintain compliance and operational readiness.
  • Collaborate with regional business units, legal teams, and senior leadership, providing expert guidance on regulatory and policy matters to support compliance objectives.
  • Liaise with regulators, auditors, and external stakeholders, ensuring consistent, professional representation of the organisation and effective management of external relationships.
  • Work with the Cyber Security Programme Manager and VP Digital Risk & Compliance to design and deliver global compliance training programmes, promote a culture of ethical conduct and regulatory awareness, and ensure consistent communication of policy updates across the organisation.
  • Develop and maintain compliance reporting dashboards and KPIs, provide regular updates to governance committees and senior leadership, and ensure timely escalation of key risks and issues.
  • Drive continuous improvement of compliance frameworks and processes, leveraging technology and automation to enhance efficiency, and benchmarking practices against industry standards to ensure ongoing effectiveness.

Who We’re Looking For

At Rolls-Royce we put safety first, do the right thing, keep it simple, and make a difference. These principles form the behaviours that guide us and are an essential component of our assessment process. They are the fundamental qualities that we seek for all roles.

  • Significant experience in global policy, compliance, or risk management within highly regulated environments, ideally aerospace, defence, or similarly complex industries.
  • Demonstrated ability to influence and engage senior stakeholders, regulators, and government bodies across multiple jurisdictions and security environments.
  • Experience leveraging AI and automation to streamline policy and compliance processes, enhancing efficiency, reducing manual effort, and enabling effective horizon scanning for emerging requirements and threats.
  • Strong understanding of aerospace and defence regulatory frameworks (e.g., export controls such as ITAR/EAR, security classifications, government contracting requirements) and international compliance standards.
  • In-depth knowledge of IT governance, information security, and digital risk frameworks (e.g., ISO 27001, NIST, NIS regulations), with the ability to apply these in secure and sensitive environments.
  • Proven ability to design and implement global policy frameworks, including governance models, lifecycle management, and assurance processes.
  • Experience identifying and managing compliance, operational, and cyber risks, including development of robust control environments and risk mitigation strategies.
  • Experience working within environments involving classified information, national security requirements, or sensitive technologies, with a strong understanding of confidentiality and access controls.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Equal Opportunities Employer

We are an equal opportunities employer. We’re committed to developing a diverse workforce and an inclusive working environment. We believe that people from different backgrounds and cultures give us different perspectives which are crucial to innovation and problem solving. We believe the more diverse perspectives we have, the more successful we’ll be. By building a culture of caring and belonging, we give everyone who works here the opportunity to realise their full potential.

Please be aware that the priority will be given to employees identified as being at high risk.

It is advised that you inform your current manager of your application for this role.

You can learn more about our global Inclusion strategy at Our people | Rolls-Royce

Level: C
Job Category: Information Technology
Posting Date: 07 Aug 2026; 00:08
Posting End Date: 13 Aug 2026

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Policy development
Compliance management
Risk management
Information security
Governance frameworks
Regulatory compliance
Cybersecurity
Stakeholder engagement
Audit readiness
Automation
ISO 27001
NIST
NIS regulations
Export controls
IT governance

Location

Bristol, England, United Kingdom

Sign up to applySee more jobs like this