Cyber Security Regulatory Compliance and Process Improvement Manager

Company: AstraZeneca
Apply for the Cyber Security Regulatory Compliance and Process Improvement Manager
Location: Macclesfield
Job Description:

Overview

In this role you will translate global cybersecurity rules into practical requirements, drive improvements to governance and controls, and sustain a business‑aligned compliance framework. You’ll collaborate across Legal, Compliance, IT and business functions to protect information assets while meeting regulatory expectations. You’ll shape security posture through risk assessments, evidence, and remediation activities across regions. This is a chance to influence security governance in a large multinational with a patient‑focused mission.

Pay / Benefits

  • competitive salary and benefits package
  • flexible benefits fund including holiday purchase and flexible time off
  • pension contributions
  • Share Save Plans
  • performance recognition scheme

Responsibilities

  • Regulatory implementation and monitoring: convert regulations into actionable controls and communicate implications to collaborators.
  • Process improvement and control uplift: identify opportunities to enhance cybersecurity processes and sustain improvements.
  • Governance and stakeholder management: support governance forums, track actions, and report on compliance posture and delivery status.
  • Policy and compliance framework: maintain and improve IT security policy and regulatory frameworks to stay aligned with risks and objectives.
  • Training and awareness: develop and deliver regulatory cybersecurity training for leadership and key functions.
  • Risk, assurance, and gap assessment: conduct or support risk assessments, gap analyses, and control reviews to prioritise remediation.
  • Audit, evidence, and remediation: gather and manage evidence for audits, track remediation actions with owners.
  • Incident reporting and regulatory response: support incident reporting obligations and coordinate with Legal, Compliance, and technical teams.
  • Cross-functional collaboration and assurance: embed regulatory expectations across Enterprise Risk & Compliance, R&D, Operations, IT/OT, and partners.

Key requirements

  • Degree in information security, cybersecurity, computer science or closely related subject.
  • Professional certifications such as CRISC, CISM, CISSP.
  • Significant hands-on experience in cybersecurity regulatory compliance and risk within a large multinational.
  • Experience interpreting regulations across multiple jurisdictions (EMEIA and UK).
  • Experience supporting control frameworks, policies, assurance processes, and remediation activities.
  • Strong knowledge of NIST CSF and ISO 27001.
  • Understanding of the relationship between cybersecurity, risk, legal interpretation, resilience, and business objectives.
  • Experience conducting gap assessments, control reviews, and evidence-based compliance processes.
  • Good awareness of IT architecture and controls to protect information assets across environments.
  • Strong communication to translate regulatory and risk info into practical actions for senior stakeholders.
  • Ability to influence and collaborate in ambiguous, multi-priority environments.
  • strong communication
  • ability to influence others
  • collaboration across diverse teams
  • NIST CSF
  • ISO 27001
  • cybersecurity controls and governance

…

Posted: October 3rd, 2026