ESA logo

ESA Cyber Security and INFOSEC Manager

ESA

Noordwijk, Paris, Frascati
Full-time
5-10 years experience
On-site

Key Skills

Cyber security
INFOSEC
Risk management
Security auditing
System certification
Accreditation
Security policy
Leadership
Relationship management
Communication skills
Problem-solving
Strategic planning
Information protection
Business continuity management
Incident response
Stakeholder management

Job Description

 

Location
ESTEC, Noordwijk, Netherlands, or ESA Headquarters, Paris, France, or ESRIN, Frascati, Italy

Description

The ESA Cyber Security and INFOSEC Manager is in the ESO Corporate Security Assurance Management Office, ESA Security Office, Directorate of Resources and Services.


Reporting to the Head of the ESO Corporate Security Assurance Management Office, you will be responsible for leading all activities related to the cyber security assurance of ESA corporate and directorate systems in accordance with the requirements of the ESA Security Directives. You will, in addition, be responsible for the coordination of a dedicated team supporting cyber security, system certification and accreditation activities. You will carry out your duties in coordination with the relevant representatives of the various ESA directorates, and in synergy with the lnfosec Panel Member State representatives.

Duties

The ESA Cyber Security and INFOSEC Manager's tasks and responsibilities will include:

  • the coordination and management of all ESA Corporate and Directorate Cyber Security Audits;
  • the regular review and updating of the ESA Cyber Security Policy;
  • supervising correct ESA-wide implementation of the ESA Security Regulations and Directives in the domains of communications and information systems and security accreditation and certification policy and procedures;
  • ensuring the correct ESA-wide implementation of the Information Protection Policy and Directive;
  • supporting activities to be presented before the ESA Member State lnfosec Panel and before the Industrial Security Panel.


Your duties will be performed coordinating a dedicated team within ESO and with the support of specialised industry.

 

In particular:

  • managing the future Cyber Ramp-Up Security Assurance programme;
  • maintaining and executing a programme of cyber security governance audits and technical assessments for corporate and directorate systems in line with a Council-approved ESA Security Master Plan;
  • supporting the delivery of operational and strategic level cyber threat landscape and intelligence reports;
  • management and execution of lnfosec certification and accreditation activities for unclassified and classified networks, systems and applications at corporate and directorate level;
  • independently evaluating security dossiers and drafting formal certification and accreditation statements for approval by the ESA Security Accreditation Authority;
  • defining and maintaining security policy and process guidelines in support of information protection, certification and accreditation processes and baseline security assurance specifications in response to an evolving cyber security threat landscape;
  • supporting corporate and directorate programme and system security risk assessments and delivering risk appraisal recommendations for approval by the ESA Security Accreditation Authority;
  • supporting, in full coordination with CSOC Operations and ESACERT, cyber incident notification, containment, eradication, recovery, remediation and reporting activities;
  • delivering security training programmes, briefings and awareness sessions in the domains of INFOSEC (COMSEC, ITSEC, CYBERSEC), information protection, security risk and business continuity management;
  • supporting the establishment, evolution and continuous improvement of an ESA-wide Cyber Security Maturity Model programme;
  • supporting the definition of classified procurement packages including Programme Security Instructions and Security Classification Guides.


You will also be responsible for identifying, assessing, managing and reporting the health and safety risks in your area of responsibility.

Technical competencies

In-depth knowledge of high-security assurance requirements for classified systems and programmes
Extensive experience as a security certifier or accreditor for complex systems
Knowledge of ESA and EU accreditation processes
Knowledge and application experience of cyber security and risk management standards and frameworks
Substantial experience in cyber security policy and system security engineering
Experience in conducting cyber security audits

Behavioural competencies

Result Orientation
Operational Efficiency
Fostering Cooperation
Relationship Management
Continuous Improvement
Forward Thinking


For more information, please refer to the ESA Core Behavioural Competencies guidebook 

Education and professional experience

A master's in engineering, computer science, or cyber security is required for this post together with, in principle, 4 years of relevant professional experience. Alternatively, candidates with a bachelor's degree, complemented by an additional four (4) years of relevant professional experience may be considered.

