At a Glance
- Tasks: Lead cybersecurity initiatives and ensure compliance across multiple sites in the UK.
- Company: Join a leading aerospace and defence company committed to innovation and security.
- Benefits: Enjoy a hybrid work model, competitive salary, and opportunities for professional growth.
- Other info: Be part of a diverse team that values creativity and collaboration.
- Why this job: Make a real impact in safeguarding critical information systems against cyber threats.
- Qualifications: 12+ years in cybersecurity with strong knowledge of risk management and security frameworks.
The predicted salary is between 60000 - 80000 £ per year.
We are seeking a highly experienced and strategic Information System Security Officer to lead our cyber and regulatory compliance programs across RTX business units for sites located in the UK. This role is critical for ensuring the cyber posture of the sites and for establishing the guidelines and actions needed to protect the company's Information Systems against cyber threats, respond to digital compliance risks, and foster a company‑wide culture of cybersecurity. The successful candidate will provide technical leadership, oversee multi‑site governance and risk management, and ensure alignment between RTX ES Cybersecurity services (including IT and OT) with Business functions to safeguard critical assets, applications, systems, and data.
The candidature is expected to follow a hybrid work model, balancing remote and on‑site presence based on business needs, key meetings, critical milestones, team collaboration needs, audits or incident response requirements. Remote work could be acceptable as long as the candidate can regularly visit the sites.
- Governance
- Ensure the management and local cyber governance of the Information Systems within the sites under ISSO scope.
- Ensure adherence to global and regional/local regulatory requirements and applicable frameworks (ISO 27001, ISO27005, NIST SP800-171, Cyber Essentials, CMMC Global etc.).
- Maintain the Information Security Management System (ISMS) or equivalent governance model.
- Define, implement, coordinate, manage and monitor activities related to the Part‑IS regulation (acting as Aviation Safety ISMS Manager).
- Drive internal and external audits, certifications, and compliance readiness across multiple sites.
- Continuously monitor emerging regulations and standards, ensuring proactive compliance and risk management.
- Ensure relationship and interface with cyber stakeholders in relation to site ecosystem including security authorities, customers & partners.
- Define, derive and maintain security policies, procedures and guidance for Restricted and Classified IS located on site (if any) and ensure their implementation with the support of DT team.
- Ensure accreditation activities on Restricted and Classified networks (when applicable).
- Execute an annual security awareness plan to reduce business compliance risks, cyber operational risks and to foster a cyber culture within the sites.
- Cyber Risk Management
- Manage information security risks (identification, evaluation and treatment) according to applicable enterprise‑wide cyber risk program and regulations including but not limited to Part‑IS and NIS2.
- As part of the risk management, the ISSO will perform/lead risk assessment for the sites and associated risk treatment plan with the support of DT Int'l Operations and RTX Global GRC teams.
- Oversee implementation of security controls (technical, administrative, physical) for applications, infrastructure, Cloud, and OT systems under ISSO scope.
- Ensure secure enablement of new technologies and digital transformation programs.
- Compliance
- Ensure compliance with applicable security requirements for the sites (internal policies, applicable regulations and customer frameworks).
- Ensure compliance with applicable security requirements for the third parties engaged with the sites (internal policies, applicable regulations and customer frameworks).
- Drive supplier cyber risks identification and treatment for the sites.
- Support enterprise‑wide compliance program (e.g., DT Assessment, Part‑IS internal audit) and external audit/assessment from customers and regulators (e.g., CASE audit, Part‑IS audit).
- Security Event and Incident Management
- Ensure that threat detection capabilities provided by RTX Cyber‑Defense team are fully implemented.
- Monitor, detect and respond to cyber threats exposing Restricted and Classified networks (when applicable).
- Support the RTX Cyber‑Defense Operations for any event or incident occurring on the sites.
- Drive incident response preparedness and act as point of contact for security incidents.
