← Back to jobs

Information Security Incident and Risk Manager

Skills

iso 27001jiranistrisk assessmentsharepoint

Description

Job Title\: Information Security Incident and Risk Manager

Location\: Portsmouth Naval Base - Remote Working Available with some occasional travel to site working

Grade\: GG10

You’re expected to have completed 12 months in role prior to applying for an advertised vacancy and you should also discuss the internal opportunity with your line manager to ensure sustained business continuity and to further support your career development.

We know there may be exceptional individual circumstances that impact this, in the first instance please discuss this with your line manager.

If you don’t feel you can talk to your line manager, you can contact your HRBP.

PLEASE NOTE\: Should you be invited for interview; you acknowledge that the Recruitment team will contact you and your line manager regarding your application for this opportunity.

Who we are\:

Join BAE Systems and you’ll be part of something bigger. As a valued member of our global colleague network, you’ll bring your unique skills and perspectives to help pioneer progress and protect what matters most. You’ll be trusted to play your part in delivering the advanced, technology-led defence, aerospace and security solutions of tomorrow, shaping a safer future, for all of us.

From the depths of the ocean, to the far reaches of space, there’s no limit to where a career at BAE Systems could take you.

Job Description\:

This role is responsible for leading the management of information security incidents and cyber risk across the business, ensuring potential threats are identified, assessed, and mitigated effectively. Working closely with stakeholders across technical and non-technical teams, you will coordinate incident response activities, maintain risk registers, drive security improvements, and support compliance with industry and regulatory standards. This is an excellent opportunity for an experienced security professional looking to influence security strategy within a complex and highly regulated environment.

Core duties\:

  • Support the investigation, coordination and resolution of complex cyber and information security incidents, working with stakeholders across the business and wider enterprise security teams.
  • Own the Information Security Risk Register, ensuring risks are identified, assessed, tracked and reported to support effective decision-making.
  • Conduct and facilitate security risk assessments across projects, systems and business change initiatives, providing strategic risk-based recommendations.
  • Drive continuous improvement of incident response, risk management and security governance processes, ensuring consistency and operational effectiveness.
  • Design and lead cyber incident simulation and tabletop exercises, enhancing organisational preparedness, resilience and response capability.
  • Act as a senior Information Security SME, advising stakeholders on security risks, regulatory requirements, compliance obligations and industry best practice.

Essential Skills\:

  • Strong understanding of cyber security principles, risk assessment methodologies, security governance, and frameworks such as ISO 27001, NIST, DEF STANs and DEF CONs.
  • Experience leading or coordinating cyber/information security incidents, investigations, evidence gathering, lessons learned activities, and crisis response.
  • Proven ability to assess, manage and communicate security risks, maintain risk registers, and support risk acceptance processes within regulated or government environments.
  • Confident engaging with stakeholders at all levels, translating technical and non-technical information, influencing decision-making, and driving collaborative outcomes.
  • Experience using tools such as Archer, SharePoint and Jira, alongside producing clear, audit-ready documentation, reports, risk assessments and incident records.

Why BAE Systems?

Here you’ll build a career with purpose and limitless possibilities. With lifelong learning and meaningful work, this is a place where you can grow your career with confidence and be empowered to be your best. You’ll be recognised for your contribution and enjoy rewards tailored to what’s most important to you and your family, support for your financial and personal wellbeing, as well as a balanced lifestyle. In an environment embracing sustainable ways of working and with a strong sense of shared purpose, our supportive culture is a place you can feel you belong and proud of the difference you make.

A place where everyone can thrive\:

We’re committed to building an inclusive workplace where everyone feels valued and supported. We know that a diversity of backgrounds, perspectives and experiences strengthens our teams and is vital to the work we do.

We welcome applications from all suitably qualified people, who are BAE Systems employees and have been in their current role for 12 months or longer.

Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks.

Closing Date\: 23rd October 2026

We reserve the right to close this vacancy early if we receive sufficient applications for the role. Therefore, if you are interested, please submit your application as early as possible.

#LI-RG1

#LI-Hybrid

Get similar jobs in United Kingdom by email

We'll email you when new jobs similar to this one appear.

Similar jobs

Explore more Information Security Incident and Risk Manager jobs in United Kingdom.

Finding similar jobs…