6 дней назад
Cyber Security Manager (Aerospace)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cyber Security Manager (Aerospace): Owning the GRC estate and leading operational digital security and compliance for an aircraft wing manufacturing site with an accent on ISMS governance, Airbus compliance, and cybersecurity maturity assessment. Focus on aligning ISO 27001, NIST CSF, EASA Part-IS, OT security, supply chain assessments, and Microsoft Defender XDR operations.
Location: Prestwick, Ayrshire, UK; site-based (100%). Occasional travel is required. Applicants must have the legal right to work in the UK; visa sponsorship is not available.
Company
manufactures aircraft wing structures for Airbus commercial aircraft from its Prestwick site.
What you will do
- Own the GRC Suite and Active Risk Manager portal, including control tracking, risk plans, and audit evidence.
- Build and maintain the ISMS policy suite in line with ISO 27001:2022, Airbus requirements, and Group Directives.
- Manage Airbus cybersecurity compliance, internal audits, evaluations, and remediation action plans.
- Lead cybersecurity maturity assessments using NIST CSF 2.0 and industrial threat modelling.
- Govern Microsoft Defender XDR policies, coordinate with the managed security service provider, and lead post-incident reviews.
- Oversee OT and safety alignment, supply chain security assessments, security awareness campaigns, staff, contractors, budgets, and vendor SLAs.
Requirements
- Extensive information security, GRC, or cyber operations experience in aerospace, defence, manufacturing, or heavy industry.
- Proven experience designing, building, and delivering an enterprise ISMS.
- Expertise in ISO 27001:2022, NIST CSF 2.0, EASA Part-IS, and formal risk methodologies such as EBIOS RM, ISO 27005, or NIST 800-30.
- Experience with aerospace supply chain requirements, Airbus cybersecurity frameworks, GRC platforms, and Microsoft Defender XDR.
- Security governance, risk, or audit certification such as CISM, CRISC, CISA, CISSP, or ISO 27001 Lead Auditor/Implementer.
- Technical understanding of factory OT environments, network segmentation, and industrial automation security.
Culture & Benefits
- 37-hour working week with a half-day Friday.
- 33 days of annual leave, increasing with service, plus a performance-linked annual bonus.
- Defined contribution pension with 4% employee and 8% employer contributions.
- Life assurance worth four times basic salary, virtual GP service, employee assistance, and wellbeing support.
- Professional development and training opportunities, with free on-site parking.
Hiring process
- Offers are subject to right-to-work checks, employment references, Disclosure Scotland, and a pre-employment medical including drug and alcohol testing.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Head of Site Security (Aerospace)
6 дней назад
Ground System Security Design Engineer (Aerospace)
6 дней назад
2nd/3rd Line Cyber Defence Engineer
11 дней назад
Security Architect (Cybersecurity)
5 дней назад
PCI DSS Advisory & Service Delivery Manager (Cybersecurity)
65 000GBP
10 дней назад