04 ago
|
Satlantis
|
Bilbao
ppAt SATLANTIS, we design advanced space technologies to tackle general challenges from above. Our satellites are conceived, designed, and built to deliver reliable, high-performance Earth observation data in demanding orbital environments. /ppAs a bCybersecurity GRC Analyst /b, you will help strengthen the governance, risk management, and compliance foundations that protect our technology, information, and business operations. Working closely with IT, Cybersecurity, business stakeholders, suppliers, and external partners, you will contribute to ensuring that security requirements are effectively implemented, monitored, evidenced, and continuously improved. /ph3bWhat’s in it for you /b /h3ullibReal impact on cybersecurity governance /b: Your work will directly contribute to strengthening the security and resilience of a growing space technology organization. /lilibProfessional growth in a cutting-edge sector: /b Develop your expertise in cybersecurity governance, risk management, compliance, and information security within the space industry. /lilibFlexible working hours: /bBecause balance and trust are part of how we work. /lilibYoung, dynamic environment /b: Join a proactive team where autonomy, innovation, and collaboration drive our daily routine. /lilibPrivate health insurance: /b Your wellbeing comes first, with comprehensive coverage. /lilibCampus perks: /b Discounts at gym and restaurants on the UPV/EHU campus, plus fresh fruit, great coffee, and a motivating work atmosphere. /li /ulh3bYour mission /b /h3pYour mission will be to support the effective governance, risk management, and compliance of SATLANTIS’ cybersecurity and information security environment. /ppThrough structured coordination, monitoring, documentation, and continuous improvement, you will help ensure that security requirements are implemented, risks are tracked, audit commitments are addressed,
and cybersecurity performance remains visible to decision-makers. /ppYour main responsibilities will be: /pullibSupport the maintenance and continuous improvement of ENS High compliance and the ISMS /b, including the statement of applicability, security bpolicies, standards, procedures, records, and control evidence. /b /lilibSupport the oversight of the external SOC service and vulnerability management process, /bmonitoring service performance, escalations, asset coverage, risk classification, remediation deadlines, and outstanding actions. /lilibCoordinate internal and external audits, /bmanaging audit evidence and maintaining the register of findings, observations, and non-conformities, together with their corresponding corrective action plans and closure status. /lilibCoordinate the maintenance and testing of IT continuity and disaster recovery plans /bwith the relevant service and business owners. /lilibSupport /bsupplier security assessments, contractual security reviews, supplier SLA monitoring, remediation activities, and customer cybersecurity questionnaires and evidence requests. /lilibConduct and maintain technology risk assessments /b, propose treatment actions, and monitor their implementation, while supporting the application and monitoring of the information classification scheme. /lilibSupport incident notification and regulatory deadline tracking related to ENS, NIS2, and GDPR. /b /lilibPrepare periodic cybersecurity governance, risk, and compliance dashboards and /breports for the Head of IT Cybersecurity.
/li /ulh3bWhat will set you up for success /b /h3ullibTechnical foundation: /bYou hold a Higher Vocational Qualification, University Degree, or equivalent professional experience in Cybersecurity, Information Technology, Telecommunications, Computer Science, Risk Management, Law with a technology specialization, or a related field. /lilibExperience and knowledge: /b /li /ululliulliBasic practical knowledge of security and compliance frameworks such as ENS, ISO 27001, NIS2, and GDPR. /liliExperience maintaining structured documentation, control evidence, risk registers, or audit records, together with a general technical understanding of IT infrastructure, networks, identity, endpoints, cloud services, and cybersecurity controls. /liliA working understanding of SOC operations, incident management, vulnerability management, and remediation processes will help you monitor performance, track actions, and challenge deviations when needed. /liliBasic understanding of technology risk assessment and supplier and supply-chain security assessment processes will help you contribute to managing cybersecurity risks across the organization. /li /ul /li /ulullibAutonomy and Teamwork /b: Ability to work independently and in a team. /lilibCommunication skills /b: Native or equivalent Spanish and technical English. /lilibPreferred skills: /bulliExperience participating in ENS or NIS2 implementation, maintenance, or audit activities. /liliFamiliarity with Microsoft 365 security and compliance technologies, including Entra ID, Intune, Defender, or Purview, and AWS. /li /ul /li /ulh3bReady to strengthen cybersecurity in the space industry? /b /h3pIf you’re excited about turning cybersecurity requirements into practical improvements and contributing to the security and resilience of space technologies, this is your chance. Apply now and join our mission at SATLANTIS. /p /p #J-18808-Ljbffr
📌 CYBERSECURITY GRC ANALYST (Bilbao)
🏢 Satlantis
📍 Bilbao