Information Security Officer (Cybersecurity)

Tui Care Foundation
Luton, UK
14 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Cloud Computing Security Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Security Management Open Web Application Security Software Engineering Systems Integration

Job description

Flexible working: Work is something you do, not somewhere you go. We encourage a healthy work-life balance with a dynamic working environment. A career to shape: Access the TUI Learning Hub to level-up and reach your ambitions. Broaden your network: We champion intercultural collaboration and provide opportunities to work on global projects and teams. Community: Get involved with incredible local charity and sustainability initiatives like the TUI Care Foundation. ABOUT THE JOB

  • As part of the role, you will be the Cyber Security Responsible Manager (CSRM) for the UK airline and will require necessary security clearance when starting the role.

You’ll promote and inspire a security-first culture at TUI, directing the development and implementation of an enterprise Information Security strategy that’s aligned to our business needs. Leading the provision of Information Security resources, expertise and guidance, you’ll ensure each Domain is motivated and empowered to deliver their prioritised roadmap. Your extensive business knowledge will help you drive adoption of security policies, standards and controls through expert advice, protecting our most critical assets with appropriate assurance and rigorous testing. Managing security incidents effectively through engagement with our security operations team, you’ll ensure lessons learned and audit findings are remediated whilst maintaining effective security operations. Building strong working relationships across business and IT teams, you’ll explain complex ideas to audiences at all levels in a persuasive manner, instilling secure ways of working. You’ll report on the overall effectiveness of the security programme against defined key performance indicators, driving continuous improvement and leading workstreams focused on developing the GRC team.

Requirements

You’re an experienced authentic leader with a solid understanding of technology and managing Information Security risks in the enterprise, passionate about delivering business value. Your strong people leadership skills help you build a positive enabling security culture based on trust, quality and pragmatic risk management, with experience mentoring and developing security talent from different cultural backgrounds. As a great communicator and influencer, you’re comfortable working across hierarchical, organisational, cultural and market boundaries, articulating IT security issues clearly to both technical and non-technical audiences. You hold a recognised security accreditation (CISSP/CISM/CISA etc.) or equivalent experience with demonstrable Continuous Professional Development, maintaining a good understanding of latest security threats and mitigating strategies. Your experience includes implementing and maintaining an Information Security Management framework such as ISO27001 or NIST CSF, with a strong understanding of international regulatory context, particularly NIS 2, Part-IS and aviation-specific requirements. You have experience governing or managing audits by aviation regulators across Europe, integrating security into software development lifecycle and cloud security, with good understanding of technology standards like CIS, NIST, PCI, OWASP, ITIL and COBIT (experience with AWS workloads is desirable).

Benefits & conditions

Personal benefits: Attractive remuneration, discretionary bonus schemes, generous travel benefits, extensive health & well-being support, and more.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:00 min

Designing data ingestion architecture with system integration

Eldert Grootenboer +1 · World Congress 2023

1:22 min

Understanding software engineering as more than just coding

Lilia Gargouri Lilia Gargouri · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all