European Space Agency - ESA

ESA Cyber Security and INFOSEC Manager

European Space Agency - ESA  •  Kingdom of the Netherlands (Onsite)  •  50 minutes ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Location

ESTEC, Noordwijk, Netherlands, or ESA Headquarters, Paris, France, or ESRIN, Frascati, Italy

Description

The ESA Cyber Security and INFOSEC Manager is in the ESO Corporate Security Assurance Management Office, ESA Security Office, Directorate of Resources and Services.

Reporting to the Head of the ESO Corporate Security Assurance Management Office, you will be responsible for leading all activities related to the cyber security assurance of ESA corporate and directorate systems in accordance with the requirements of the ESA Security Directives. You will, in addition, be responsible for the coordination of a dedicated team supporting cyber security, system certification and accreditation activities. You will carry out your duties in coordination with the relevant representatives of the various ESA directorates, and in synergy with the lnfosec Panel Member State representatives.

Duties

The ESA Cyber Security and INFOSEC Manager's tasks and responsibilities will include:

  • the coordination and management of all ESA Corporate and Directorate Cyber Security Audits;
  • the regular review and updating of the ESA Cyber Security Policy;
  • supervising correct ESA-wide implementation of the ESA Security Regulations and Directives in the domains of communications and information systems and security accreditation and certification policy and procedures;
  • ensuring the correct ESA-wide implementation of the Information Protection Policy and Directive;
  • supporting activities to be presented before the ESA Member State lnfosec Panel and before the Industrial Security Panel.

Your duties will be performed coordinating a dedicated team within ESO and with the support of specialised industry.

In particular:

  • managing the future Cyber Ramp-Up Security Assurance programme;
  • maintaining and executing a programme of cyber security governance audits and technical assessments for corporate and directorate systems in line with a Council-approved ESA Security Master Plan;
  • supporting the delivery of operational and strategic level cyber threat landscape and intelligence reports;
  • management and execution of lnfosec certification and accreditation activities for unclassified and classified networks, systems and applications at corporate and directorate level;
  • independently evaluating security dossiers and drafting formal certification and accreditation statements for approval by the ESA Security Accreditation Authority;
  • defining and maintaining security policy and process guidelines in support of information protection, certification and accreditation processes and baseline security assurance specifications in response to an evolving cyber security threat landscape;
  • supporting corporate and directorate programme and system security risk assessments and delivering risk appraisal recommendations for approval by the ESA Security Accreditation Authority;
  • supporting, in full coordination with CSOC Operations and ESACERT, cyber incident notification, containment, eradication, recovery, remediation and reporting activities;
  • delivering security training programmes, briefings and awareness sessions in the domains of INFOSEC (COMSEC, ITSEC, CYBERSEC), information protection, security risk and business continuity management;
  • supporting the establishment, evolution and continuous improvement of an ESA-wide Cyber Security Maturity Model programme;
  • supporting the definition of classified procurement packages including Programme Security Instructions and Security Classification Guides.

You will also be responsible for identifying, assessing, managing and reporting the health and safety risks in your area of responsibility.

Technical competencies

In-depth knowledge of high-security assurance requirements for classified systems and programmes

Extensive experience as a security certifier or accreditor for complex systems

Knowledge of ESA and EU accreditation processes

Knowledge and application experience of cyber security and risk management standards and frameworks

Substantial experience in cyber security policy and system security engineering

Experience in conducting cyber security audits

Behavioural competencies

Result Orientation

Operational Efficiency

Fostering Cooperation

Relationship Management

Continuous Improvement

Forward Thinking

For more information, please refer to the ESA Core Behavioural Competencies guidebook

Education and professional experience

A master's in engineering, computer science, or cyber security is required for this post together with, in principle, 4 years of relevant professional experience. Alternatively, candidates with a bachelor's degree, complemented by an additional four (4) years of relevant professional experience may be considered.

