Back to jobs
Aon Corporation
Aon Corporation

Associate Director - Cyber M&A - Infrastructure Sector

City of London On-site 5-10 yrs exp
Cyber securityDue diligenceInfrastructureOperational technologyRisk assessment

Requirements

Requires strong cyber security expertise within critical infrastructure environments and experience with IT/OT systems. Candidates must demonstrate deep knowledge of security frameworks and possess strong client-facing consulting skills.

Job Description

Associate Director, Cyber M&A – Infrastructure Sector

Do you bring deep cyber technical knowledge with the ability to understand and articulate cyber security risks and trends across critical national infrastructure, including the threat vectors impacting energy, transport, water, digital infrastructure and social infrastructure assets?

Do you have client-facing skills that allow you to translate technical and operational technology (OT) findings into commercial and financial impact for infrastructure funds and corporate investors across the M&A lifecycle?

If so, then we would love to hear from you in connection with these new opportunities based within Aon’s multifaceted M&A Transactions Solutions (AMATS) practice, situated within our flagship London office!

Aon is in the business of better decisions

At Aon, we shape decisions for the better to protect and enrich the lives of people around the world.

As an organisation, we are united through trust as one inclusive team, and we are passionate about helping our colleagues and clients succeed.

What the day will look like

In this wide and varied role, with a specific focus on the infrastructure sector, your key responsibilities will include:

  • Conduct cyber due diligence on infrastructure investments, supporting acquisitions, carve-outs and wider transaction activity.
  • Assess IT and Operational Technology (OT) environments across sectors such as energy, transport, water, digital and social infrastructure.
  • Identify cyber security risks, evaluate maturity levels and develop practical remediation recommendations.
  • Map security requirements, regulatory obligations and minimum security standards to create robust improvement plans.
  • Support business development activities, including client pitches, proposals and onboarding for infrastructure investors and corporate clients.
  • Work closely with senior collaborators and clients, providing advice on cyber strategy, integration, carve-outs, incident response and portfolio-wide cyber improvement programmes.

How this opportunity is different

This is far more than a traditional cyber role. You'll be at the centre of high-profile M&A transactions, advising investors and businesses on the cyber and technology risks that shape deal value across critical infrastructure assets. Working alongside market-leading specialists in cyber, AI, technology, risk and human capital, you'll help clients navigate some of the most sophisticated and strategically important transactions in the market. With Cyber M&A one of the firm's fastest-growing areas, this is a rare opportunity to join a high-growth team, influence major investment decisions, and build your profile in a niche where technical expertise and commercial impact truly come together.

Skills and experience that will lead to success

For success in this role, we're looking for someone who can demonstrate:

  • Strong cyber security expertise within critical infrastructure environments, with experience across sectors such as energy, transportation, telecommunications, water, or social infrastructure.
  • A deep understanding of cyber security frameworks, regulations, and governance, including NIST CSF, IEC 62443, NIS2, KRITIS, NERC, and other relevant standards.
  • Experience working across both IT and Operational Technology (OT) environments, with a strong appreciation of the unique risks, threats, and controls associated with each.
  • Proven capability in conducting OT cyber maturity assessments and audits, identifying control gaps and developing practical remediation and resilience strategies.
  • Broad technical cyber security knowledge, spanning areas such as security architecture, OT networks, cloud security, AI, data protection, security operations, and secure software development.
  • Strong client-facing and consulting skills, with the ability to develop compelling proposals, lead collaborator discussions, and deliver value to infrastructure operators, investors, and corporate clients.

Desirable: Industry-recognised certifications such as CISSP, CISM, CRISC, or ISO 42001.

2575941

Education

Professional Certificate

Skills

Cyber securityDue diligenceInfrastructureOperational technologyRisk assessmentM&ANIST CSFIEC 62443NIS2Security architectureCloud securityData protectionSecurity operationsConsultingBusiness developmentIncident response