Additional requirements

  • The potential to manage individuals or a team of experts;
  • The ability to organise their activities and ensure a motivating work environment;
  • Strong leadership capabilities, with proven relationship management and communication skills;
  • The ability to drive your team's performance, developing your people by encouraging learning, delegating responsibility and giving regular and constructive feedback;
  • Strong problem-solving skills to deal with day-to-day operational challenges, together with demonstrated planning and organisational skills;
  • Strong result orientation with the ability to set priorities and present practical solutions both orally and in writing;
  • The ability to manage challenging situations proactively and constructively and to be customer-focused.
  • People management experience is an asset, as is international experience, i.e. outside your home country, as well as experience in diverse functional areas relevant to ESA activities.

 

  • Excellent organisational and stakeholder management skills;
  • Willingness to travel;
  • International experience including interfacing with international and intergovernmental organisations’ security frameworks or national security authorities;
  • Professional certifications in cyber security would be an asset.

Diversity, Equity and Inclusiveness 
ESA is an equal opportunity employer, committed to achieving diversity within the workforce and creating an inclusive working environment. We therefore welcome applications from all qualified candidates irrespective of gender, sexual orientation, ethnicity, religious beliefs, age, disability or other characteristics. 

At the Agency we value diversity, and we welcome people with disabilities. Whenever possible, we seek to accommodate individuals with disabilities by providing the necessary support at the workplace. The Human Resources Department can also provide assistance during the recruitment process. If you would like to discuss this further, please contact us via email at [email protected].
 
Important Information and Disclaimer
In principle, recruitment will be within the advertised grade band (A2-A4). However, if the selected candidate has less than four years of relevant professional experience following the completion of the master’s degree, the position may be filled at A1 level.

Applicants must be eligible to access information, technology, and hardware which is subject to European or US export control and sanctions regulations & eligible to acquire the security clearance by their national security administrations.

During the recruitment process, the Agency may request applicants to undergo selection tests. Additionally, successful candidates will need to undergo basic screening before appointment, which will be conducted by an external background screening service, in compliance with the European Space Agency's security procedures.

Note that ESA is in the process of transitioning to a Matrix setup, which could lead to organisational changes affecting this position.

The information published on ESA’s careers website regarding working conditions is correct at the time of publication. It is not intended to be exhaustive and may not address all questions you would have. 

 

Nationality and Languages 
Please note that applications are only considered from nationals of one of the following States: Austria, Belgium, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Luxembourg, the Netherlands, Norway, Poland, Portugal, Romania, Slovenia, Spain, Sweden, Switzerland, the United Kingdom and Canada, Cyprus, Latvia, Lithuania and Slovakia. 

According to the ESA Convention, staff shall be recruited on the basis of their qualifications, taking into account an adequate distribution of posts among nationals of the Member States.

The working languages of the Agency are English and French. A good knowledge of one of these is required. Knowledge of another Member State language would be an asset.  

Core Responsibilities

The manager will lead cyber security assurance activities, including audits, policy updates, and system certification for ESA corporate and directorate systems. They will coordinate a dedicated team and interface with Member State representatives to ensure compliance with security directives and threat landscape requirements.

Requirements

A master's degree in engineering, computer science, or cyber security is required, along with at least four years of relevant professional experience. Candidates must possess strong leadership, communication, and problem-solving skills, and be eligible for security clearance.

Benefits

  • Professional development
  • Inclusive working environment
  • Support for individuals with disabilities

About ESA

Industry: Space Research and Technology

Company size: 1,001-5,000 employees

We are the European Space Agency. Our mission is the peaceful exploration and use of space for the benefit of everyone. We watch over Earth, develop and launch inspiring space projects, train astronauts and push the boundaries of science and technology, seeking answers to the big questions about the Universe. We are scientists, engineers and business professionals from all over Europe working together in a diverse and multinational environment. We are dedicated to united space in Europe and united Europe in space.

Added Today