Additional requirements

  • The potential to manage individuals or a team of experts;
  • The ability to organise their activities and ensure a motivating work environment;
  • Strong leadership capabilities, with proven relationship management and communication skills;
  • The ability to drive your team's performance, developing your people by encouraging learning, delegating responsibility and giving regular and constructive feedback;
  • Strong problem-solving skills to deal with day-to-day operational challenges, together with demonstrated planning and organisational skills;
  • Strong result orientation with the ability to set priorities and present practical solutions both orally and in writing;
  • The ability to manage challenging situations proactively and constructively and to be customer-focused.
  • People management experience is an asset, as is international experience, i.e. outside your home country, as well as experience in diverse functional areas relevant to ESA activities.
  • Excellent organisational and stakeholder management skills;
  • Willingness to travel;
  • International experience including interfacing with international and intergovernmental organisations’ security frameworks or national security authorities;
  • Professional certifications in cyber security would be an asset.

Diversity, Equity and Inclusiveness

ESA is an equal opportunity employer, committed to achieving diversity within the workforce and creating an inclusive working environment. We therefore welcome applications from all qualified candidates irrespective of gender, sexual orientation, ethnicity, religious beliefs, age, disability or other characteristics.

At the Agency we value diversity, and we welcome people with disabilities. Whenever possible, we seek to accommodate individuals with disabilities by providing the necessary support at the workplace. The Human Resources Department can also provide assistance during the recruitment process. If you would like to discuss this further, please contact us via email at contact.human.resources@esa.int.

Important Information and Disclaimer

In principle, recruitment will be within the advertised grade band (A2-A4). However, if the selected candidate has less than four years of relevant professional experience following the completion of the master’s degree, the position may be filled at A1 level.

Applicants must be eligible to access information, technology, and hardware which is subject to European or US export control and sanctions regulations & eligible to acquire the security clearance by their national security administrations.

During the recruitment process, the Agency may request applicants to undergo selection tests. Additionally, successful candidates will need to undergo basic screening before appointment, which will be conducted by an external background screening service, in compliance with the European Space Agency's security procedures.

Note that ESA is in the process of transitioning to a Matrix setup, which could lead to organisational changes affecting this position.

The information published on ESA’s careers website regarding working conditions is correct at the time of publication. It is not intended to be exhaustive and may not address all questions you would have.

Nationality and Languages

Please note that applications are only considered from nationals of one of the following States: Austria, Belgium, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Luxembourg, the Netherlands, Norway, Poland, Portugal, Romania, Slovenia, Spain, Sweden, Switzerland, the United Kingdom and Canada, Cyprus, Latvia, Lithuania and Slovakia.

According to the ESA Convention, staff shall be recruited on the basis of their qualifications, taking into account an adequate distribution of posts among nationals of the Member States.

The working languages of the Agency are English and French. A good knowledge of one of these is required. Knowledge of another Member State language would be an asset.

European Space Agency - ESA

About European Space Agency - ESA

The European Space Agency (ESA) is Europe’s gateway to space. Its mission is to shape the development of Europe’s space capability and ensure that investment in space continues to deliver benefits to the citizens of Europe and the world.

ESA is an international organisation with 23 Member States. By coordinating the financial and intellectual resources of its members, it can undertake programmes and activities far beyond the scope of any single European country.

ESA's 23 Member States are Austria, Belgium, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Luxembourg, the Netherlands, Norway, Poland, Portugal, Romania, Slovenia, Spain, Sweden, Switzerland and the United Kingdom.

Slovakia, Latvia and Lithuania are Associate Members. Canada takes part in some projects under a cooperation agreement.

Four other EU states have Cooperation Agreements with ESA: Bulgaria, Croatia, Cyprus and Malta.

Industry
Government & Public Safety
Company Size
5,001-10,000 employees
Headquarters
Paris, FR
Year Founded
Unknown
Website
esa.int
Social Media