IT Security Specialist x4

Listing reference: atns_000930
Listing status: Online
Apply by: 5 August 2026
Position summary
Industry: Aviation & Aerospace
Job category: Informatics
Location: Bedfordview
Contract: Permanent
Remuneration: Market Related
EE position: No
Introduction
To identify cybersecurity risks and mitigate them through the deployment of technologies and processes, and the creation of awareness.
Job description

Monitoring – Conduct continuous scanning and security monitoring of all IT cybersecurity domains, i.e., networks, Firewalls, Anti-virus, Mobile devices, and Patch management. Monitor IT security governance with ATNS to ensure standards are maintained. Perform continuous threat and vulnerability management monitoring. Monitor compliance with ICT Security policies, processes, and procedures. Identify, analyse, and assess potential security risks and develop effective mitigation plans and actions to avoid or minimise their occurrence. Make recommendations based on monitoring outputs to improve the organisation's security posture. Participate in an integrated IT security forum. 

Security policies and frameworks – Ensure that the IT security architecture meets all cybersecurity requirements. Manage dependencies across business areas and ensure that IT security components are aligned. Develop and implement organisation-wide policies, programmes, and ongoing practices to preserve the availability, integrity and confidentiality of information resources in compliance with applicable security governance and standards. Identify and implement suitable tool sets to manage the IT security environment 

Cybersecurity – Operate and control the Information Security Management System (ISMS). Implement key Information Security projects as required. Conduct information gathering on internal and external security intelligence for the investigation of security incidents. Investigate, respond to and take action on information security incidents. Responsible for writing incident reports and submitting them to Senior Management for decision-making purposes. Selects, applies, and ensures adherence to good information security practices. Ensure internal and external suppliers and partners implement security to the required standard and maintain positive relationships with vendors. Ensures that all IT risks are mitigated and addressed. Responsible for investigation into incidents related to recovery of deleted files, analysing and interpreting data linked to crime, analysing mobile telephone records and uncovering links between events, groups and individuals through the pursuit of data trails. Maintains detailed records of investigations to be used as evidence in internal disciplinary hearings as well as the court of law. 

Governance- Manage IT security events/incidents effectively, ensuring compliance with the IT security policy. Manage and comply with all IT policies, processes, procedures and standards relating to IT security systems. Manage configuration and change-control records for IT security system activities. Develop metrics that allow the enterprise to gauge the success of security system investments. Monitor and report on IT Disaster Recovery exercises conducted with the business across all IT systems to ensure business continuity and make recommendations to support continuous improvement. Develop the Disaster Recovery Plan in accordance with business requirements and review it regularly to ensure its relevance and effectiveness. Conduct/ review and sign off on IT Security audits 

Minimum requirements

Minimum Formal Qualifications: 

Degree or diploma in Computer Science, IT or Engineering

Certification as an Information Systems Security Professional (CISSP) is required

Certification as an Information Security Manager (CISM) is required

Certification as an Information Systems Auditor (CISA) is required

Other related certifications will be accepted instead of any one of the abovementioned ones when necessary

 

Minimum Years of Experience: 

Minimum 3 years’ experience in the IT environment, of which 2 years should be in an enterprise IT security function

 

Our website uses cookies so that we can provide you with the best user experience. By continuing to use our website, you agree to our use of cookies.