ATR - Cybersecurity Manager (H/F) - AVIONS DE TRANSPORT REGIONAL (ATR) GIE
This role contributes to the implementation of the Information Security Management System (ISMS), participates in risk assessments, supports cybersecurity-by-design initiatives, performs supplier evaluations, assists with incident analysis, and ensures the production of documentation and evidence required for compliance.
The position covers a broad perimeter, giving exposure to governance, engineering, IT, suppliers, compliance, and operations, while maintaining a technical focus suitable for a junior engineer (3-5 years of experience).
The Cybersecurity Engineer also acts as a Product Security Officer , contributing to the identification, documentation, and follow-up of cybersecurity requirements for ATR products, systems, and services.Key Responsibilities 1. ISMS Operational Support- Produce and maintain ISMS documentation (procedures, control evidence, records, KPIs) in support to the ISMS Officer.
- Support internal audits and compliance assessments led by the ISMS Officer.
- Contribute to the monitoring of cybersecurity controls and remediation follow-up.
- Assist in preparing evidence for EASA, OSAC, DSAC audits and inspections.
- Support the implementation and continuous improvement of ISMS processes.
- Perform SRA analyses under the supervision of the ISMS Officer and Deputy CISO.
- Identify threats, vulnerabilities, and applicable security controls.
- Contribute to the maintenance of the Information Security Risk Register.
- Support mitigation tracking and documentation.
- Prepare technical summaries and recommendations.
- Support cybersecurity-by-design activities for Engineering and IT projects.
- Assist in defining technical cybersecurity requirements for aircraft systems, IT solutions, digital projects, and suppliers.
- Contribute to design reviews and ensure traceability of requirements.
- Perform security evaluations, provide technical inputs, and support integration tasks.
- Act as a Product Security Officer, contributing to product-level cybersecurity analyses.
- Conduct supplier cybersecurity assessments (questionnaires, evidence checks, scorecards).
- Support Procurement in integrating cybersecurity requirements into RFPs and contracts.
- Perform follow-up of supplier compliance deliverables.
- Contribute to Make/Buy analysis by providing technical insights.
- Prepare material for cybersecurity awareness campaigns and support their delivery.
- Contribute to internal communication content (guidelines, quick-reference materials).
- Provide technical coaching to project teams when requested.
- Support IT during cybersecurity incident diagnostics and evidence gathering, contributing to containment, analysis, and documentation.
- Identify, analyse, and qualify vulnerabilities (systems, applications, configurations, supplier deliverables).
- Support vulnerability triage and remediation follow-up with IT and Engineering teams.
- Contribute to root cause analyses and lessons learned documentation.
- Assist in improving detection and response processes.
- Networks & Protocols: knowledge of TCP/IP architectures, Firewalls, Proxies, VPN.
- Operating Systems: understanding of Windows Server and Linux security.
- Security Tools: first experience with SIEM, IDS/IPS, EDR/XDR, WAF, PKI solutions.
- Cryptography: understanding of encryption and key management principles.
- Scripting: basic skills in Python, Bash/Shell or PowerShell.
- Cloud Security: familiarity with AWS, Azure or GCP security mechanisms.
- Product Security: ability to contribute to cybersecurity evaluations for ATR products and systems
- 3-5 years’ experience in cybersecurity, IT security, or systems/software engineering.
- Basic understanding of ISO 27001, Part-IS, NIS2, NIST CSF.
- Technical curiosity and willingness to learn aviation cybersecurity.
- Strong analytical and problem-solving mindset.
- Ability to work transversely with Engineering, IT, Programs, Procurement.
- Fluent in English; French is desirable.
- Pierre will contact you
- Innovative and digital assessment
- To get to know you better: interview Pierre then with Mehdi our Hr Recruiter
Il/Elle contribue à la mise en uvre du Système de Management de la Sécurité de l’Information (ISMS), participe aux analyses de risques, soutient les initiatives security-by-design, réalise des évaluations fournisseurs, assiste les investigations lors d’incidents et produit la documentation et les preuves nécessaires à la conformité réglementaire.
