Cyber Engineering and Automation Manager

Company: IAG Transform
Apply for the Cyber Engineering and Automation Manager
Location:
Job Description:

Cyber Engineering and Automation Manager

Join to apply for the Cyber Engineering and Automation Manager role at IAG Transform.

Looking for a challenge in one of the world’s leading airline groups – a dual FTSE 100 and IBEX 35 listed company that combines airlines in Ireland, the UK and Spain with key non-airline businesses, enhancing their presence in the aviation market.

Purpose of the Role

This is a high-impact greenfield role ideal for a strategic and hands‑on cybersecurity professional. As a senior manager within the Group SOC, you will define and implement the end‑to‑end operating model for collaboration between the central Security Operations Center (SOC) and supporting functions. You will formulate core processes, define handover areas with the core SOC, and establish the technology stack and deliverables necessary to enable scalable and effective security operations encompassing cyber threat intelligence and cyber incident response.

A key early responsibility will be contributing to the onboarding and transition of a new Managed Security Services Provider (MSSP). You will work closely with the chosen vendor to define operational procedures, service delivery models, key performance indicators (KPIs), and service level agreements (SLAs). Building a strong, collaborative relationship with the MSSP will be a critical short‑term goal.

In the longer term, this role will take ownership of developing the business case for building and strengthening internal capabilities – laying the foundation for a future in‑house team and transitioning key functions where strategically appropriate. You will also be expected to build trusted relationships with external stakeholders across operating companies to ensure SOC services are aligned with business risk and operational priorities.

Accountabilities

  • Automation of SOC Processes
    • Design and implement automation solutions to streamline repetitive tasks such as alert triaging, incident response, and reporting.
  • Platform Support and Tool Integration
    • Oversee and complete transition of SIEM platform support from incumbent to new supplier, resolving any transition blockers.
    • After transition, be responsible for overall BAU platform maintenance of Splunk (SIEM).
    • Creation and maintenance of the SOC KnowledgeBase stores.
    • Integrate various security tools (SIEM, SOAR, firewalls, etc.) to improve data flow and response coordination.
  • Optimization of Workflows
    • Enhance and optimize SOC workflows for improved efficiency and reduced manual effort.
  • Development of Playbooks
    • Create automated response playbooks for common security incidents, enabling faster and more consistent incident handling.
  • Collaboration with Security Teams
    • Work closely with SOC analysts and engineers to identify areas for automation and provide technical solutions.
  • Monitoring and Maintenance
    • Ensure continuous operation and performance of automation tools, resolving issues as they arise.

Required Skills, Qualifications & Experience

  • Proficiency in automation tools (e.g., SOAR platforms, Ansible, Phantom).
  • Expertise in scripting languages (e.g., Python, PowerShell, Bash).
  • Strong knowledge of SOC processes (incident response, threat detection).
  • Experience with SIEM platforms (e.g., Splunk).
  • Ability to integrate and automate security tools.
  • Strong problem‑solving and analytical skills.
  • Experience in developing automated workflows and playbooks.
  • Knowledge of security frameworks (e.g., MITRE ATT&CK, NIST).
  • Strong collaboration and communication skills.
  • Experience with log management and event correlation automation.

Seniority Level

Mid‑Senior level

Employment Type

Full‑time

Job Function

Information Technology

Industry

Airlines and Aviation

#J-18808-Ljbffr…

Posted: December 27th, 2025