Confidential mandate

Aviation Cyber-Airworthiness Evidence Director — Urban Air Mobility

Planned Hiring / New

Aviation Cyber-Airworthiness Evidence Director mandate in Rome, Italy · Urban Air Mobility

An urban-air-mobility developer needs an independent director to construct certification-grade cybersecurity evidence across aircraft systems, ground services and software updates within six months in Rome.

The mandate

Aircraft threat assessments, system-safety analyses and software verification currently use different configuration baselines, leaving certification reviewers unable to trace a cyber failure condition from attack path to tested mitigation. Ground maintenance, charging and update services add external dependencies whose assurance packages stop at their own product boundary. The defined problem is to create one reviewable cyber-airworthiness evidence chain without reopening the aircraft's entire safety architecture.

The deliverables are an approved cybersecurity certification plan, aircraft-and-ground trust-boundary model, threat and failure-condition crosswalk, requirement trace, verification catalogue, supplier-evidence index, residual-risk register and compliance summary. Each artefact must identify configuration, evidence owner and authority question; inherited supplier claims need stated reliance conditions rather than being copied into the aircraft case as facts.

Milestone one on 30 October 2026 delivers the agreed certification perimeter and evidence-gap map. Milestone two on 18 December provides the reviewed threat-to-requirement chain and supplier acceptance criteria; milestone three on 12 February 2027 completes witnessed verification for priority failure conditions; final delivery on 31 March requires the consolidated compliance dossier, closed reviewer comments and client-team rehearsal.

The accountable executive, system-safety head, quality director and certification liaison will accept the work only when sampled claims trace bidirectionally from aircraft configuration through hazard, security requirement, implementation and test result. Deliberately failed mitigations must produce the expected detection or safe response, supplier evidence must meet its declared scope, and client engineers must answer a mock authority review without consultant intervention.

The client provides controlled access to aircraft architecture, safety assessments, requirements, test rigs, supplier submissions, change records and authority correspondence, with named engineering owners available within two working days. The consultant cannot approve airworthiness, change flight-safety requirements, direct flight tests or make representations to authorities; formal compliance findings and production configuration remain with authorised company personnel.

Why this is external work

Internal cyber and safety teams each authored portions of the current case and cannot independently reconcile conflicting baselines. Certification staff need concentrated experience translating adversarial behaviour into airworthiness evidence rather than another design review. A bounded external director can expose unsupported reliance and leave a repeatable assurance method before formal authority scrutiny intensifies.

What you will own

  • Reconcile aircraft, ground, maintenance and update configurations into one controlled cybersecurity certification perimeter with explicit exclusions.
  • Map credible attack paths to safety effects, security requirements, assurance objectives and accountable verification owners.
  • Challenge supplier submissions for configuration coverage, independence, test realism, vulnerability handling and continuing-airworthiness obligations.
  • Build bidirectional traceability from threat assumptions through implemented controls to retained test evidence and unresolved findings.
  • Specify witnessed tests for privilege abuse, malicious update, datalink manipulation and compromised ground-service dependencies.
  • Maintain a reviewer-comment ledger that records evidence requested, conclusion reached, accountable approver and configuration impact.
  • Transfer the evidence index, test catalogue, supplier conditions and mock-review record through a client-led certification rehearsal.

Candidate qualifications

  • Directed cybersecurity assurance for a certified aircraft, avionics platform or comparably safety-regulated airborne system.
  • Can evidence a threat-to-safety-to-verification chain accepted during certification or formal airworthiness review.
  • Integrated aircraft, ground support, maintenance, datalink and software-update dependencies into a controlled assurance perimeter.
  • Challenged supplier evidence where tested configuration, independence or continuing-vulnerability obligations were materially incomplete.
  • Worked directly with safety, quality, systems engineering and certification authorities while preserving each decision boundary.
  • Delivered a compliance dossier that internal engineers later defended without consultant authorship or unsupported inherited claims.

Non-negotiables

  • Available for all Rome, Turin and Cologne milestone sessions and controlled test activity.
  • Independent of avionics suppliers, certification advisers and test laboratories whose evidence enters the dossier.
  • Will not imply authority approval, sign airworthiness findings or direct flight-safety decisions.
  • Has director or designated-principal authority in aviation cybersecurity assurance, not enterprise IT compliance.
  1. 49 words maximum. Which cyber-airworthiness claim have you traced from attack path through witnessed verification?
  2. 49 words maximum. Describe supplier evidence you rejected because its configuration scope was misleading.
  3. 49 words maximum. What failed test would force you to reopen a seemingly complete compliance chain?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.