At a Glance
- Tasks: Join our Cyber Security team to protect vital aerospace and defence operations.
- Company: Airbus Defence and Space is a leader in aerospace innovation and sustainability.
- Benefits: Enjoy competitive pay, flexible hours, hybrid work, and extensive personal development opportunities.
- Other info: Airbus promotes diversity and offers support for applicants with disabilities.
- Why this job: Be part of a passionate team tackling real-world cyber threats with cutting-edge technology.
- Qualifications: Technical skills in security tools, Python programming, and threat analysis are essential.
The predicted salary is between 36000 - 60000 £ per year.
**Job Description:** **SECURITY CLEARANCE: **Must have or be able to obtain security clearance eligibility to access UK Ministry of Defence establishments, working within ITAR and Export Control restrictions **LOCATION: ** Newport, South Wales, Portsmouth or Stevenage **TYPE: ** Full time **HOURS: ** 37. **WHAT\'S IN IT FOR YOU** * **Financial Reward: ** Competitive salary, annual profit share, contributory pension, share options, car leasing scheme, free onsite parking, season ticket loan, tax-free technology scheme, discounted shopping and much more * **Work / Life Balance: ** 37 hour week, flexible working around core hours and Friday afternoons off, hybrid working, up to 2 additional days per month as TOIL, option to buy/sell holiday * **Personal Development: ** Personalised development plan, Airbus Leadership University and unlimited access to 10,000+ E-learning courses, internal mobility including international opportunities * **Health & Wellbeing: ** Wellbeing benefits (including 24/7 online GP and mental health support), Employee Assistance Programme, discounted family health / dental insurance / eye tests, cycle-to-work scheme * **Family and Caregiving: ** Life assurance, enhanced pay for maternity, paternity, adoption and shared parental leave and caregiving * **Inclusive Environment: ** Wellbeing room, Multi-faith room, Employee Representative Groups (Gender, LGBTQ+, International, Generational, Disability, Social & Cultural Diversity, Neurodiversity) Our world is changing. And so are we. From our commitment to zero-carbon flight ( #ZEROe ) to cleaning up space , sustainability is at the heart of our purpose . So what\'s your next change? Airbus Defense and Space is looking for a passionate and talented Cyber Security Detection & Automation Engineer to join our international Incident Response Team (CSIRT), in Newport, Portsmouth or Stevenage. A mission critical part for us in order to secure our world-class business. This is a technical, hands-on role that will work with a variety of security tools and technologies protecting our whole enterprise. You will be responsible for managing our Cyber Threat Intelligence (CTI) research and Threat Hunting activities, the entire lifecycle of our detection rules repository and SOC automation stack. You will be responsible for the technical evolution of our SOC blueprint and managing enhancement projects to integrate new features and solutions into our Security Operation Centers (SOC). This is a fantastic opportunity to join a team who live and breathe cyber security and to work for a company with great products and technologies around the globe. **HOW YOU WILL CONTRIBUTE TO THE TEAM** * **Threat Analysis - **Leverage the organization’s CTI provider as a strategic asset , not just a data source-integrating external intel with internal context to assess real impact and relevance. Conduct in-depth analysis of cyber threats (APT groups, malware campaigns, zero-days, etc.) and assess their relevance to Airbus operations, especially the aerospace and defense-related. Translate complex threat data into clear, actionable intelligence for technical and non-technical stakeholders. Produce regular and ad hoc threat intelligence reports , briefings, and dashboards tailored to specific business units or leadership needs. * **Threat Hunting - ** Proactively hunt for signs of adversary presence within enterprise environments using threat intelligence, telemetry, and hypothesis-driven methods. Design and execute structured threat hunting playbooks based on known TTPs (e.g., MITRE ATT&CK) and emerging threats, enabling consistent, repeatable hunts. Develop code-based playbooks (e.g., Jupyter Notebooks or Python scripts) that integrate threat intelligence, log sources, and detection logic-making them reusable by SOC, IR, and detection engineering teams. Collaborate with detection engineers to convert hunt findings into long-term detections and SIEM use cases , contributing to continuous monitoring improvements. Continuously refine and document hunt processes and hypotheses for knowledge sharing across cyber defense