Skip to content
← Back to job listings

Cyber Security Manager

5580 Prestwick Aerosystems Limited · Prestwick, United Kingdom

CybersecurityExternal listingfull-time16 minutes ago

About The Role

Prestwick Aerosystems continues Ayrshire’s long‑standing aircraft manufacturing tradition. From our Prestwick site, we manufacture aircraft wing structures used on Airbus commercial aircraft worldwide.

Prestwick Aerosystems is seeking a Cyber Security Manager to own the complete GRC estate and lead the operational delivery of digital security and compliance across the organisation. Reporting directly to the Digital Security Officer (DSO), this role bridges strategic risk governance and steady-state business operations, taking core accountability for establishing and maintaining our ISMS, maintaining full Airbus compliance, and evaluating cybersecurity maturity.

How you will contribute to the team

Primary Responsibilities

  • Full GRC Estate & Platform Ownership: Serve as the primary business owner for our GRC Suite and Active Risk Manager (ARM) portal, maintaining continuous control tracking, Risk and Opportunities Management (ROM) plans, and automated audit evidence.
  • ISMS Build & Policy Governance: Build, localize, and sustain the Information Security Management System (ISMS) policy suite from scratch, aligning controls with ISO 27001:2022, the Airbus Digital Handbook, and mandatory Airbus Group Directives.
  • Airbus Compliance & Audit Management: Maintain full operational compliance for Airbus Cybersecurity Level for subsidiaries, design internal audit schedules, run evaluations against the Airbus Subsidiary Questionnaire, and manage the remediation Action Plans.
  • Cybersecurity Maturity & Threat Profiling: Lead ongoing baseline cybersecurity maturity assessments using NIST CSF 2.0 and execute industrial threat modelling using industry standard methodologies.

Secondary Responsibilities

  • Operational Technology (OT) & Safety Alignment: Partner with factory operations to integrate the digital ISMS with physical Safety Management Systems (SMS) to maintain EASA Part-IS regulatory alignment.
  • Security Operations & Incident Governance: Govern Microsoft Defender XDR security policies (Endpoint, Servers, Office 365) and act as the operational contact for our Managed Security Service Provider, driving post-incident Return of Experience (RETEX) root-cause reviews.
  • Supply Chain & Third-Party Security: Conduct Supply Chain Information Security Assessments (SCISA), ensure mandatory Airbus clauses are integrated into supplier contracts, and verify vendor penetration tests.
  • Security Culture & HR Liaison: Oversee employee security learning journeys, run phishing simulation campaigns, and partner with HR to enforce specialized recruitment screening for high-access positions.
  • Team Leadership & Financial Control: Manage internal security staff and external contractors, execute performance management cycles, oversee GRC/security tool budgets, and enforce vendor performance SLAs.

Requirements for the role

You will have

  • Extensive experience leading Information Security Management, GRC, or cyber operations in aerospace, defence, manufacturing, or heavy industrial sectors.
  • Proven track record of designing, building, and delivering an enterprise ISMS.
  • Deep expertise in ISO 27001:2022, NIST CSF 2.0, EASA Part-IS, and formal risk methodologies (EBIOS RM, ISO 27005, or NIST 800-30).
  • Experience managing aerospace supply chain requirements and mandatory Airbus cybersecurity frameworks.
  • Hands-on proficiency with GRC platforms (FENCE, MetricStream, etc) and the Microsoft Defender XDR stack.
  • Professional certification in security governance, risk, or auditing (e.g., CISM, CRISC, CISA, CISSP, or ISO 27001 Lead Auditor/Implementer).
  • Solid technical understanding of factory OT environments, network segmentation, and industrial automation security.

What we will offer you

  • 37‑hour working week (half‑day Friday)
  • Defined contribution pension (4% employee / 8% employer)
  • 33 days annual leave (rising with service)
  • Annual bonus linked to company performance
  • Life assurance (4× basic salary)
  • Virtual GP service, Employee
  • Assistance Programme and wellbeing support
  • Professional development and training opportunities
  • Free on‑site parking
  • What happens next
  • If you are ready to play a key role in supporting our people and operations at Prestwick, apply today.

Right to Work in the UK

All applicants must have the legal right to work in the UK at the time of application. Prestwick Aerosystems is unable to offer visa sponsorship for this role. Any offer of employment will be subject to satisfactory Right to Work checks, carried out in accordance with UK Government requirements.

You will also be required to complete employment references, Disclosure Scotland and a pre‑employment medical.

Prestwick Aerosystems is an equal opportunity employer. We welcome applications from all backgrounds and are committed to building a diverse and inclusive workplace.

This job requires an awareness of any potential compliance risks and a commitment to act with integrity, as the foundation for the Company’s success, reputation and sustainable growth.

Company

Prestwick Aerosystems Limited

Employment Type

Permanent -------

Experience Level

Professional

Job Family

Your application data will be processed by Prestwick Aerosystems and other companies under the control of Airbus for all necessary hiring, vetting, and security checks. This processing is required to assess your suitability for employment

This is an external listing. JobSpring does not represent or verify the employer. Report this listing