About the Role
The Head of Cyber Governance and Assurance is accountable for establishing and leading the Group-wide cyber governance, risk, and assurance function across International Airlines Group (IAG). This role builds a risk-led, threat-informed, and resilience-focused assurance program, integrating cloud and IT resilience, continuous KPI monitoring, vulnerability remediation, and business continuity readiness.
Responsibilities
- Define and maintain the Group Cyber, Risk & Assurance Strategy, aligning with IAG’s risk appetite, regulatory requirements, threat landscape, and business priorities.
- Establish a cohesive assurance operating model within the Group.
- Integrate IT Resilience and DR assurance, ensuring the right capabilities and processes are in place.
- Strengthen KPI monitoring by establishing ongoing measurements that highlight resilience gaps and emerging risks.
- Own and maintain the IAG Group Cyber Risk Register, ensuring it accurately reflects the aggregated risk landscape across all OpCos.
- Define, maintain, and periodically review the Group Cyber Risk Appetite Statement in collaboration with the Group CISO.
- Conduct regular structured risk assessments at Group level, incorporating cross OpCo systemic risks, shared dependencies, and third-party supply chain risks.
- Develop and maintain a cyber risk taxonomy that enables consistent risk identification, classification, and escalation across all OpCos.
- Ensure that Group-level risks are escalated in a timely and structured manner.
- Engage with OpCo risk functions to understand local risk profiles and ensure material risks are surfaced to Group level.
- Drive quantification of cyber risk in business and financial terms.
- Provide Group-level assurance over IT/Cloud Resilience, backup/recovery capabilities, and disaster recovery test execution.
- Ensure resilience controls are measurable, tested routinely, and aligned with IAG's operational needs.
- Drive the evolution from periodic testing to continuous assurance.
- Oversee assurance of cyber crisis response readiness, simulation testing, and crisis playbook validation.
- Maintain an ongoing program of policy compliance assurance across all OpCos.
- Work closely with the Head of CTO to ensure assurance activity is aligned to policy maturity stages.
- Report on OpCo policy compliance status, tracking formal exceptions, waivers, and remediation plans.
- Establish and operate a structured, independent assurance capability that actively validates the accuracy and completeness of information reported by OpCos to Group.
- Design and own the IAG Group Cyber Assurance Framework.
- Establish and manage an annual Assurance Plan that prioritizes OpCo assessments based on risk profile, historical compliance performance, threat landscape, and regulatory obligations.
- Conduct active assurance reviews of OpCo-submitted compliance data, KPIs, and control attestations.
- Maintain and operate a Data Accuracy and Validation Framework.
- Identify and escalate instances where OpCo-reported data is inaccurate, incomplete, or inconsistent with independently obtained evidence.
- Operate the Group's risk-tiered Assurance Level model.
- Develop a continuous assurance monitoring capability.
- Maintain a consolidated Findings and Remediation Tracker.
- Provide structured feedback loops to OpCo CISOs and security leads.
- Provide clear, aggregated Group-level reporting on assurance effectiveness and remediation progress.
- Prepare executive-level dashboards and assurance summaries.
- Present assurance outcomes to the Group CISO, OpCo CISOs, senior technology executives, and, when needed, Audit & Risk Committees.
- Engage with Internal Audit to ensure cyber related audit activities are aligned with the assurance programme.
- Ensure the assurance programme satisfies regulatory requirements.
- Partner with OpCo stakeholder areas to drive effective remediation.
- Identify cross‑OpCo systemic weaknesses and propose Group-wide corrective programs.
Requirements
- 10+ years of cyber assurance leadership experience, with strong exposure to global, complex, regulated, federated organisations.
- Demonstrated experience leading cyber assurance, IT audit, or second‑line risk functions.
- Proven experience in resilience assurance—crisis readiness, BCP/DR, cloud / IT resilience, and recovery validation.
- Proven track record of designing and delivering independent assurance programs — including evidence validation, structured testing, and assurance reporting — in a complex, regulated environment.
- Direct experience of cyber risk management at enterprise or Group level, including risk register ownership, risk appetite setting, and Board/Committee reporting.
- Demonstrable experience challenging and independently validating data submitted by operating entities, identifying inaccuracies, and managing escalations professionally.
- Familiarity with regulatory frameworks (e.g. NIST CSF, ISO 27001/2, PCI DSS, GDPR, NIS/NIS2/UK NIS).
- Strategic, analytical, and able to define long‑term transformational assurance roadmaps.
- Strong business acumen with the ability to connect control failures to operational risk impacts.
- Excellent storyteller with data — able to translate metrics and complex control evidence into actionable insights.
- Strong leadership, influencing and stakeholder management skills across federated and multicultural organisations.
- Advocates “no surprises” assurance culture, independence, and transparency.
Skills
- Cyber assurance
- IT audit
- Risk management
- Resilience assurance
- Crisis readiness
- BCP/DR
- Cloud/IT resilience
- Recovery validation
- Independent assurance programs
- Evidence validation
- Structured testing
- Assurance reporting
- Risk register ownership
- Risk appetite setting
- Board/Committee reporting
- Data validation
- NIST CSF
- ISO 27001/2
- PCI DSS
- GDPR
- NIS/NIS2/UK NIS
- Strategic planning
- Analytical skills
- Business acumen
- Data storytelling
- Leadership
- Influencing
- Stakeholder management
Location
- London, UK
- Dublin
- Madrid
- Barcelona
- Kraków
Work Type
- Full-time
Experience Level
- Senior leadership
- 10+ years of cyber assurance leadership experience
Benefits
- Health insurance
- Pension
- Performance bonuses
About the Company
- IAG Transform is part of International Airlines Group (IAG), one of the world’s leading airline groups and owner of some of the biggest brands in the sky.
- IAG Transform provides creative and innovative solutions to drive sustainable transformation by delivering procurement and airline services, as well as group-wide systems across IAG.
- IAG is one of the world’s largest airline groups with 600+ aircraft carrying more than 122 million customers to 260 destinations across 91 countries each year.
- IAG brings together leading airline brands Aer Lingus, British Airways, Iberia, Level, Vueling.
- These are supported by IAG Loyalty that spans all its airlines and beyond, offering the global currency Avios and including BA Holidays, and IAG Cargo which delivers vital goods and produce around the world.
- As the first airline group globally to commit to net zero by 2050, sustainability is a core part of IAG’s strategy.
- IAG Transform plays a critical role in driving transformation across IAG and the aviation industry, through expertise and capabilities in procurement, technology, AI, innovation, and transformation.
Equal Opportunity
- We are an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.
