Digital Security Management
Job Summary
Job Description:
DIGITAL SECURITY MANAGEMENT
The Digital Security Manager is responsible for overseeing and driving digital security operations for Airbus and all its divisions and affiliates in China including the Commercial Aircraft Defence & Space and Helicopters divisions divisions.
The job holder is responsible for overseeing and driving digital security operations across China encompassing:
Implementation of the corporate digital security strategy within business operations
Industrial digital security activities
Digital security risk identification and mitigation
Support for digital security audits technical evaluations and compliance frameworks
Support for the HR secure hiring process
Contributions to threat intelligence
On-demand support for technical legal investigations
Data Leakage Prevention (DLP) management
Support to digital security training and awareness programs
Support security evaluations during the procurement call for tender (CFT) selection process
Main activities
Strategic activities
Support the Chief Information Security Officer (CISO) in deploying corporate digital security initiatives
Coordinate and facilitate local digital security initiatives and programs across China
Identify consolidate and manage digital security risks and their corresponding response plans in China
Assist the CISO in drafting validating and publishing digital security policies processes and position papers
Client-related activities
Interface directly with local business units on digital security topics
Liaise closely with the IM Cybersecurity team regarding operational controls and initiatives
Operational activities
Ensure absolute compliance with Corporate and Divisional digital security requirements and standards
Provide dedicated security support for products services and ongoing projects
Provide guidance formal responses and validation for digital security requests and queries
Contribute to security awareness by designing organizing and delivering educational materials and training sessions
Manage digital risks through comprehensive identification assessment reporting and remediation follow-ups
Ensure thorough vulnerability management and follow-up across all corporate IT and Operational Technology (OT) assets
Support technical legal investigations and forensic laboratory activities on-demand
Coordinate and support technical digital security technical evaluations
Coordinate and support audits and regulatory compliance initiatives (e.g. ISO27001 PART-IS etc.)
Implement localized digital security projects and strategic initiatives
Scout new and emerging technologies that enhance the digital security posture
Support on-demand security screening of candidates including establishing formalizing and maintaining comprehensive screening processes tools and methodologies
Contribute to and proactively anticipate threat intelligence
Continuously improve the precision and response capabilities of Data Leakage Prevention (DLP) information
Evaluate vendor security postures within procurement processes to support business selection
Execute other tasks as assigned by the CISO
Outputs
Financial Outputs
N/A
Client-related Outputs
Ensure that all business activities remain fully compliant with corporate security policies and standards
Supervision of IM cybersecurity operational compliance KPIs to ensure they consistently meet targets
Operational Outputs
Achievement of yearly operational objectives
Delivery of high-quality timely security support to the business
Maintenance of an accurate digital security risk exposure map and corresponding action plans
On-demand technical support for specific legal investigations
Timely completion and follow-up of technical evaluations
High-quality timely execution of candidate screening
Precise and responsive DLP detection and mitigation
Rigorous security assessments for the CFT process
Skills & Experience
Education & Professional Qualifications
Academic Background: Bachelors or Masters degree in Computer Science Cybersecurity Information Technology Engineering or a related field
Certifications: possessing professional certifications or framework-specific certifications (e.g. ISO 27001) are a strong plus
Knowledge & Experience
Cybersecurity Operations: experience in digital security risk management or cybersecurity operations
Regulatory & Compliance: Comprehensive understanding of Chinese cybersecurity laws and regulations. Familiarity with aviation standards like PART-IS.
IT/OT Environment: experience securing both standard Information Technology (IT) and Operational Technology (OT) / Industrial Control Systems (ICS) environments
Skills & Competencies
Technical & Operational Skills: Risk Management Incident Response Forensics Vulnerability Management DLP IT/OT Security
Soft Skills & Leadership: Stakeholder Management Cross-Functional Collaboration Risk Communication Analytical Mindset Discretion & Confidentiality
Languages: Full professional proficiency in both English and Mandarin (mandatory for global and local stakeholder interfacing)
This job requires an awareness of any potential compliance risks and a commitment to act with integrity as the foundation for the Companys success reputation and sustainable growth.
Company:
Airbus (China) Enterprise Management and ServicesEmployment Type:
Permanent-------
Experience Level:
ProfessionalJob Family:
Cyber SecurityBy submitting your CV or application you are consenting to Airbus using and storing information about you for monitoring purposes relating to your application or future employment. This information will only be used by Airbus.
Airbus is committed to achieving workforce diversity and creating an inclusive working environment. We welcome all applications irrespective of social and cultural background age gender disability sexual orientation or religious belief.
Airbus is and always has been committed to equal opportunities for all. As such we will never ask for any type of monetary exchange in the frame of a recruitment process. Any impersonation of Airbus to do so should be reported to.
At Airbus we support you to work connect and collaborate more easily and flexibly. Wherever possible we foster flexible working arrangements to stimulate innovative thinking.