Ce poste offre une exposition large (gouvernance, engineering, IT, fournisseurs, conformité, opérations) tout en conservant un rôle de référent technique junior (3 à 5 ans d’expérience).
Il/Elle agit également en tant que Product Security Officer, contribuant à l’identification et au suivi des exigences de cybersécurité sur les produits, systèmes et services ATR.Responsabilités principales Support opérationnel ISMS- Produire et maintenir la documentation ISMS (procédures, preuves, registres, KPIs) en support de l’ISMS Officer.
- Contribuer aux audits internes et évaluations de conformité.
- Participer au suivi des contrôles de sécurité et des plans de remédiation.
- Préparer les éléments nécessaires pour les audits EASA, OSAC, DSAC.
- Soutenir l’amélioration continue des processus ISMS.
- Réaliser des analyses SRA sous supervision de l’ISMS Officer et du Deputy CISO.
- Identifier menaces, vulnérabilités et contrôles applicables.
- Contribuer à la mise à jour du registre des risques.
- Assurer le suivi documentaire des mitigations.
- Préparer des synthèses techniques et recommandations.
- Contribuer aux activités security-by-design des projets Engineering et IT.
- Participer à la définition des exigences techniques de cybersécurité.
- Contribuer aux revues de conception et à la traçabilité des exigences.
- Réaliser des évaluations de sécurité et analyses techniques.
- Intervenir comme Product Security Officer sur les sujets produits et systèmes.
- Réaliser des évaluations cybersécurité fournisseurs.
- Soutenir Achats pour intégrer les exigences cyber dans les RFP et contrats.
- Suivre la conformité des livrables fournisseurs.
- Apporter une vision technique dans les décisions Make/Buy.
- Préparer les supports pour les campagnes de sensibilisation.
- Contribuer aux communications internes cyber.
- Apporter un support technique ponctuel aux équipes projets.
- Soutenir IT lors des diagnostics d’incidents et collecte de preuves.
- Identifier, analyser et qualifier les vulnérabilités.
- Suivre les remédiations avec IT et Engineering.
- Contribuer aux analyses de causes racines et leçons apprises.
- Participer à l’amélioration des capacités de détection et réponse.
- Réseaux & Protocoles : TCP/IP, firewalls, proxys, VPN.
- Systèmes d’exploitation : Windows Server, Linux.
- Outils de sécurité : SIEM, IDS/IPS, EDR/XDR, WAF, PKI.
- Cryptographie : principes de chiffrement et gestion de clés.
- Scripting : Python, Bash/Shell, PowerShell.
- Cloud : sécurité AWS, Azure ou GCP.
- Product Security : contribution à l’analyse sécurité des produits ATR.
- 3 à 5 ans d’expérience en cybersécurité, sécurité IT ou ingénierie systèmes/logiciels.
- Connaissance de base des référentiels ISO 27001, Part-IS, NIS2, NIST CSF.
- Rigueur, analyse, curiosité, envie d’apprendre.
- Capacité à travailler en transverse.
- Anglais courant ; français souhaité.
- Vous serez contacté(e) par Pierre
- Évaluation innovante et numérique
- Pour apprendre à vous connaître : entretien avec Pierre et ensuite avec Mehdi RH Recruiter
Airbus is committed to achieving workforce diversity and creating an inclusive working environment. We welcome all applications irrespective of social and cultural background, age, gender, disability, sexual orientation or religious belief. Airbus is, and always has been, committed to equal opportunities for all. As such, we will never ask for any type of monetary exchange in the frame of a recruitment process. Any impersonation of Airbus to do so should be reported to . At Airbus, we support you to work, connect and collaborate more easily and flexibly. Wherever possible, we foster flexible working arrangements to stimulate innovative thinking. #J-18808-Ljbffr