Fantastic challenges. Amazing opportunities.
GKN Aerospace is reimagining air travel: going further, faster and greener! Fuelled by great people whose expertise and creativity sets the standards in our industry, we’re inspired by the opportunities to innovate and break boundaries. We’re proud to play a part in protecting the world’s democracies. And we’re committed to putting sustainability at the centre of everything we do, opening up and protecting our planet. With over 16,000 employees across 33 manufacturing sites in 12 countries we serve over 90% of the world’s aircraft and engine manufacturers and achieved sales of £3.35 bn.in 2023. There are no limits to where you can take your career.
Job Summary
The role of Cyber Security Officer is responsible for interpreting regulatory and contractual requirements, mapping controls, assessing controls and advising IT/OT and business teams on control implementation. The Cyber Security Officer is expected to support activities for security risk management, reporting, policy lifecycle, training and awareness, governance, risk and compliance program delivery, and third-party risk management. This position will be collaborating with stakeholders across various business departments such as IT, Legal and Compliance, and HR to ensure risks are managed effectively and efficiently in accordance with company policies and applicable requirements.
Job Responsibilities
Safety:
1. Required to follow all HSE rules and regulations. Must wear appropriate PPE as required.
Governance:
2. Support the development, implementation and maintenance of strong governance, risk and compliance processes.
3. Continuously improve the security framework, methodology, standards, and system of internal controls.
4. Report on findings, track status, and ensure corrective actions are complete and sustainable.
5. Support operational reporting, management communications, and executive governance committees.
6. Support and/or lead continuous improvement initiatives to deliver on operational and strategic goals.
7. Sustain relationships with auditors, regulators, and compliance partners.
Risk and Compliance:
8. Support risk identification and assessment, response and mitigation, control monitoring and reporting.
9. Gather and evaluate information, including to support auditors, regulators, and compliance partners.
10. Develop and perform tests, to evaluate the design and effectiveness of key controls as is necessary for compliance.
11. Review test findings, identify control weaknesses, present results, and recommend actions to remediate issues.
12. Support issue management, risk acceptances, and the corrective action program (POAM).
13. Deliver high quality reporting (data, reports, presentations), communicating effectively in both technical and business terms.
14. Support workforce security activities including culture, awareness and training.
15. Assist in the maintenance of the US Defence certification and accreditation.
16. Assist in the coordination and response to alerts and directives (US-CERT / CISA), and submission of incident reports to applicable authorities.
17. Coordinate local incident response activities, and liaison with security operations, business, regulators and third parties.
18. Complete supplier assurance questionnaires and conduct risk assessments.
GRC Systems Administration:
19. Support operation and administration of GRC systems for Cyber Security and IT.
20. Support, develop, and configure GRC system services and improvements.
21. Specialize in questionnaires, workflows, reports, and dashboards.
22. Serves as a resource to Cyber Security and IT/OT and business teams on GRC matters.
Job Qualifications
Required Qualifications:
23. Bachelor’s Degree in a technology-related field or equivalent experience.
24. 3+ years of experience with a focus on security and compliance.
25. Must be fluent (speaking and reading) the English Language
26. Must be a US Citizen or Green Card Holder due to program security clearance requirements and/or SSA requirements.
27. Must hold or be capable of obtaining and maintaining DoD SC Clearance (or higher).
Additional Qualifications:
28. Experience with cyber security governance, risk, and compliance management.
29. Experience in writing policies, procedures, and controls in one or more standards/frameworks.
30. Experience with UK HMG/MOD Information security requirements, accreditation and best practice security solutions for the UK defence sector.
31. Knowledge of computer networking concepts, and network and system security methodologies.
32. Knowledge of risk management processes.
33. Knowledge of cyber threats and vulnerabilities.
34. Ability to work in a large, highly regulated complex environment.
35. Ability to work well under minimal supervision and the skills to deal with ambiguity.
Preferred Qualifications:
36. Experience coordinating tasks to complete third party assessments.
37. Experience in RMF for US DoD security programs and/or with risk management practices in both a compliance and security context.
38. Knowledge of Aerospace regulations and export control requirements.
39. Knowledge of NISPOM, JSIG, ICD 503 and/or DCSA DAAPM.
40. Knowledge of CMMC, NIST SP 800-171 and/or NIST SP 800-53, ISO 27001.
41. Knowledge of DISA STIG and/or equivalent implementation guidance.
42. Professional information security certification like CISSP, CISM, or other relevant security-related designation.
We’ll offer you fantastic challenges and amazing opportunities. This is your chance to be part of an organisation that has proven itself to be at the cutting edge of our industry; and is committed to pushing the boundaries even further. And with some of the best training on offer in the industry, who knows how far you can go?
A Great Place to work needs a Great Way of Working
Everyone is welcome to apply to GKN. We believe that we can only achieve our ambitions through a coming together of diverse minds who enjoy collaborating in an inspirational environment. Through our commitment to diversity, inclusion and belonging and by living our five powerful principles we’ve created a culture where everyone feels welcome to contribute. It’s a culture that won us ‘The Best Workplace Culture Award’. By embracing and celebrating what makes us unique we encourage everyone to bring their full self to work.
We’re also committed to providing an accessible recruitment process, so if you require reasonable adjustments at any stage during our recruitment process please get in touch and let us know.
We are the place where human dreams, plus human endeavour, shape the future of aerospace innovation and technology.
#LI-HYBRID