Cyber Security Manager
Airbus
- Location
- Prestwick
- Work model
- On-Site
- Level
- Mid
- Posted
- Sep 4, 2026
Skills
About this role
Job Description
Cyber Security Manager hours per week (half‑day Friday) Type: Full‑time Salary: Level 5 Travel Required: Occasional Work Location: Site‑based (100%) Security Checks: BPSS, Disclosure Scotland, pre‑employment medical (including drug and alcohol testing) Join One of Ayrshire’s Largest Engineering Employers Prestwick Aerosystems continues Ayrshire’s long‑standing aircraft manufacturing tradition. From our Prestwick site, we manufacture aircraft wing structures used on Airbus commercial aircraft worldwide. Prestwick Aerosystems is seeking a Cyber Security Manager to own the complete GRC estate and lead the operational delivery of digital security and compliance across the organisation. Reporting directly to the Digital Security Officer (DSO), this role bridges strategic risk governance and steady-state business operations, taking core accountability for establishing and maintaining our ISMS, maintaining full Airbus compliance, and evaluating cybersecurity maturity. How you will contribute to the team Primary Responsibilities Full GRC Estate & Platform Ownership: Serve as the primary business owner for our GRC Suite and Active Risk Manager (ARM) portal, maintaining continuous control tracking, Risk and Opportunities Management (ROM) plans, and automated audit evidence. ISMS Build & Policy Governance: Build, localize, and sustain the Information Security Management System (ISMS) policy suite from scratch, aligning controls with ISO 27001:2022, the Airbus Digital Handbook, and mandatory Airbus Group Directives. Airbus Compliance & Audit Management: Maintain full operational compliance for Airbus Cybersecurity Level for subsidiaries, design internal audit schedules, run evaluations against the Airbus Subsidiary Questionnaire, and manage the remediation Action Plans. Cybersecurity Maturity & Threat Profiling: Lead ongoing baseline cybersecurity maturity assessments using NIST CSF 2.0 and execute industrial threat modelling using industry standard methodologies. Secondary Responsibilities Operational Technology (OT) & Safety Alignment: Partner with factory operations to integrate the digital ISMS with physical Safety Management Systems (SMS) to maintain EASA Part-IS regulatory alignment. Security Operations & Incident Governance: Govern Microsoft Defender XDR security policies (Endpoint, Servers, Office 365) and act as the operational contact for our Managed Security Service Provider, driving post-incident Return of Experience (RETEX) root-cause reviews. Supply Chain & Third-Party Security: Conduct Supply Chain Information Security Assessments (SCISA), ensure mandatory Airbus clauses are integrated into supplier contracts, and verify vendor penetration tests. Security Culture & HR Liaison: Oversee employee security learning journeys, run phishing simulation campaigns, and partner with HR to enforce specialized recruitment screening for high-access positions.
Team
Leadership & Financial Control: Manage internal security staff and external contractors, execute performance management cycles, oversee GRC/security tool budgets, and enforce vendor performance SLAs. Requirements for the role You will have: Extensive experience leading Information Security Management, GRC, or cyber operations in aerospace, defence, manufacturing, or heavy industrial sectors. Proven track record of designing, building, and delivering an enterprise ISMS. Deep expertise in ISO 27001:2022, NIST CSF 2.0, EASA Part-IS, and formal risk methodologies (EBIOS RM, ISO 27005, or NIST 800-30). Experience managing aerospace supply chain requirements and mandatory Airbus cybersecurity frameworks. Hands-on proficiency with GRC platforms (FENCE, MetricStream, etc) and the Microsoft Defender XDR stack. Professional certification in security governance, risk, or auditing (e.g., CISM, CRISC, CISA, CISSP, or ISO 27001 Lead Auditor/Implementer). Solid technical understanding of factory OT