teams. * **Monitoring & Anticipation - ** Maintain situational awareness of the evolving threat landscape through open-source intelligence (OSINT), commercial feeds, dark web monitoring , and collaboration with national cybersecurity bodies. Detect and flag early indicators of potential cyber campaigns targeting aerospace or defense sectors. Assist in the development and fine-tuning of detection rules and alerts for monitoring security systems (e.g., SIEM, EDR). Contribute in the specification of telemetry log sources and data normalization for its processing in Cyber Detection. Develop tools and techniques to identify patterns and anomalies in network traffic, system logs, and application data that could indicate security incidents (Threat Hunting). Implement adversary emulation tests to assess the quality of the detection rules * **Stakeholder Engagement - ** Build relationships with external CTI peers in industry and government to share best practices, TTPs (tactics, techniques, procedures), and threat actor profiles . Ensure timely and accurate dissemination of threat data to internal stakeholders across the organization, including CISO-level reports. * **Rapid Response Enablement - ** Design and maintain workflows for the rapid delivery of intelligence to incident response and risk teams, enabling faster decision-making and containment. Support post-incident analysis by enriching forensic investigations with relevant threat intelligence context. **ABOUT YOU** * **Technical Skills - ** Understanding of security tools such as EDR, Windows Logging, firewalls, intrusion detection/prevention systems (IDS/IPS). Deep knowledge of Operating System insights (Windows/Linux). Experience with Python is a requirement, PowerShell/Bash are a plus. Understanding of DevOps, git. * . * * **Analytical Skills - ** Strong knowledge of threat actor tactics, techniques, and procedures (TTPs) and frameworks like MITRE ATT&CK , Kill Chain, and Diamond Model. Proficiency with SIEM tools (e.g., Splunk, ELK), threat intelligence platforms (e.g., MISP, ThreatConnect), and endpoint detection tools (e.g., EDR/XDR). Experience building code-based hunting or automation playbooks (e.g., Python, Jupyter Notebooks, PowerShell ). Familiarity with scripting or automation for IOC enrichment, API integrations , and telemetry analysis. Ability to correlate multiple data sources and pivot across logs, alerts, and CTI for deeper investigation. Understanding of threat modeling, detection engineering , or purple teaming is a plus. **Not a 100% match? No worries! Airbus supports your personal growth with custom development solutions.** **HOW WE CAN SUPPORT YOU** Many of our staff work flexibly in many different ways, including part-time. Please talk to us at the interview about the flexibility you need and we’ll always do our best to accommodate your request. Please let us know if you need us to make any adjustments for the selection process - you can share this with your Talent Acquisition Partner if you are invited to interview. Examples may include (but not exclusive to) accessible facilities; auxiliary aids; room layout, etc. Any information disclosed will be treated in the strictest confidence. As a Disability Confident Employer, Airbus UK will offer an interview to any applicant that considers themselves to have a disability or long-term condition and meets the minimum criteria of the role (as set out in the job advert). To ‘opt in’, just select the option during your application submission and our Talent Acquisition team will contact you. * #LI:MF1 * This job requires an awareness of any potential compliance risks and a commitment to act with integrity, as the foundation for the Company’s success, reputation and sustainable growth. ****Company:**** AIRBUS Defence and Space Limited *Employment Type:* Permanent ------- *Experience Level:* Professional *Job Family:* Cyber Security By submitting your CV or application you are consenting to Airbus using and storing information about you for monitoring purposes relating to your application or future employment. This information will only be used by Airbus. Airbus is committed to achieving workforce diversity and creating an inclusive working environment. We welcome all applications irrespective of social and cultural background, age, gender, disability, sexual orientation or religious belief. Airbus is, and always has been, committed to equal opportunities for all. As such, we will never ask for any type of monetary exchange in the frame of a recruitment process. Any impersonation of Airbus to do so should be reported to emsom@airbus.com . At Airbus, we support you to work, connect and collaborate more easily and flexibly. Wherever possible, we foster flexible working arrangements to stimulate innovative thinking.
