This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As Cyber Delivery Assurance Lead, you'll act as the British Airways cyber representative embedded within product delivery teams, ensuring cyber risk is actively managed and security controls are designed, implemented and operating effectively across programmes and products. This is a hands-on cyber assurance role. You'll be expected to bring strong practical experience of applying cyber security controls, assessing real systems and architectures, and working directly with delivery teams to embed security by design — not simply reviewing documentation or providing high-level guidance. Reporting to the Head of Cyber & IT Risk, you'll work closely with BA Tech Delivery teams, the BA Cyber Team and the IAG Cyber Security Office to ensure solutions meet BA's risk appetite and regulatory obligations.
Job Responsibility
Provide delivery assurance to ensure programmes and products operate within BA's cyber risk appetite
Work hands-on with delivery teams to embed security by design and ensure appropriate cyber controls are implemented and operating effectively
Interpret and apply cyber security policies, standards and guidelines across product releases and ongoing maintenance
Conduct threat and risk assessments across varied technology stacks and define proportionate mitigating controls
Provide authoritative advice on the practical application of security controls, legislation and regulatory requirements
Act as the cyber point of contact for programmes and products, supporting secure delivery end-to-end
Engage proactively with the IAG Cyber Security Office assurance and architecture functions to ensure consistency and best practice
Identify, manage and report cyber risks and exceptions throughout the product lifecycle
Support cyber governance forums and provide clear, accurate updates on security deliverables
Promote cyber risk awareness and support security awareness initiatives across the organisation
Requirements
Strong hands-on cyber security experience, with the ability to assess real systems and influence secure design and delivery decisions
Broad technical understanding of cyber security controls across multiple technology domains
Confidence working directly with engineers, architects and delivery teams to resolve security issues pragmatically
Ability to balance standards compliance with practical delivery constraints
Excellent stakeholder management skills, with experience influencing at senior levels
Calm, resilient approach in fast-paced and changing environments
Clear, positive communicator who can explain cyber risk and controls effectively
Proven experience providing cyber security assurance or secure delivery support in complex environments
Demonstrable experience performing threat and risk assessments and defining mitigating controls
Experience working in regulated environments with strong cyber and compliance requirements
Knowledge of cyber security frameworks and regulatory requirements such as NIST, PCI DSS, GDPR and NIS
Experience in agile delivery environments is advantageous
Relevant cyber security qualifications (e.g. CISSP, ISO27001 Lead Implementer, SANS GIAC or equivalent) desirable
Nice to have
Experience in agile delivery environments is advantageous
Relevant cyber security qualifications (e.g. CISSP, ISO27001 Lead Implementer, SANS GIAC or equivalent) desirable
What we offer
Brilliant staff travel benefits including unlimited basic and premium standby tickets on British Airways flights
Up to 30 discounted 'Hotline' airfares per year for yourself, friends, and family
Market-leading defined contribution (DC) pension with up to 7% employer contributions
Flexible benefits including critical illness cover, childcare vouchers, cycle to work, additional life insurance cover, private medical insurance, dental plan, and healthcare cash plan