GRC Cyber Security Consultant

AirbusBristol, EnglandOn-siteFull-timeSenior, 5–8 yearsListed 53 minutes ago

Apply now

About this role

Job Description:

Company Statement

Airbus Protect is a wholly owned subsidiary of Airbus Group. We are a risk management leader in safety,  cybersecurity and sustainability.

We protect businesses and products from end-to-end, going beyond mere compliance to strengthen incident prevention and resilience at every level.

The Role

As a Cyber Security Consultant at Airbus Protect, you will act as a trusted advisor to our clients, delivering expert guidance across a diverse range of sectors. This is a multi-faceted role designed for someone who can help our customers navigate the increasingly complex threat and regulatory landscapes. You will be navigating both tactical and technical compliance challenges alongside high-level strategic risk management.

Due to the sensitive nature of the projects we deliver for our clients, it is an essential requirement that you currently hold, or meet the criteria to obtain, UK Government Security Clearance . This foundational requirement goes hand-in-hand with our need for a proven track record in cyber security consulting. We expect your practical experience navigating complex GRC challenges to be firmly underpinned by recognised industry certifications—such as CISSP, CISM, or ISO 27001—demonstrating your established capability to advise clients with authority and technical rigor.

Key Responsibilities may include:

Governance

- Strategic Consulting: Advise clients on sound security architecture principles, including Secure by Design, network segmentation, and zero-trust frameworks, ensuring technical solutions align with business priorities.
- Technical Advisory: Lead engagements on specialised areas providing both high-level strategy and technical oversight. Providing consultancy on complex technical topics such as IDAM, PAM, and DLP, translating these into clear, actionable business advice.
- Regulatory Guidance: Advise and assure compliance against current and emerging frameworks/standards and regulations such as ISO27001, ISA/IEC62443, NIST CSF, NIST 800-53, NCSC CAF, NIS2, the Cyber Resilience Act, the AI Act, EASA Part-IS.
- AI Integration: Leverage AI tools to optimise internal delivery while consulting customers on the secure adoption and governance of AI within their own environments and in regulatory compliance.
- Multi-Project Leadership: Efficiently manage and execute multiple client engagements simultaneously, prioritising deliverables, driving project timelines, and consistently delivering quality consulting outputs while maintaining strong customer relationships across various industry sectors.

Risk

- Risk Management: Produce high-quality risk assessments and assurance artefacts across the full system lifecycle, tailoring your approach to the client’s specific business context, including consideration of technical and human factors.
- Risk Mitigation & Guidance: Translate technical gaps and architectural risks into prioritised, actionable remediation plans, advising delivery teams and business stakeholders on achieving compliance and long-term cyber resilience.
- Gap assessment: Conduct comprehensive gap assessments against relevant cybersecurity standards, frameworks, and regulations (e.g., ISO27001, ISA/IEC62443, NIST CSF, NIST 800-53, NCSC CAF, NIS2, the Cyber Resilience Act, the AI Act, EASA Part-IS) to evaluate client security postures, identify control deficiencies, and deliver prioritised, actionable remediation roadmaps that guide clients toward full compliance readiness.

Compliance

- Cyber Resilience: Devise and test strategies that ensure clients can withstand and respond to cyber incidents.
- Secure Design & Baseline Assurance: Evaluate system architectures and technical configurations against established security baselines and Secure by Design principles. Identify design and configuration vulnerabilities early in the delivery lifecycle, providing actionable recommendations to guide customers toward secure, resilient, and compliant solutions.

Supporting New Business:

Beyond technical delivery, you will play a supporting role in the growth and market presence of Airbus Protect:

- Content Creation: Authoring technical blogs, white papers, and insights on emerging security trends to enhance our brand authority.
- Sales and Marketing Support: Support to Sales and Marketing colleagues with technical representation at customer and marketing events. Developing compelling case studies and service descriptions aligned with our services portfolio. Representing Airbus at webinars, industry panels, and conferences to showcase our expertise.
- Business Development: Active participation in the bid process and supporting ongoing customer relationship management to identify new opportunities.

The Individual

We are seeking a proactive self-starter capable of taking a forward-looking approach to understanding customer requirements by providing effective inputs that add tangible benefit to the customer’s business.

Essential Requirements:

- Experience: 5–10 years of experience in a cyber security consulting or technical leadership role
- Clearance: Must hold, or have the ability to obtain, UK Government Security Clearance .
- Qualifications: At least one of the following certifications (CISSP, CISM, CCSP, CISA, ISO 27001, GICSP, ISA62443) or equivalents.
- Frameworks and Standards: Demonstrable experience of regulatory compliance and Standards adherence.
- Mindset: A self-starter who stays ahead of the curve on threat intelligence and industry best practices.
- Communication: Exceptional presentation skills; able to communicate complex technical topics to non-technical stakeholders.
- Collaboration: Proven ability to work autonomously while contributing effectively to multiple virtual and transnational teams and customers across concurrent projects.
- AI Literacy: Demonstrable understanding of how to use AI tools for productivity and the principles of securing AI environments.
- Business Acumen: Demonstrable evidence of business support benefits undertaken and realised
- Mobility: Full UK Driving Licence.
- Locality: Whilst this is a Hybrid Role, you will be expected to be in our Bristol office for at least 2-3 days a week.

Remuneration & Benefits

- Competitive Salary
- Annual profit share scheme.
- Comprehensive company benefits and private healthcare options consistent  with a market-leading transnational organisation.

Airbus Protect is an equal opportunities employer. At Airbus, inclusion means celebrating and valuing diversity in all its forms.. This commitment ensures every employee – irrespective of their socio-economic background, age, race, ethnicity, physical ability, neurodiversity, gender, sexual orientation, or any other characteristic – feels valued and included, empowering them to reach their full potential within a respectful environment."

This job requires an awareness of any potential compliance risks and a commitment to act with integrity, as the foundation for the Company’s success, reputation and sustainable growth.

Company:
Airbus Protect Limited

Contract Type:
Permanent

Experience Level:
Professional

Job Family:
General Security <JF-CG-GS>

By submitting your CV or application you are consenting to Airbus using and storing information about you for monitoring purposes relating to your application or future employment. This information will only be used by Airbus.
Airbus is committed to achieving workforce diversity and creating an inclusive working environment. We welcome all applications irrespective of social and cultural background, age, gender, disability, sexual orientation or religious belief.

Airbus is, and always has been, committed to equal opportunities for all. As such, we will never ask for any type of monetary exchange in the frame of a recruitment process. Any impersonation of Airbus to do so should be reported to  [email protected] .

At Airbus, we support you to work, connect and collaborate more easily and flexibly. Wherever possible, we foster flexible working arrangements to stimulate innovative thinking.