IT Compliance Executive (12 months contract with Completion Bonus)
- Develop, implement, and maintain the Information Security Management System (ISMS) in compliance with EASA Part-IS requirements.
- Coordinate and monitor compliance with EASA Part-IS for all relevant domains (Part-145, Part-CAMO, Part-21, Part-OPS, etc.).
- Conduct risk assessments related to information security threats, including cybersecurity risks, and maintain the security risk register.
- Communicate with the competent authorities and relevant parties on establishing the information security compliance.
- Lead internal audits, vulnerability assessments, and gap analyses to identify deficiencies and improvement opportunities in ISMS.
- Collaborate with IT, Safety, and Quality departments to integrate security controls into existing processes.
- Ensure effective incident response and recovery procedures are in place for information security breaches or attempted attacks.
- Provide training and awareness programs for staff on information security best practices and regulatory obligations.
- Monitor evolving EASA guidance, cybersecurity threats, and industry best practices to ensure continuous compliance and risk mitigation.
- Document policies, procedures, and reports as part of the ISMS and ensure proper version control and availability.
Qualifications
- Bachelor’s degree in Information Security, Computer Science, Aviation Safety, or a related field.
- Little / No experience in information security or regulatory compliance in the aviation or critical infrastructure sector.
- Understanding of EASA regulatory framework, particularly Part-IS, Part-145, Part-CAMO, or related domains.
- Familiarity with international information security standards (e.g., ISO/IEC 27001).
- Knowledge of risk management, incident response, and business continuity in aviation.
- Experience in cybersecurity tools, systems, and practices.
- Excellent communication and project management skills.