Job Posting Organization: The European Space Agency (ESA) is an intergovernmental organization dedicated to the exploration of space. Established in 1975, ESA has grown to include 22 member states and employs over 2,200 staff members. The agency operates across multiple countries, with its headquarters located in Paris, France, and additional facilities in the Netherlands and Italy. ESA's mission is to shape the development of Europe's space capability and ensure that investment in space continues to deliver benefits to the citizens of Europe and the world. The agency is committed to fostering international cooperation in space exploration and research, and it plays a crucial role in advancing scientific knowledge and technological innovation in the field of space science and applications.
Job Overview: The ESA Cyber security" style="border-bottom: 1px dotted #007bff !important;">Security and INFOSEC Manager will play a pivotal role in the ESO Corporate Security Assurance Management Office, which is part of the ESA Security Office under the Directorate of Resources and Services. This position involves leading all activities related to cyber security assurance for ESA's corporate and directorate systems, ensuring compliance with ESA Security Directives. The manager will coordinate a dedicated team focused on cyber security, system certification, and accreditation activities. The role requires collaboration with various ESA directorates and Member State representatives to ensure a cohesive approach to cyber security across the organization. The successful candidate will be responsible for managing the Cyber Ramp-Up Security Assurance programme, conducting cyber security audits, and maintaining the ESA Cyber Security Policy. Additionally, the manager will support the delivery of cyber threat intelligence reports and oversee INFOSEC certification and accreditation activities for both unclassified and classified systems.
Duties and Responsibilities: The duties and responsibilities of the ESA Cyber Security and INFOSEC Manager include: coordinating and managing all ESA Corporate and Directorate Cyber Security Audits; regularly reviewing and updating the ESA Cyber Security Policy; supervising the implementation of ESA Security Regulations and Directives; ensuring compliance with the Information Protection Policy; supporting activities presented to the ESA Member State INFOSEC Panel; managing the Cyber Ramp-Up Security Assurance programme; executing cyber security governance audits and technical assessments; delivering operational and strategic cyber threat landscape reports; managing INFOSEC certification and accreditation for networks and systems; evaluating security dossiers and drafting certification statements; defining security policy and process guidelines; supporting security risk assessments; coordinating cyber incident response activities; delivering security training and awareness sessions; and supporting the establishment of an ESA-wide Cyber Security Maturity Model programme.
Required Qualifications: Candidates must possess strong leadership capabilities, excellent organizational and stakeholder management skills, and the ability to motivate and manage a team of experts. They should demonstrate strong problem-solving skills, result orientation, and the ability to manage challenging situations proactively. Effective communication skills are essential, as is the ability to interface with international and intergovernmental organizations. Professional certifications in cyber security are considered an asset, along with international experience and experience in diverse functional areas relevant to ESA activities.
Educational Background: A master's degree in engineering, computer science, or cyber security is required for this position. Alternatively, candidates with a bachelor's degree and an additional four years of relevant professional experience may also be considered. This educational background ensures that candidates have the necessary technical knowledge and skills to effectively manage cyber security and INFOSEC responsibilities within ESA.
Experience: Candidates should have a minimum of four years of relevant professional experience in cyber security, particularly in high-security assurance requirements for classified systems and programs. Extensive experience as a security certifier or accreditor for complex systems is essential, along with knowledge of ESA and EU accreditation processes. Experience in conducting cyber security audits and familiarity with cyber security policy and system security engineering are also required.
Languages: The working languages of ESA are English and French. A good knowledge of one of these languages is mandatory, while knowledge of another Member State language would be considered an asset. This linguistic requirement ensures effective communication within the diverse international environment of ESA.
Additional Notes: The position is a four-year appointment, extendable to indefinite, and falls within the grade band A2-A
Recruitment will be conducted within this grade band, but candidates with less than four years of relevant experience may be considered for an A1 level position. Applicants must be eligible to access information subject to European or US export control regulations and must be able to acquire security clearance from their national security administrations. The recruitment process may include selection tests, and successful candidates will undergo basic screening before appointment. ESA is committed to diversity and inclusiveness, welcoming applications from all qualified candidates regardless of gender, sexual orientation, ethnicity, religious beliefs, age, disability, or other characteristics.
Info
Job Posting Disclaimer
This job posting is provided for informational purposes only. The accuracy of the job description, qualifications, and other details mentioned is the sole responsibility of the employer or the organization listing the job. We do not guarantee the validity or legitimacy of this job posting. Candidates are advised to conduct their own due diligence and verify the details directly with the employer before applying.
We are not liable for any decisions or actions taken by applicants in response to this job listing. By applying, you agree that all application processes, interviews, and potential job offers are managed exclusively by the listed employer or organization.
Beware of fraudulent job offers. Do not provide sensitive personal information or make any payments to secure a job.