Digital Security Compliance Manager
3 days ago
Albacete
ph3Job Description /h3 pDigital Security Compliance Manager is responsible to ensure that AHE Information Security Management System (ISMS) compliance checklists for national and international regulations are established and maintained in conformity with AHE/AH global policies and directives, and that these ones, together with the associated processes, methods and tools, demonstrate compliance with the applicable Information Security regulations. /p ul liLead the implementation, maintenance, and continuous improvement of the Information Security Management System (ISMS) and the National and International Security Frameworks (ENS, NIS2, PART-IS,…). /li liDevelop, review, and maintain key compliance documentation (Statement of Applicability, Security Policies, Compliance Plans, Security Risk Assessments) and other control frameworks. /li liConduct maturity diagnostics, asset identification, gap analyses, and compliance assessments using CCN-STIC and Airbus Group methodologies. /li liDefine, configure and review technical security controls, including hardening, network security, business continuity and recovery plans. /li liInternal audit the security controls and measures. /li liCollaborate with the suppliers and vendor assessment and supervision. /li liEnsure Product Security. /li liActively participate in the management of certification and conformity audits (internal and external). /li liLead technical and organizational risk analysis and management, using methodologies such as Magerit, EBIOS RM or ISO 31000, for the selection and prioritization of controls. /li liAdvise on the life cycle of business and transformation projects, ensuring that solutions, platforms, and services are designed under the principles of “secure by design” and “zero trust”. /li liDevelop proofs of concept and/or pilots of cybersecurity tools on classified environments or environments configured under CCN-CERT regulations, evaluating their suitability. /li liIT Systems and networks administration and hardening. /li liWork cross-functionally with business areas, IT, security, and compliance, translating regulatory requirements into effective technical actions. /li liAdvice and Business Support: Provide expert advice to different business areas on the application of security regulations and the secure design of new IT services and projects, in addition to providing support in cross-functional cybersecurity tasks required by the Security department. /li liManage and coordinate security projects autonomously, ensuring alignment with corporate policies. /li liPrepare periodic reporting to the executive layer on the evolution, regulatory compliance, and status of security risks. /li liTraining, Awareness, and Physical Security: Develop and execute training and awareness plans on cybersecurity and physical security for personnel. Collaborate in the definition and implementation of physical security measures applicable to the systems. /li /ul h3Key Competencies /h3 ul liAutonomy, discretion and rigor to apply and follow standards and regulations. /li liHigh Communication skills and a team player able to work in an intercultural environment. /li liAble to assess situations quickly and decide on the best course of action. /li liAbility to work under pressure and in flexible time, if required. /li liManage Authorities Customer relations. /li liCapacity to anticipate risks and difficulties. /li liInitiative and proactivity. /li liSolution oriented / Welcome problems. /li liFlexible to travel on short notice when required. /li /ul h3Skills /h3 ul liEducation in telecommunications or computer engineering, or a related scientific-technical field. /li liAt least 10 years of experience (at least 4 years in Cybersecurity), with proven experience with security policies and processes design and implementation. /li liImplementation and maintenance of security controls based (at least 1 desired): ENS, NIS2, ISO/IEC 27001, CCN-STIC. 3 /li liSecurity risk management (at least 1 desired) (Magerit, EBIOS RM, ISO 31000). /li liProject management skills to develop security plans, manage security projects, coordinate suppliers and collaborate with other departments. /li liHigh Communication skills and a team player able to work in an intercultural environment. /li liSkills in IT Systems Administration, Networks, AI and digitalization is a plus. /li liCertifications in information security (CISSP, CISM, CRISC, Lead Auditor ISO 27001) is a plus. /li liKnowledge of Airworthiness regulation is a plus. /li liExperience in auditing is a plus. /li liTechnical knowledge of information security management and cybersecurity risks is a plus. /li liKnowledge of ISO 27001, ISO27005, EBIOS RM is a plus. /li liLanguages: English and Spanish mandatory, French is a plus. /li /ul h3Company /h3 pAirbus Helicopters España, SA /p h3Employment Type /h3 pPermanent /p h3Experience Level /h3 pProfessional /p h3Job Family /h3 pCyber Security /p h3Equal Opportunities /h3 pAirbus is committed to achieving workforce diversity and creating an inclusive working environment. We welcome all applications irrespective of social and cultural background, age, gender, disability, sexual orientation or religious belief. /p pAirbus is, and always has been, committed to equal opportunities for all. /p pAny impersonation of Airbus to do so should be reported to /p /p #J-18808-Ljbffr