Cyber Security Manager overseeing business-wide cyber risk management at Heathrow. Shaping policies, ensuring compliance, and building regulator relationships for NIS standards.
Responsibilities
Lead day-to-day cyber risk management, ensuring risks are identified, assessed, and managed effectively across the business.
Develop and enhance risk management policies and standards, aligning with industry best practice and Heathrow’s enterprise risk framework.
Work closely with assurance teams to oversee compliance of key systems and drive corrective actions where needed.
Engage with regulators and authorities, including the Civil Aviation Authority, to support Heathrow’s compliance with NIS Regulations and other cyber resilience requirements.
Champion a culture of proactive risk management, driving continuous improvement and alignment with Heathrow’s strategic goals
Requirements
Degree-educated (or equivalent experience) with experience in cyber risk management, ideally across IT and OT environments.
Holds or working towards relevant certifications such as CISSP, CISM, C-RISC, CISA, or ISO 27001 Lead Auditor/Implementor.
Strong knowledge of information security controls, standards and frameworks, including ISO 27001, NIST, and NCSC CAF.
Solid understanding of the UK cyber regulatory landscape, particularly the NIS Regulations 2018; aviation sector experience (e.g. CAP1753) advantageous.
Experienced in applying risk management frameworks (e.g. ISO 27005, NIST RMF) within complex operational environments.
Proven leadership and stakeholder management skills, able to collaborate effectively with both technical SMEs and senior executives.
Site Security Officer supporting security operations at Saab Surveillance in Sweden. Managing risk analyses, security at events, and providing expertise on security projects.
Information Security Specialist responsible for protecting systems and data at Ituran. Collaborating with teams and ensuring compliance with security measures and regulations.
Senior Cloud & Information Security Engineer responsible for EC Markets' technical security posture. Designing and operating secure systems while ensuring regulatory compliance and cloud infrastructure security.
Product Security Engineer focusing on ensuring software resilience against attacks during development phases. Collaborating with DevOps and Engineering teams to enhance security protocols.
IT audit specialist responsible for executing technology and cybersecurity audits at an international bank in Zurich. Collaborating with top management to enhance internal controls and efficiencies.
IT Systemadministrator focusing on Sophos Security at bauXpert GmbH. Responsible for IT infrastructure management and support tasks in a hybrid environment.
Cyber Security Specialist designing and implementing security controls for Squarcle clients. Supporting compliance with regulations and best practices in a digital environment.
Head of Security at Street Group managing organizational security and working with IT and Engineering teams. Leading security posture and compliance while mitigating emerging threat vectors.
Security Consultant providing technical leadership in electronic security systems engineering for complex built environments. Leading projects through all lifecycle stages while engaging with clients and contractors.