hirly

Apply with hirly

Cyber Security Regulatory Compliance and Process Improvement Manager

Astrazeneca · UK - Macclesfield

Upload your resume to see how well you match this job — free, in seconds, no account needed.

Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.

Already have an account? Sign in to see your saved application

Cyber Security Regulatory Compliance and Process Improvement Manager Macclesfield, UK (3 days on site per week) About AstraZeneca AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery, development and commercialisation of prescription medicines for some of the world’s most serious diseases. But we’re more than one of the world’s leading pharmaceutical companies. At AstraZeneca, we are pioneering new frontiers by identifying and treating patients earlier, working towards the aim of eliminating cancer as a cause of death. Come and join our AZ team where you will play a pivotal role in this exciting period of development!! We are looking for an IT security professional who understands that security is a journey rather than a destination. Cybersecurity cannot be permanently “fixed”; instead, we must continually improve our processes, controls, and risk position against an evolving threat landscape. The successful candidate will understand that technology alone cannot solve cybersecurity challenges and that effective security depends on strong governance, collaboration, awareness, and sustainable ways of working. As part of this capability, the role holder will help ensure that AstraZeneca’s information assets are adequately protected in relation to confidentiality, integrity, and availability. The role will support the implementation of cyber regulatory requirements, drive improvements to cybersecurity processes and controls, and help maintain a clear, business-connected IT security policy and compliance framework. Key Responsibilities:

  • Regulatory Implementation and Monitoring : Translate global, regional, and local cybersecurity regulations, standards, and supervisory expectations into practical business requirements, controls, processes, and implementation activities. Support monitoring of regulatory developments and communicate their implications to relevant collaborators.
  • Process Improvement and Control Uplift : Find opportunities to improve cybersecurity processes, governance, controls, and ways of working. Drive practical and sustainable improvements through collaboration, analysis, clear documentation, and diligent follow-up.
  • Governance and Stakeholder Management : Coordinate cybersecurity regulatory and compliance governance activities by preparing materials, gathering inputs, tracking actions, and providing clear updates on compliance posture, readiness, risks, and delivery status. Support governance forums and ensure decisions and actions are followed through to completion.
  • Policy and Compliance Framework : Support the maintenance and continuous improvement of AstraZeneca’s IT security policy framework, regulatory compliance framework, and associated controls. Ensure that these remain aligned with regulatory expectations, internal risk management practices, and the organisation’s security objectives.
  • Training and Awareness : Support the development and delivery of cybersecurity regulatory training and awareness activities for leadership teams and key business functions, including Manufacturing, Quality, Supply Chain, and R&D . Help collaborators understand their obligations and the practical implications of cybersecurity requirements.
  • Risk, Assurance, and Gap Assessment : Conduct or support security assurance activities, risk assessments, regulatory gap assessments, and control reviews across functions, markets, and sites. Assess complex situations, balance strategic and tactical requirements, and support the identification and prioritisation of remediation activity.
  • Audit, Evidence, and Remediation : Gather, review, organise, and maintain traceable and defensible compliance evidence for internal and external audits, assurance reviews, and regulatory assessments. Track remediation actions and work with control owners and stakeholders to ensure identified gaps are addressed effectively and on time.
  • Incident Reporting and Regulatory Response : Support cybersecurity incident reporting obligations under applicable frameworks, including NIS2/CER,

UK Nis

, and other relevant regional regulations. Coordinate inputs across Legal, Compliance, Incident Management, and technical teams to support reporting, documentation, and regulatory response activities.

  • Cross-Functional Collaboration and Assurance Opportunities : Work closely with Enterprise Risk & Compliance, R&D, Operations, IT/OT, Engineering, and regional market teams to embed cybersecurity and regulatory expectations into day-to-day activities. Identify new security assurance opportunities and support the management of supplier- and customer-related cybersecurity requirements. Requirements:
  • A degree in information security, cybersecurity, computer science or a closely related subject area. Additionally, a recognised professional certifications such as CRISC, CISM, CISSP.
  • Significant hands on experience in cybersecurity, cybersecurity regulatory compliance, cyber risk, IT risk, security assurance, process improvement, controls, or compliance frameworks within a large, complex, multinational organisation.
  • Experience interpreting and applying cybersecurity regulations, standards, policies, or supervisory expectations in a practical business environment, including across multiple jurisdictions in EMEIA and the UK.
  • Experience supporting or maintaining cybersecurity control frameworks, IT security policies, compliance activities, assurance processes, and risk remediation activity.
  • Strong knowledge of frameworks such as

Nist Csf

and ISO 27001.

  • A good understanding of the relationship between cybersecurity, enterprise risk, legal interpretation, operational resilience, regulatory compliance, and business objectives.
  • Experience conducting or supporting gap assessments, control reviews, remediation tracking, process improvement, and security posture uplift activities.
  • Experience supporting audits, assurance reviews, regulatory assessments, and evidence-based compliance processes, with the ability to produce clear, accurate, and well-structured documentation.
  • Good awareness of IT architecture, design, configuration, implementation, and the range of controls needed to protect information assets across technology and business environments.
  • Strong communication with the ability to translate complex regulatory, technical, and risk-related information into practical actions and clear updates for senior stakeholders.
  • Ability to influence others and deliver positive outcomes through collaboration, including in situations where there is ambiguity, contending priorities, or limited direct authority.
  • Strong collaboration and relationship-building skills across technical, operational, legal, compliance, and business teams, including diverse and multinational environments.
  • Experience working in a quality- and compliance-focused environment, with the application of policies, procedures, standards, and documented controls. In Office Requirement: When we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world. Competitive salary and benefits package on offer! The successful candidate will have access to a flexible employee benefits fund, including holiday purchase and flexible time off, pension contributions, Share Save Plans, A performance recognition scheme and a competitive, generous remuneration package. Date Posted 01-Oct-2026 Closing Date 05-Oct-2026 Our mission is to build an inclusive and equitable environment. We want people to feel they belong at AstraZeneca and Alexion, starting with o