Senior Security Management- IRIS2
Iahtgs · Spain
About The Role
Hispasat, as part of the SpaceRISE consortium, is responsible for the technical implementation and ensuring the success of the IRIS² project, leveraging its extensive experience in satellite communications. This collaboration is essential to provide secure and reliable high-performance communication solutions to the European Union and its member states.
To be part of this project, we are looking for Security Management (SM) . The responsibilities of the position are as follows:
Responsibilities
- Define, implement and oversee the Information Security Management System and the comprehensive security measures required for the IRIS² programme.
- Ensure alignment with EU and ESA security policies, the Concession Agreement, EUSPA security-accreditation standards, applicable project documentation and international frameworks including ISO/IEC 27000 and 31000, NIST SP 800-53, CIS Controls, ISO 22301 and NIST SSDF.
- Coordinate and oversee the management and protection of classified programme information in accordance with applicable legislation and regulations.
- Define and oversee the programme security-control system, with particular attention to the security requirements established for IRIS².
- Ensure compliance with the legal and regulatory security requirements associated with the programme and with instructions from the European Commission, ESA and EUSPA.
- Develop and maintain security policies, procedures, guidelines, secure-installation guides and manuals.
- Coordinate the integration of protection measures, including encryption, access control and alert monitoring, and oversee vulnerability remediation.
- Develop and oversee the programme and supply-chain security-risk matrix, identify internal and external threats, and define and monitor mitigation strategies and plans.
- Establish organisational priorities, limits, risk tolerances and assumptions to support internal and supply-chain risk-management decisions.
- Oversee operational resilience and business continuity and coordinate continuity plans for normal operations, operations under attack and recovery scenarios.
- Oversee technical security plans and the design and coordination of incident-response protocols, ensuring compliance with NIS2 and the programme control framework.
- Oversee audits, assess the impact of potential security breaches and define contingency plans.
- Coordinate security and cybersecurity activities with other organisational areas, including the Security Operations Centre.
- Ensure compliance with security requirements throughout the SpaceRISE consortium's multi-tier supply chain, including prime contractors, subcontractors and suppliers.
- Coordinate with programme stakeholders and participate in projects implementing security measures.
Minimum requirements
- Bachelor's Degree in Industrial Engineering, Computer Science, Information Systems or an equivalent technical discipline; specialisation in cybersecurity or European space law is considered an asset.
- 4 to 6 years of experience in the implementation and maintenance of security-management systems, preferably in space programmes, governmental satellite communications or critical telecommunications infrastructure.
- ISO/IEC 27001 ISMS Lead Auditor certification is required.
- Specialist certification in implementation of the Spanish National Security Scheme is required.
- CISSP or CISM certification is highly valued; CISA, CCSP, Cloud Security, CEH, OSCP or CompTIA Security+ certifications are considered assets.
- Practical expertise in ISO/IEC 27000, ISO/IEC 31000, NIST SP 800-53, CIS Controls, ISO 22301, NIST SSDF, OWASP and SAFECode.
- Experience managing classified information.
- Knowledge of multi-tier supply chains in European Union programmes, including public procurement, satellite operators, satellite manufacturers, Ground Segment suppliers and technology subcontractors.
- Experience assessing security maturity and collaborating on secure-by-design architectures for space and satellite-communications systems.
- Knowledge of the EU regulatory framework applicable to critical governmental satellite-communications infrastructure, including NIS2, DORA, EU Secret requirements and Regulation (EU) 2023/588.
- Independent judgement, integrity and the ability to act impartially in relation to programme-management authorities.
- Strong communication and leadership skills and experience coordinating multidisciplinary teams, auditors and technical and non-technical stakeholders across a pan-European supply chain.
- Nationality of an EU Member State and willingness to undergo an EU Secret clearance process.
- Fluency in English, both written and spoken; any other European language is considered an asset.
Location
- Arganda del Rey, Madrid, Spain.
At Hispasat we promote equal opportunities and an inclusive environment. All our selection processes are based on objective criteria, without distinction of gender, age, origin, sexual orientation, disability or other personal or social conditions. We value diversity as a driver of innovation and growth.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
