Be at the heart of actionFly remote-controlled drones into enemy territory to gather vital information.

Apply Now

Aerospace Cybersecurity Technical Lead

Bristol
4 weeks ago
Create job alert

This role will lead the technical delivery of cybersecurity artefacts aligned to EASA, UK CAA and associated airworthiness regulations. You will support developing and refining our client's Airworthiness Security Process (AWSP) and oversee the creation of core artefacts to support certification. This client-facing role ideally suits someone with deep experience in aerospace system security, airworthiness security assurance, and regulatory alignment. You will be a trusted advisor to engineering teams and Expleo cybersecurity consultants, ensuring best-practice alignment, efficient delivery, and high-quality outputs across the certification lifecycle.

Responsibilities

Act as the technical lead for cybersecurity delivery to aerospace clients, ensuring alignment with the development roadmap and certification programme.
Provide subject matter expertise on airworthiness security, system security engineering, and certification artefact production aligned to EASA and UK CAA expectations.
Lead the development and review of cybersecurity documentation, including the PSecAC (Airworthiness Security Process Plan), PASRA (Preliminary Aircraft Security Risk Assessment), ASAM (Aircraft Security Architecture Model), and Security Verification Methods.
Provide input into the AWSP frameworks, including the tailoring of compliance checklists, activity outcomes, and document templates.
Ensure traceability between security risk assessments, controls, and compliance objectives across the aircraft systems and software architecture.
Coordinate the development of cybersecurity methods and processes, contributing to their alignment with recognised standards.
Engage with DAG's internal stakeholders, including engineering, safety, and systems integration teams, to embed cybersecurity into the design and certification lifecycle.
Act as the primary technical interface for cybersecurity between Expleo and clients, supporting queries, reviews, and audits.
Support internal QA and delivery governance for all security engineering artefacts, ensuring consistency, rigour, and traceability to certification requirements.
Provide mentoring and support to Expleo consultants embedded in the client workstreams, sharing knowledge and building internal aerospace security capability.

Qualifications

A degree (or equivalent experience) in Aerospace Engineering, Systems Engineering, Cybersecurity, or a related technical discipline.
Recognised cybersecurity certifications (e.g., CISSP, CISM, GICSP, CCSK) and/or relevant systems engineering accreditations (INCOSE ASEP/CSEP).
Formal training or applied experience with aviation cybersecurity standards such as ED-202A/DO-326A, DO-355A, ED-203A, DO-356A.

Skills

In-depth knowledge of aircraft systems, avionics networks, data buses (ARINC 429, AFDX), and embedded platform architectures.
Strong grasp of cybersecurity engineering principles in the context of safety-critical systems and regulated environments.
Demonstrated experience leading the development of cybersecurity assurance artefacts for certification programmes.
Practical understanding of airworthiness risk modelling, threat identification, attack surface reduction, and aircraft-level threat scenarios.
Ability to produce certification-ready documentation aligned to EASA/UK CAA guidance, including traceability to compliance objectives.
Strong communication and interpersonal skills, with the ability to translate complex cybersecurity concepts for engineering, safety, and programme stakeholders.
Knowledge of aerospace cybersecurity policy, risk management, and threat intelligence as applied to aircraft development environments.

Experience

Experience in cybersecurity, with at least 5 years focused on aerospace, defence, or regulated engineering environments.
Proven track record of delivering security artefacts in support of product certification or aircraft programme development.
Previous experience supporting or working within a DOA or similar regulated environment.
Hands-on involvement with aircraft-level cybersecurity engineering, including network segmentation, security zones, access control, and data integrity assurance.
Experience working across multi-disciplinary teams involving engineering, avionics, software, safety, and regulatory specialists.
Familiarity with regulatory alignment processes and compliance checklists for EASA and/or UK CAA cybersecurity requirements
Experience supporting cybersecurity assurance within other EASA/UK CAA-regulated aerospace programmes.
Familiarity with Capella, Polarion, or other MBSE platforms in the context of security architecture and systems modelling.
Practical understanding of Secure Software Development Assurance (SSDA) and interaction between security and safety lifecycles.
Experience responding to regulatory audits, design reviews, and certification authority engagements.
Understanding aircraft production and supply chain security, including configuration management, supplier assurance, and design data integrity.
Exposure to digital threat modelling techniques tailored to aerospace domains (MITRE ATT&CK for ICS/Aerospace, STRIDE-LM).
Ability to contribute to internal capability development, methodology refinement, and knowledge transfer across delivery teams.

Benefits

Collaborative working environment - we stand shoulder to shoulder with our clients and our peers through good times and challenges
We empower all passionate technology loving professionals by allowing them to expand their skills and take part in inspiring projects
Expleo Academy - enables you to acquire and develop the right skills by delivering a suite of accredited training courses
Competitive company benefits
Always working as one team, our people are not afraid to think big and challenge the status quo

Related Jobs

View all jobs

Hardware Design Engineer

Head of Digital & Technology IT/OT

Director of Operations

Aerospace Production Engineer

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

The Best Free Tools & Platforms to Practise Cyber Security Skills 2025/26

Cyber security is one of the most in-demand career fields in the UK. From preventing data breaches to monitoring networks and defending against ransomware, the role of cyber professionals is critical across every industry. With organisations of all sizes facing increasing threats, demand for skilled professionals continues to rise. But employers don’t just want theory—they want proof that you can analyse systems, detect vulnerabilities, and respond to incidents. The good news is that you don’t need to pay thousands of pounds for training to build practical experience. A wide range of free tools and platforms allow you to practise cyber security skills safely, ethically, and at no cost. This article explores the best free resources available in 2025 to help you gain hands-on skills in ethical hacking, penetration testing, digital forensics, network monitoring, and incident response.

Top 10 Skills in Cyber sScurity According to LinkedIn & Indeed Job Postings

In today’s digital age, cyber security is no longer optional—it’s mission-critical. From financial institutions to healthcare providers, government departments to tech startups, every sector in the UK is under rising cyber threats. As a result, employers are constantly on the hunt for skilled professionals who can defend, detect, and respond effectively. But with cyber threats evolving at pace, what exactly are employers seeking? By analysing job postings on LinkedIn and Indeed, this article reveals the Top 10 cyber security skills UK organisations are demanding in 2025. Read on to discover how to present these skills effectively on your CV, in interviews, and through practical proof of experience.

The Future of Cybersecurity Jobs: Careers That Don’t Exist Yet

Cyber security has become one of the most critical issues of our age. Once regarded as a technical problem confined to IT departments, it is now a board-level priority, a government mandate, and a daily necessity for individuals. The shift towards cloud services, remote working, connected devices, and artificial intelligence has dramatically increased the risks of digital attacks. In the UK, cyber security is central to national resilience. The government has identified cyber as a “tier one” threat to national security, alongside terrorism and pandemics. The private sector, from banks to retailers, now sees data breaches and ransomware as existential risks. Global spending on cyber security is projected to exceed $250 billion by 2030, with the UK already home to a thriving cyber industry employing tens of thousands. Yet, as powerful as the industry already is, we are only at the beginning. The technologies shaping the next two decades—AI, quantum computing, edge computing, extended reality, and biotechnology—will radically reshape cyber security. Many of the most vital cyber security jobs of the future don’t exist yet. This article explores why new roles will emerge, the careers likely to appear, how today’s jobs will evolve, why the UK is well-positioned, and how professionals can prepare now.