About this role
Location: Hybrid working – primarily based at G&O Springs Ltd, Broad Ground Road, Lakeside, Redditch, Worcestershire, B98 8YP
Contract Type: Fixed Term (24 months)
Basis: Full Time
Closing Date: 23.59 hours BST on Sunday 11 October 2026
Interview Date: Monday 02 November 2026
About the Role:
The successful applicant on this Knowledge Transfer Partnership (KTP) project will develop and embed an in-house cyber security compliance capability at G&O Springs, equipping the business to meet NIST SP 800-171, CMMC readiness requirements and ISO 27001 expectations across both office and factory environments.
You will work within G&O Springs, collaborating with senior management, IT, engineering and production teams to map information flows, design priority controls, and build the governance routines the business needs to pursue US & UK defence and aerospace supply-chain opportunities.
What you will gain:
Develop and implement advanced cybersecurity and digital resilience frameworks (including ISO 27001 and NIST 800-171) within a live aerospace and defence manufacturing environment
Gain hands-on experience embedding governance, risk management, incident response and continuous improvement processes across complex digital and operational systems
Work within a high-growth SME supplying major aerospace and defence organisations, contributing to strategic capability development and market expansion
Contribute to establishing a permanent in-house cybersecurity capability that supports access to high-value, security-critical programmes and international markets
Collaborate closely with leading experts from Aston University and the Manufacturing Technology Centre, benefiting from academic supervision and industry mentoring
This KTP offers a unique opportunity for an individual keen to lead and deliver strategic business change. You will work closely with senior University academics and company leadership to apply cutting-edge cybersecurity and digital resilience practices, embedding them into real-world operations to drive sustainable growth and long-term competitive advantage. What we are looking for:
Skills/ experience required for this exciting role include:
Essential
A minimum master’s degree in information security, Cyber Security, or a closely related discipline. Demonstratable advanced theoretical knowledge and practical understanding of secure systems, risk management, and cyber resilience. Strong analytical and research capability, supported by effective project management and stakeholder engagement skills. Proven competence in policy development, quality assurance, process mapping, and gap analysis against recognised information security frameworks (including ISO 27001 and NIST). Experience within an industrial setting or with policy/process development in compliance-focused environments is highly desirable.
Desirable:
Relevant professional certifications or accreditations in cyber security, information security, risk, governance, compliance, or change management (e.g. CISM, CISSP, ISO 27001 Implementer, or equivalent). Experience with Operational Technology/Manufacturing and Cyber security. Attributes: Analytical thinker who can solve complex problems Able to articulate business and technical problems, logical solutions and impactful outcomes Team player who works productively across locations and disciplines Adaptable and comfortable in a hybrid work setting (office-based with travel) Proactive learner who makes the most of development opportunities Communicates well with both technical and non-technical stakeholders
Additional Benefits and support:
£2000 per annum for personal and professional development for the duration of the project Annual leave (26 days p/a) 4 Day Working Week (Monday to Thursday) hybrid working arrangement Professional support and mentorship Mental Health and wellbeing support: https://www.aston.ac.uk/staff-public/hr/Benefits-and-Rewards/health-wellbeing
