✓Verified

Sourced directly from Aerocloud's own careers page

GovSecOps Lead

Aerocloud

Manchester, England, United Kingdom["Permanent"]

Thinking of applying? Check your CV against this job first.

See your match score, your strongest skills for this role, and what's missing — before you spend time on an application.

Your real
match score

Free CareerPilot account · Takes about 2 minutes

AeroCloud: Revolutionizing Airport Operations AeroCloud is the new-age operating system for airports aiming to grow. Our suite includes Airport Operating Systems (AOS), PPS, and Passenger Flow Management solutions, empowering airports to gain deep insights into the movement of passengers and aircraft around the world. We achieve this by becoming the airport’s first call for technology. Whether in times of need or growth, we stand alongside our clients, offering support through innovative software that drives their success.   Our Commitment to Excellence At AeroCloud, being the airport’s first call means exceeding expectations at every customer interaction. This is not just a goal; it’s our standard. We prioritize detail, diligence, and a proactive approach in everything we do. If there’s a task to be completed, we see it through. If a customer needs an answer we don’t yet have, we respond promptly to let them know we’re on it. We believe in keeping our team informed, being transparent, and maintaining accountability at every step.   About The Role Airports are critical national infrastructure, and the standards their regulators hold them to flow straight down to us in contracts, questionnaires and audits. We're hiring a GovSecOps Lead to make governance and security part of how we build, rather than something that slows the teams down. This is a hands-on lead role reporting to the Head of Engineering: DevOps, applied to governance. Think compliance as code. Controls live in the pipeline, evidence is generated automatically, and drift gets caught before an auditor sees it. At the start you'll be a team of one. You'll build much of this yourself and work with our platform and engineering teams to get the rest delivered. You won't be overseeing other people's work. You'll be doing it. The function may grow, but you'll build it from the ground up. We work with specialist partners who assess us against ISO 27001 and other frameworks. You'll use those relationships and turn what they find into engineering work.   Responsibilities • Turning the findings from our governance and security partners (control gaps, ISO findings, data-protection issues, pen test results) into clearly specified, sized pieces of work • Handing that work to the right platform or product team, agreeing when it lands, and following it through to production rather than leaving it at "raised" • Building the automation yourself: evidence collection from our AWS and Azure estates and GitHub, policy-as-code checks, guardrails in infrastructure as code and GitHub Actions, and the scripts and integrations that tie it together. You'll use Claude and other AI tooling heavily to move fast • Making sure things stay fixed. That means regression checks in the pipeline, alerting when a control drifts, and a clear view of what's open and what's closed • Setting up and running regular sessions with the teams, such as backlog reviews, workshops and short training, so they understand why a control matters, not just that it exists • Leading us through ISO/IEC 27001 certification first, then keeping the ISMS alive through surveillance audits, with SOC 2, NIST CSF and NIS2 asks following behind • Owning the relationship with our partners: setting their priorities, holding them to what they've committed to, and making sure we get value from the days we buy   What You’ll Own • The security and governance backlog across teams, from spec to delivery, and the reporting that shows whether it's moving • The automation that keeps us compliant: evidence collection, control checks, drift detection and regression tests • The ISMS end to end: scope, Statement of Applicability, risk register, internal audit and management review • One control set mapped across ISO 27001, SOC 2, NIST CSF and customer frameworks, so one piece of evidence answers many questions • The regular rhythm with the teams: reviews, workshops and training that keep security part of how we work • Customer assurance: security questionnaires, tender security sections and third-party assessments   What We’re Looking For • You're a doer. You'd rather write the check, the script or the pipeline step than a policy that asks people to remember something • You're comfortable in code and in the cloud, AWS and Azure. You can read and write TypeScript and infrastructure as code, and you use AI tools like Claude day to day to build and ship faster • You can write a ticket an engineering team can pick up without a follow-up meeting: the problem, the fix, how to test it and what done looks like • You get work delivered through teams you don't manage, by being useful, clear and persistent rather than by escalating • You coach well. Engineers come away understanding the risk and building the right thing next time without being asked • You've taken an organisation through ISO 27001 (or an equivalent externally audited standard) as the person accountable for getting it done • You can explain our real exposure to the exec team plainly, without overstating the risk or burying it   The pace here is faster and the structure lighter than most established engineering orgs. Governance has to fit that. If a control adds a meeting or a manual step, the answer is usually to automate it, not to accept the drag.   Our Stack   AWS and Azure, with GitHub for source control and CI/CD (GitHub Actions). Infrastructure as code (AWS CDK), TypeScript, MongoDB Atlas. Testing and observability are built into how we work.   We use Claude and other AI tooling across engineering. You'll pick and own the compliance automation tooling.   What We Offer • Competitive salary • Best in Class Share Options scheme * 25 days PTO + statutory holidays • Take your birthday off work on us as well • Extensive upskilling and training • Digital Nomad Scheme   Our Ethos AeroCloud recognises Diversity, Equality, and Inclusion at the heart of our business. They represent the mutual trust, respect and understanding we strive for. They are integral to our brand, reputation, success, business sustainability and employee relations impact. Our vision is to have a diverse, equal and inclusive organisational culture. We want everyone who comes into contact with us, both face to face and virtually, to feel valued and respected. We want our workplace both in the office and at home to foster belonging to all colleagues to feel seen, connected, supported and proud. We will draw on the rich diversity of our workforce and harness the diverse contributions and considerable talents of our staff to achieve our vision in line with our organisational values and DE&I principles. AeroCloud is an equal opportunities employer so if you have any specific work or access requirements as a result of a condition or disability then AeroCloud would be committed to working with you on the best way to support this at work.

Applying to this job? Don't just find it — prepare for it.

With CareerPilot, you can:

Match

See how your CV compares to this job.

Tailor

Strengthen your CV for this specific role.

Prepare

Practise for the interview beforehand.