Job Description:Job Profile Summary:Reporting to the Chief Information Officer, the VP of Cybersecurity sets and leads AerSale's enterprise cybersecurity strategy, governance, and operations. The role protects AerSale's information, systems, products, and customers across all three business segments - building a Zero Trust posture, governing the secure adoption of AI, and ensuring the compliance obligations of a publicly traded aviation company are met. The VP of Cybersecurity leads the teams that identify, protect, detect, respond to, and recover from cyber threats and vulnerabilities.
Essential Duties and Responsibilities:Strategy & Governance- Define and own the enterprise cybersecurity strategy, roadmap, and budget, aligned to business risk and AerSale's growth objectives.
- Establish and maintain security policies, standards, and a governance framework (e.g., NIST CSF) and report risk posture to executive leadership and the Audit Committee.
- Operate enterprise cyber risk management: risk assessments, threat modeling, control design, and remediation tracking.
Architecture & Engineering- Lead the design and implementation of a Zero Trust architecture spanning identity, network, endpoint, data, and cloud.
- Direct security tooling strategy and operations - SIEM, DLP, IPS/IDS, EDR/XDR, identity and access management, and email and cloud security.
- Embed "secure by design" practices and partner with application and engineering teams on secure software and integration designs.
AI & Data Security- Govern the secure adoption of enterprise AI (e.g., the Claude Team deployment and Microsoft 365 Copilot): establish controls for data egress/leakage, prompt-injection and model-misuse risks, acceptable use, and data-classification boundaries.
- Partner with data and AI leadership to secure data pipelines, integration/MCP layer, and AI/ML workflows.
Security Operations & Incident Response- Lead monitoring, threat detection, vulnerability management, and incident response; maintain and regularly exercise incident-response and breach-notification plans.
- Maintain current threat intelligence from law enforcement and industry sources and brief stakeholders with actionable guidance.
Compliance, Third-Party & Product Risk- Ensure compliance with applicable obligations - SOX IT general controls, FAA / aviation cybersecurity expectations, and customer and contractual requirements; coordinate audits and remediation.
- Lead third-party / supply-chain security risk management and vendor security assessments.
People & Culture- Build, lead, and develop the cybersecurity team; run the enterprise security-awareness and phishing-resilience program.
Education & Experience- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field; Master's preferred.
- 10+ years in cybersecurity, including at least 5 years in a security leadership / managerial role.
- Demonstrated experience building security programs and Zero Trust architectures in a regulated and/or publicly traded environment.
- Experience governing cloud (Microsoft 365 / Azure), AWS and SaaS security.
Skills & Abilities- Deep knowledge of security frameworks (NIST CSF, ISO/IEC 27001) and risk management.
- Hands-on familiarity with SIEM, DLP, IPS/IDS, EDR/XDR, and IAM technologies.
- Experience defining governance and controls for enterprise AI adoption (data egress, prompt-injection, acceptable use).
- Ability to manage budgets, teams, and compliance programs.
- Strong executive communication and cross-functional collaboration with senior leadership.
- Leadership and strategic planning in cybersecurity.
Preferred- Industry certifications (e.g., CISSP, CISM, CCSP, CRISC).
- Aviation / aerospace or other regulated-industry experience; familiarity with SOX, FAA, and - if applicable to defense-related work - CMMC requirements.
If you would like to see your career take flight, apply today!