🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Salary: £56,667 to £71,957 – (dependent on experience) Contract Type: Permanent – Full-Time Security Level: SC Location: Gatwick – Hybrid - min 2 days in the office or industry visits per week. Visa Restrictions: This position does not offer visa sponsorship Closing Date: Friday 28 th August 2026 Screening Calls: w/c 31 st Monday 2026 Interview Date: From w/c Monday 14 th September 2026 We are the UK's aviation and aerospace regulator and recognised as a world leader in its field. Our activities are diverse, enabling the aviation industry to meet the highest safety standards, and we pride ourselves on our ability to adapt to the constantly evolving aviation environment. The Role Are you an experienced information security professional looking for a new challenge? Or perhaps you're keen to move from an internal consultancy, assurance, or IT audit role into a more outward-facing position where you can influence the future of cyber security in aviation? If so, this could be the opportunity for you. The CAA Cyber Safety Oversight Team provides cyber security oversight across a range of aviation safety domains, including Aerodromes, Continuing Airworthiness, Air Traffic Management, and Flight Operations. We have built a highly collaborative environment where cyber specialists work alongside aviation experts to develop, implement, and continuously improve proportionate, risk-based oversight approaches. Alongside our aviation safety responsibilities, the CAA as co-competent authority with the Department for Transport (DfT) for the Network and Information Systems Regulations 2018 (NIS) is responsible for regulatory oversight and post-incident investigations under NIS, delivered through the CAA's Cyber Security Oversight Process for Aviation (CAP1753). As an Aviation Cyber Oversight Specialist, you will play a pivotal role in delivering the UK Aviation Cyber Security Strategy and the CAA's Cyber Security Oversight Strategy. You will help drive the evolution of our cyber oversight capabilities, ensuring our approach remains proactive, intelligence-led, and aligned with the Regulator's Code, Growth Duty, and CAA Regulatory Principles. Working at the forefront of aviation cyber security, you will contribute to the development and application of cyber security regulations, standards, and guidance that help maintain the safety, security, and resilience of the UK's aviation sector. A key part of the role will involve shaping and delivering the CAA's cyber oversight activities. This includes leading and participating in audits and inspections of aviation organisations, assessing the cyber risks associated with systems critical to aviation safety, security and resilience, reviewing cyber security self-assessments and evidence and formulating an expert opinion on an organisation cyber security posture, monitoring the implementation of corrective actions, and holding organisations accountable for addressing identified deficiencies. The successful candidate will have a strong background in information technology, operational technology, cyber security, or senior GRC roles, with practical knowledge of information security frameworks and controls, and the ability to evaluate technical documentation and controls implementation Strong stakeholder engagement skills are essential. You will be comfortable working with a diverse range of organisations and individuals, from technical specialists and senior leaders to government and industry representatives and will be able to communicate complex concepts clearly and effectively to different audiences. Core Accountabilities To work in collaboration with CAA safety and security colleagues to establish and mobilise an ongoing oversight regime that ensures aviation organisations are meeting cyber security requirements according to their applicable regulations Perform initial and ongoing oversight activities predominantly in aviation safety, but also in aviation security and resilience where appropriate. Activities will include, but not limited to, audits (both onsite and remote), inspections, reviewing evidence and reports, determining the suitability of corrective actions and monitoring progress in completion Confidently communicate areas of non-compliance both with CAA stakeholders and aviation organisations Work with, and guide, accredited third parties in line with the CAA’s Cyber Security Oversight model Represent the CAA Cyber Oversight Team to the wider industry through working groups and events Participate in the development and delivery of aviation cyber security training and guidance Review aviation cyber security risk through threat and vulnerability assessments, communicating effectively to both industry and other CAA capability areas to inform safety and security decision making Contribute towards a culture of continuous improvement in developing cyber security oversight practices, standards, and guidance consistent with the Regulators’ Code, the CAA’s cyber oversight objectives, our safety objectives and aviation security regulations About You Essential: The ideal candidate would be someone seeking a new challenge that currently works in a hands-on cyber security, information security or information technology or operations technology capacity Experience in technology systems supporting critical infrastructure or operational environments, is highly desirable Practical experience with security frameworks such as ISO 27001, NIST Cybersecurity Framework, NCSC Cyber Assessment Framework (CAF), or similar industry standards, ideally in an assessment or audit capacity Knowledge of cloud computing and security, industrial control systems (ICS), operational technology (OT), or critical infrastructure, cyber security Professional certifications such as CISSP, CISM, CRISC, Network+, Security+, GICSP, SANS ICS410/301/401, ISO ISA/IEC 62443, ISO27001 lead auditor/implementer, CCSK or equivalent recognised certifications. You'll be capable of translating complex technical concepts for diverse stakeholder audiences, from technical teams to senior management and other government departments and CAA colleagues You’re a great team player with a forward-thinking approach, recognising that cyber security in UK civil aviation is a rapidly evolving area, meaning that there are many technical and regulatory uncertainties You will possess strong analytical and communication skills with the ability to present technical oversight reports clearly and concisely, both in writing and verbally Strong interpersonal skills and the ability to build and maintain relationships and resolve conflict calmly Since the role will require travel to visit regulated entities, suitable candidates will hold a clean UK driver's license and not be averse to travel. This may also necessitate occasional overnight stays Additional Information For many appointments within the CAA, these roles require access to operationally sensitive infrastructure and/or Nationally Protected information. For these roles the post holders must undergo National Security Vetting and achieve the appropriate level of clearance. SC - To be vetted we will usually expect a reasonable period of residency in the UK so that meaningful checks can be undertaken. For this role t his will need to be 5 years. If you do not meet these requirements, we may not be able to accept your application. For more information on CTC and SC clearance please visit - Vetting explained - GOV.UK (www.gov.uk) The CAA values high ethical standards and personal integrity among employees. If invited for interview you will be asked to complete a declaration of interest. Relocation & Property The CAA will be