- Operations
- Provide expert security guidance to DT Int'l Operations (e.g., vulnerability management, remediation plan execution, support on new cyber programs).
- Support special cyber programs such as SURGE and drive critical vulnerabilities remediation in support to DT Int'l operations and CART team.
- Champion business resilience by aligning DT and OT security strategies with business continuity and disaster recovery plans.
- Provide support to the DT team on activities related to business continuity/recovery (BIA, DRP etc.).
- Technical Leadership
- Act as the point of contact for various compliance programs (e.g., EASA Part‑IS, NIS2, DFARS CMMC Global etc.) where applicable.
- Provide expert security guidance to Engineering, Operations, and Value‑Stream Leaders teams.
- Collaborate with local stakeholders (e.g., Engineering, Operations, Safety, Quality) to ensure seamless integration of information security requirements.
- Represent Information Security with external regulators, customers, and partners.
- Monitor regulatory, threat landscape and technology evolution in cybersecurity.
- Mentor and develop junior security professionals, promoting a cybersecurity culture.
Qualifications
- Bachelor's degree in Computer Science, Information Security, Engineering, or related field with 12+ years of experience in cybersecurity or Master's degree in Computer Science, Information Security, Engineering, or related field with 10+ years of experience in cybersecurity.
- Knowledge or experience in the following domains (at least 5): Risk Management, Security Architecture & Engineering, Asset Security, Communication & Network security, Security Assessment and Testing, IAM, Security Operations.
- Strong working knowledge of security frameworks: ISO 27001, 27005, NIST (CSF, SP800-171, SP800‑82) etc.
- Experience leading multi‑site/global compliance programs.
- Excellent knowledge of risk management methodologies and audit practices.
- Strong communication and stakeholder management skills at C‑level.
- Relevant certifications (one or more): CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, ISO 27005 Risk Manager, OSCP, CEH, GIAC etc.
- Experience in regulated industries (e.g., aerospace, defense, manufacturing, or critical infrastructure).
- Knowledge on EASA Part‑IS, NIS2, national MoD security regulations.
- Experience working with/for regulators/authorities or customers (e.g., Aerospace & Defense OEMs).
- Experience and expertise in the following security fields: threat monitoring & detection, security incidents management, penetration testing and/or technical audit, software development security (threat modeling, secure coding).
- Familiarity with Industrial Control Systems (ICS) / OT cybersecurity.
- Background in safety‑critical or regulated environments.
Soft Skills
- Demonstrate ownership and accountability for assigned projects/programs.
- Curious, passionate.
- Ability to withstand pressure.
- Ability to work across the organization.
- Ability to influence.
- Ability to report back to management.
- Team management.
- Sense of general interest, committed.
Additional Information
- This job may require having national security clearance. Must be eligible to obtain a higher security clearance.
- We believe a multitude of approaches and ideas enable us to deliver the best results for our workforce, workplace, and customers. We are committed to fostering a culture where all employees can share their passions and ideas so we can tackle the toughest challenges in our industry and pave new paths to limitless possibilities.
Information System Security Officer - ISSO in Wolverhampton employer: RTX Corporation
At RTX, we pride ourselves on being an exceptional employer, offering a dynamic work culture that values innovation and collaboration. Our hybrid work model allows for flexibility while ensuring that our Information System Security Officers are at the forefront of cybersecurity, with ample opportunities for professional growth and development. Located in the UK, employees benefit from a supportive environment that encourages continuous learning and engagement with cutting-edge technologies, making it a rewarding place to advance your career in cybersecurity.
StudySmarter Expert Advice🤫
We think this is how you could land Information System Security Officer - ISSO in Wolverhampton
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including RTX Corporation, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through RTX Corporation
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at RTX Corporation. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Information System Security Officer - ISSO in Wolverhampton
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at RTX Corporation insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to RTX Corporation that you’re committed to staying ahead in the game.
How to prepare for a job interview at RTX Corporation
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at RTX Corporation to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at RTX Corporation.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.