Airbus - Cyber Detection Engineer in London employer: Airbus
Airbus Defence and Space is an exceptional employer, offering a dynamic work culture that prioritises employee wellbeing and professional growth. With competitive salaries, flexible working arrangements, and a commitment to sustainability, employees are empowered to thrive in their roles while contributing to cutting-edge cyber security initiatives. The inclusive environment fosters collaboration and innovation, making it an ideal place for those seeking meaningful and rewarding careers in the aerospace and defence sectors.
Contact Details:
Airbus Recruitment Team
emsom@airbus.com
StudySmarter Expert Advice🤫
We think this is how you could land Airbus - Cyber Detection Engineer in London
✨Tip Number 1
Familiarise yourself with the specific security tools mentioned in the job description, such as EDR and SIEM tools. Having hands-on experience or knowledge of these tools will help you stand out during discussions.
✨Tip Number 2
Engage with online communities or forums related to cyber security, especially those focusing on threat intelligence and hunting. Networking with professionals in the field can provide insights and potentially lead to referrals.
✨Tip Number 3
Stay updated on the latest trends and threats in cyber security, particularly those affecting the aerospace and defence sectors. Being knowledgeable about current events can help you demonstrate your passion and expertise during interviews.
✨Tip Number 4
Prepare to discuss your experience with Python and any relevant coding projects you've completed. Showcasing your ability to develop code-based playbooks will be crucial in proving your technical skills to the hiring team.
We think you need these skills to ace Airbus - Cyber Detection Engineer in London
Cyber Threat Intelligence (CTI) Research
Threat Hunting Techniques
Knowledge of MITRE ATT&CK Framework
Proficiency in Python Programming
Experience with SIEM Tools (e.g., Splunk, ELK)
Understanding of EDR and IDS/IPS Systems
Analytical Skills for Threat Analysis
Ability to Develop Code-Based Playbooks
Familiarity with Open-Source Intelligence (OSINT)
Strong Communication Skills for Stakeholder Engagement
Experience with Incident Response Processes
Knowledge of Network Traffic Analysis
Understanding of Security Operations Centre (SOC) Functions
Ability to Correlate Multiple Data Sources
Some tips for your application 🫡
Understand the Role:Before applying, make sure you thoroughly understand the responsibilities and requirements of the Cyber Detection Engineer position. Tailor your application to highlight relevant experience and skills that align with the job description.
Highlight Technical Skills:Emphasise your technical skills in your CV and cover letter. Mention your experience with security tools, programming languages like Python, and any familiarity with frameworks such as MITRE ATT&CK. Be specific about your hands-on experience in cyber security.
Showcase Analytical Abilities:Demonstrate your analytical skills by providing examples of how you've successfully conducted threat analysis or threat hunting in previous roles. Use metrics or outcomes to illustrate your impact on security operations.
Personalise Your Application:Make your application stand out by personalising it for Airbus. Mention their commitment to sustainability and diversity, and express your enthusiasm for contributing to their mission in cyber security. This shows that you are genuinely interested in the company and its values.
How to prepare for a job interview at Airbus
✨Understand the Cyber Security Landscape
Familiarise yourself with current cyber threats, especially those relevant to the aerospace and defence sectors. Be prepared to discuss recent incidents or trends in cyber security and how they might impact Airbus operations.
✨Showcase Your Technical Skills
Highlight your experience with security tools like EDR, SIEM, and your proficiency in programming languages such as Python. Be ready to provide examples of how you've used these skills in previous roles, particularly in threat hunting or incident response.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving abilities in real-world scenarios. Practice articulating your thought process when faced with a cyber threat, including how you would analyse the situation and what steps you would take to mitigate it.
✨Engage with Stakeholders
Demonstrate your ability to communicate complex technical information to non-technical stakeholders. Prepare to discuss how you would build relationships with external CTI peers and share best practices within the organisation.