- Location
- Derby - D Site - Sinfin D Site (UK-IC), United Kingdom · Bristol
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Legal
- Seniority
- Manager
- Closing date
- Today
- Source
- Workday
Description
Job Description
Job Title: Policy and Compliance Manager (D&IT)
Working Pattern: Full Time
Working location: Derby
The Global Policy and Compliance Manager is responsible for developing, implementing, and overseeing Digital & IT policies, standards, and compliance frameworks. To support this activity, you will maintain a comprehensive inventory of compliance requirements, working closely with General Counsel to understand jurisdiction-specific obligations, regulatory timelines, and evolving legal expectations.
Supporting the VP Digital Risk & Compliance, this role focuses on establishing a pragmatic set of Digital & IT policies and standards that delivery teams can readily apply to embed appropriate security. It collaborates with key stakeholders—including General Counsel and cyber and technology leads—while incorporating leading cross-jurisdictional guidance (e.g., NCSC, CISA) to keep standards current, practical, and aligned to regulatory expectations. This role delivers significant value by reducing regulatory, cybersecurity, and operational risks through robust policy frameworks and controls, while ensuring adherence to global regulatory obligations. It drives consistency and standardisation of Digital and IT practices across regions and supports the VP Digital Risk & Compliance by providing oversight, guidance, and training related to the Information Security Management System (ISMS). The role also enhances audit readiness, improves control maturity, and increases operational efficiency through the application of automation and industry best practices.
Why Rolls-Royce?
Rolls-Royce is one of the most enduring and iconic brands in the world and has been at the forefront of innovation for over a century. We design, build and service systems that provide critical power to customers where safety and reliability are paramount.
We are proud to be a force for progress, powering, protecting and connecting people everywhere.
We want to ensure that the excellence and ingenuity that has shaped our history continues into our future and we need people like you to come and join us on this journey.
We’ll provide an environment of caring and belonging where you can be yourself. An inclusive, innovative culture that invests in you, gives you access to an incredible breadth and depth of opportunities where you can grow your career and make a difference.
What we offer:
We offer excellent development opportunities, a competitive salary, and exceptional benefits. These include bonus, employee support assistance and employee discounts.
Your needs are as unique as you are. Hybrid working is a way in which our people can balance their time between the office, home, or another remote location. It’s a locally managed and flexed informal discretionary arrangement. As a minimum we’re all expected to attend the workplace for collaboration and other specific reasons, on average three days per week.
What you will be doing:
- Lead the development, implementation, and ongoing management of global policies, standards, and procedures, ensuring alignment with regulatory requirements, industry standards, and organisational strategy
- Establish and maintain robust governance frameworks to oversee the full policy lifecycle, including creation, approval, communication, implementation, and periodic review
- Provide clear, actionable guidance to business stakeholders on regulatory obligations, associated risks, and required remediation actions to maintain compliance and operational readiness
- Collaborate with regional business units, legal teams, and senior leadership, providing expert guidance on regulatory and policy matters to support compliance objectives
- Liaise with regulators, auditors, and external stakeholders, ensuring consistent, professional representation of the organisation and effective management of external relationships
- Working with the Cyber Security Programme Manager and VP Digital Risk & Compliance design and deliver global compliance training programmes, promote a culture of ethical conduct and regulatory awareness, and ensure consistent communication of policy updates across the organisation
- Develop and maintain compliance reporting dashboards and KPIs, provide regular updates to governance committees and senior leadership, and ensure timely escalation of key risks and issues
- Drive continuous improvement of compliance frameworks and processes, leveraging technology and automation to enhance efficiency, and benchmarking practices against industry standards to ensure ongoing effectiveness.
Who we’re looking for:
At Rolls-Royce we put safety first, do the right thing, keep it simple and make a difference. These principles form the behaviours that guide us and are an essential component of our assessment process. They are the fundamental qualities that we seek for all roles.
- Significant experience in global policy, compliance, or risk management within highly regulated environments, ideally aerospace, defence, or similarly complex industries
- Demonstrated ability to influence and engage senior stakeholders, regulators, and government bodies across multiple jurisdictions and security environments
- Experience leveraging AI and automation to streamline policy and compliance processes, enhancing efficiency, reducing manual effort, and enabling effective horizon scanning for emerging requirements and threats
- Strong understanding of aerospace and defence regulatory frameworks (e.g., export controls such as ITAR/EAR, security classifications, government contracting requirements) and international compliance standards
- In-depth knowledge of IT governance, information security, and digital risk frameworks (e.g., ISO 27001, NIST, NIS regulations), with the ability to apply these in secure and sensitive environments
- Proven ability to design and implement global policy frameworks, including governance models, lifecycle management, and assurance processes
- Experience identifying and managing compliance, operational, and cyber risks, including development of robust control environments and risk mitigation strategies
- Experience working within environments involving classified information, national security requirements, or sensitive technologies, with a strong understanding of confidentiality and access controls
We are an equal opportunities employer. We’re committed to developing a diverse workforce and an inclusive working environment. We believe that people from different backgrounds and cultures give us different perspectives which are crucial to innovation and problem solving. We believe the more diverse perspectives we have, the more successful we’ll be. By building a culture of caring and belonging, we give everyone who works here the opportunity to realise their full potential.
Please be aware that the priority will be given to employees identified as being at high risk.
It is advised that you inform your current manager of your application for this role.
You can learn more about our global Inclusion strategy at Our people | Rolls-Royce
Level C