Information Security & Compliance Lead in Farnborough

Information Security & Compliance Lead in Farnborough

Farnborough Full-Time 60000 - 75000 € / year (est.) No home office possible
myairops

At a Glance

  • Tasks: Lead cyber security and data privacy initiatives while managing compliance and risk.
  • Company: Join myairops, a leader in SaaS for the aviation industry.
  • Benefits: Enjoy private healthcare, electric car scheme, and paid volunteering days.
  • Other info: Hybrid working model with opportunities for professional development.
  • Why this job: Make a real impact on security in a dynamic tech environment.
  • Qualifications: Experience in cyber security or relevant degree; strong communication skills required.

The predicted salary is between 60000 - 75000 € per year.

We are looking for a hands-on Information Security & Compliance Lead to take ownership of cyber security and data privacy across myairops. This role balances strategic oversight with practical, day-to-day security operations. You’ll be central to maintaining our SOC 2 Type II accreditation, managing third-party relationships, and ensuring our products and cloud infrastructure are secure, resilient, and compliant.

In this role, you will have the unique opportunity to lead our SOC2 audit activities, perform risk management reviews, and drive our vulnerability management program in alignment with industry best practices. Your keen eye for detail and exceptional problem-solving skills will be invaluable in analysing alerts from our monitoring platform and recommending necessary configuration changes and enhancements.

We are looking for a self-motivated individual with excellent communication and teamwork abilities, as you will collaborate extensively with cross-functional teams to achieve our security objectives. Your strong attention to detail, process-oriented mindset, and ability to meet deadlines with minimal supervision will be key to your success in this role.

About us: myairops is a leader of SaaS products to the aviation industry with customers across the globe with diverse challenges including corporate flight departments, brokers, medical providers, military and business aviation operators. Solutions are provided through innovative web-delivered software and connected mobile applications.

Responsibilities:

  • Lead security operations across our product and cloud environment (Azure), working closely with DevOps and engineering to ensure security best practices are followed.
  • Manage external relationships with security providers, including penetration testers and SOC 2 Type II auditors.
  • Own the SOC 2 audit process, coordinating internal preparation, evidence collection, and communication with auditors to ensure compliance is maintained.
  • Respond to customer security questionnaires, due diligence requests, and collaborate with sales and customer success to support commercial activities.
  • Oversee and maintain our public security and compliance portal.
  • Conduct technical audits, regular internal reviews, and assess controls against internal policies and external standards.
  • Translate audit findings and test results into clear, actionable tasks for the engineering and DevOps teams.
  • Perform vendor security assessments, managing risk across our supply chain.
  • Manage vulnerability and patch management, ensuring critical software libraries are kept up to date.
  • Enforce security policies, particularly regarding open-source software and licensing compliance.
  • Plan and lead annual Business Continuity and Disaster Recovery tests, reporting outcomes and driving improvements.
  • Evaluate and configure Azure security tooling, including firewall, DDoS, and WAF services.
  • Contribute to governance processes, reviewing change requests for potential impact on security, privacy, and service availability.
  • Collaborate with the Group CIO and DPO, contributing to wider organisational security and data privacy initiatives.

Skills, Qualifications and Experience required:

  • A solid background in cyber or information security, with experience operating at a similar level in cloud environments (ideally Azure) OR possess a degree within cyber or information security with the ability to demonstrate the attitude and aptitude to take this next career step.
  • Experience working in a software environment that is cloud native.
  • Experience of successfully achieving ISO27001 or preferably SOC2 Type 2.
  • Strong understanding of application security, cloud infrastructure, and DevOps practices.
  • Awareness of industry frameworks, such as NCSC Cyber Assessment Framework, Cyber Essentials Plus and OWASP.
  • Experience managing and selecting 3rd party vendors for audit and penetration testing.
  • Experience interacting with customer security and data privacy teams.
  • Experience conducting or managing penetration tests and security audits.
  • Can produce network and security architecture designs using software such as Microsoft Visio.
  • Ability to assess risk and prioritise security tasks in a fast-paced environment.
  • A pragmatic communicator who can bridge the gap between technical teams and auditors/customers.
  • Excellent communication and teamwork skills to collaborate effectively with cross-functional teams.
  • Detail-oriented, process-oriented and thorough.
  • Must currently hold or be able to hold UK security clearance to SC level or higher.

Advantageous:

  • Knowledge of security and data privacy controls within Microsoft Azure Cloud stack with hands on experience configuring and monitoring within Azure.
  • Knowledge of UK Government security standards.
  • Knowledge of PCI-DSS and achieving suitable standards within software.

Benefits:

  • Comprehensive Private Healthcare (after successful passing of probation)
  • Electric Car Scheme
  • Free Car Parking
  • Discounts at popular Retailers
  • 2 Paid Volunteering Days each calendar year (subject to line manager approval)
  • Investment in Training, Qualifications and Professional Development (Subject to insurance underwriting)

Information Security & Compliance Lead in Farnborough employer: myairops

At myairops, we pride ourselves on being an exceptional employer, offering a dynamic work environment in Farnborough that fosters innovation and collaboration. Our commitment to employee growth is evident through our investment in training and professional development, alongside a comprehensive benefits package that includes private healthcare and an electric car scheme. Join us to be part of a forward-thinking team dedicated to maintaining the highest standards of security and compliance in the aviation industry.

myairops

Contact Detail:

myairops Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security & Compliance Lead in Farnborough

Tip Number 1

Network like a pro! Reach out to folks in the industry on LinkedIn or at events. A friendly chat can open doors that a CV just can't.

Tip Number 2

Prepare for interviews by researching the company and its culture. Tailor your answers to show how your skills align with their needs, especially around security and compliance.

Tip Number 3

Practice makes perfect! Do mock interviews with friends or use online platforms to get comfortable discussing your experience in cyber security and compliance.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive!

We think you need these skills to ace Information Security & Compliance Lead in Farnborough

Cyber Security
Data Privacy
SOC 2 Type II Accreditation
Risk Management
Vulnerability Management
Attention to Detail
Problem-Solving Skills

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Information Security & Compliance Lead role. Highlight relevant experience in cyber security, cloud environments, and any specific achievements related to SOC 2 Type II or ISO27001. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a perfect fit for our team. Don’t forget to mention your problem-solving skills and teamwork abilities, as these are key for us.

Showcase Your Technical Skills:In your application, be sure to showcase your technical skills, especially those related to Azure security tooling and vulnerability management. We love candidates who can demonstrate their hands-on experience and understanding of industry frameworks like OWASP and Cyber Essentials Plus.

Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to submit all the necessary documents in one go. Plus, it helps us keep track of your application better!

How to prepare for a job interview at myairops

Know Your Stuff

Make sure you brush up on your knowledge of SOC 2 Type II accreditation and the specific security frameworks mentioned in the job description. Being able to discuss these topics confidently will show that you're serious about the role and understand its requirements.

Showcase Your Experience

Prepare examples from your past work where you've successfully managed security operations or led audits. Use the STAR method (Situation, Task, Action, Result) to structure your answers, making it easy for the interviewer to see your impact.

Communicate Clearly

Since this role involves collaboration with cross-functional teams, practice explaining complex security concepts in simple terms. This will demonstrate your ability to bridge the gap between technical teams and non-technical stakeholders.

Ask Insightful Questions

Prepare thoughtful questions about the company's current security challenges or their approach to compliance. This not only shows your interest in the role but also gives you a chance to assess if the company aligns with your values and career goals.