Назад
Company hidden
6 дней назад

Cyber Security Manager (Aerospace)

Формат работы
onsite
Тип работы
fulltime
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Security Manager (Aerospace): Owning the GRC estate and leading operational digital security and compliance for an aircraft wing manufacturing site with an accent on ISMS governance, Airbus compliance, and cybersecurity maturity assessment. Focus on aligning ISO 27001, NIST CSF, EASA Part-IS, OT security, supply chain assessments, and Microsoft Defender XDR operations.

Location: Prestwick, Ayrshire, UK; site-based (100%). Occasional travel is required. Applicants must have the legal right to work in the UK; visa sponsorship is not available.

Company

hirify.global manufactures aircraft wing structures for Airbus commercial aircraft from its Prestwick site.

What you will do

  • Own the GRC Suite and Active Risk Manager portal, including control tracking, risk plans, and audit evidence.
  • Build and maintain the ISMS policy suite in line with ISO 27001:2022, Airbus requirements, and Group Directives.
  • Manage Airbus cybersecurity compliance, internal audits, evaluations, and remediation action plans.
  • Lead cybersecurity maturity assessments using NIST CSF 2.0 and industrial threat modelling.
  • Govern Microsoft Defender XDR policies, coordinate with the managed security service provider, and lead post-incident reviews.
  • Oversee OT and safety alignment, supply chain security assessments, security awareness campaigns, staff, contractors, budgets, and vendor SLAs.

Requirements

  • Extensive information security, GRC, or cyber operations experience in aerospace, defence, manufacturing, or heavy industry.
  • Proven experience designing, building, and delivering an enterprise ISMS.
  • Expertise in ISO 27001:2022, NIST CSF 2.0, EASA Part-IS, and formal risk methodologies such as EBIOS RM, ISO 27005, or NIST 800-30.
  • Experience with aerospace supply chain requirements, Airbus cybersecurity frameworks, GRC platforms, and Microsoft Defender XDR.
  • Security governance, risk, or audit certification such as CISM, CRISC, CISA, CISSP, or ISO 27001 Lead Auditor/Implementer.
  • Technical understanding of factory OT environments, network segmentation, and industrial automation security.

Culture & Benefits

  • 37-hour working week with a half-day Friday.
  • 33 days of annual leave, increasing with service, plus a performance-linked annual bonus.
  • Defined contribution pension with 4% employee and 8% employer contributions.
  • Life assurance worth four times basic salary, virtual GP service, employee assistance, and wellbeing support.
  • Professional development and training opportunities, with free on-site parking.

Hiring process

  • Offers are subject to right-to-work checks, employment references, Disclosure Scotland, and a pre-employment medical including drug and alcohol testing.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →