Hiring.Camp

Information Security Manager

Geaerospace

·

Today

Location
Subang, Malaysia
Type
Full-time
Department
Security
Seniority
Manager
Experience
5+ years
Source
Workday

Description

Job Description Summary

The Information Security Manager (ISM) is the primary cybersecurity focal at the site. This role is responsible for implementing, sustaining, monitoring, and auditing cybersecurity controls; ensuring compliance with global, regional, and contractual requirements (e.g., CMMC, EASA Part-IS); and promoting a strong cybersecurity culture across the facility. The ISM bridges OT, IT, and cybersecurity, acts as first-level approver for security-related changes, and partners with site leadership and Digital Technology (DT) to continuously improve the site’s cyber posture.

Job Description

Company Overview:

Working at GE Aerospace means you are bringing your unique perspective, innovative spirit, drive, and curiosity to a collaborative and diverse team working to advance aerospace for future generations. If you have ideas, we will listen. Join us and see your ideas take flight!

Site Overview:

GE Aerospace Engine Services Malaysia (GEESM) in Subang is a key part of our global maintenance, repair, and overhaul (MRO) network, supporting the service of commercial aircraft engines, components, and accessories with world-class technical expertise. Established in 1997 as a Center of Excellence for CFM56 engines, the site has continued to grow, including becoming GE Aerospace’s first LEAP MRO facility outside the U.S. We are also expanding our footprint in Malaysia with a new LEAP engine MRO facility in Sepang!  Expected to open in late 2026, adding advanced capabilities, new technology, and opportunities to support the next generation of aviation maintenance. 

Employing more than 700 highly skilled local professionals and providing MRO services to more than 50 airlines worldwide, GEESM continues to exceed our customers’ expectations. With our technical expertise and pioneering spirit, we elevate the flying experience to new heights.

Role Overview:

Cybersecurity Implementation & Monitoring:

  • Lead the Site Cyber Implementation Team to deploy and sustain the Cyber Playbook and other corporate cyber standards.

  • Track site-level cyber activities and risks (e.g., CMMC/IA defects, EASA Part-IS, vulnerabilities, endpoint monitoring coverage) and maintain a site cyber action plan.

  • Report cybersecurity metrics in Shop MOR/Daily Management and provide updates to site and DT leadership.

  • Act as first-level approver for security-related change management requests (e.g., firewall rules, ports, OT/IT connectivity), ensuring changes are risk-assessed, documented, and compliant.

Auditing and Compliance:

  • Ensure the site complies with applicable cybersecurity regulations, standards, and contractual requirements (global, regional, and customer-specific).

  • Partner with relevant functions to support customer audits, regulatory inspections, and technical reviews.

  • Assist with root cause analysis, corrective actions, and clarifications during and after external and internal audits.

Incident Management:

  • Serve as the local support for cybersecurity incidents, coordinating with the Global Incident Response Team within Cyber and DT for triage, containment, and recovery.

  • Support incident response readiness, including communication of roles, escalation paths, and participation in drills.

  • Contribute to post-incident reviews and drive implementation of corrective and preventive actions.

Cybersecurity Culture and Continuous Improvement:

  • Actively promote cybersecurity rules and best practices within the facility.

  • Conduct presentations and training sessions for various departments to enhance cybersecurity awareness and ownership.

  • Use appropriate communication channels to disseminate cybersecurity information and expectations.

  • Engage with shop floor, OT, and cross-functional stakeholders (Operations, Quality, EHS, Compliance, Facilities, BISOs, DT) to embed cybersecurity into daily operations and projects.

Ideal Candidate:

  • The ideal candidate is having strong understanding of cybersecurity risk management in large enterprise environment. Having spent time managing audits and ensuring cyber controls are in place and working effectively. 

Required Qualifications:

  • Bachelor’s or Master’s degree in Information Technology, Cybersecurity, Computer Science, Engineering, or a related field.

  • 5-7 years of experience in operational technology (OT) and cybersecurity, preferably in manufacturing, industrial, or critical infrastructure environments.

  • Strong knowledge of regulatory and standards requirements at regional and global levels (e.g., CMMC, EASA Part-IS, IA, and contractual cybersecurity obligations).

  • Proven ability to lead projects and manage cybersecurity initiatives, coordinating cross-functional teams and driving actions to closure.

  • Ability to travel 30% (once per month) to the site to ensure cybersecurity controls are operating effectively.

Preferred Qualifications:

  • Excellent communication and stakeholder management skills, with the ability to influence and explain complex topics to non-technical audiences.

Whether we are manufacturing components for our engines, driving innovation in fuel and noise reduction, or unlocking new opportunities to grow and deliver more productivity, our GE Aerospace teams are dedicated and making a global impact. Join us and help move the aerospace industry forward.

Additional Information

Relocation Assistance Provided: No

Skills

CybersecurityRisk ManagementComplianceChange Management
Information Security Manager at Geaerospace | Hiring.Camp