04 ago
|
Hispasat
|
Madrid
ppDefinition, implementation and oversight of the Information Security Management System (ISMS) and the security measures of the IRIS² programme, in line with the security requirements set out in: /p ul liEU and ESA security policies /li lithe concession contract, /li liEUSPA security accreditation standards /li liInternational reference frameworks (ISO/IEC 27000 and 31000 series, NIST SP 800-53, CIS CSC, ISO 22301, NIST SSDF). This assessment must cover the entire multi-tier supply chain of the SpaceRISE consortium. /li liThe specific requirements defined in the project documentation /li /ul pCoordination and oversight of the management and protection of the project's classified information, in accordance with current regulations and legislation. /p pDefinition and oversight of a security control system, with particular attention to the security requirements defined for the programme. /p h3Main Responsibilities /h3 ul liEnsure compliance with legal and regulatory safety requirements associated with the program. /li liImplement and maintain the Security Management System for the IRIS² programme, in accordance with the requirements of the concession contract and the instructions of the European Commission, ESA and EUSPA. /li liDevelop security policies and procedures, including the creation and continuous update of security guidelines, guides and manuals. /li liCoordinate the integration of protective measures (encryption, access control, alert monitoring) and oversee vulnerability remediation. /li liEstablish the organization's priorities, limits, risk tolerances, and assumptions, and use them to support risk management decisions (both internal and supply chain-related). /li liDevelop and oversee the operational risk matrix for the Program and its supply chain; identify and document internal and external threats. Identify strategies and plans to mitigate them. /li liOversee operational resilience and ensure business continuity, reducing security incidents and minimizing disruptions.
/li liDevelop and coordinate the necessary business continuity plans, establishing resilience requirements for all operating states (under duress/attack, during recovery, normal operations). /li liOversight of technical plans, design and coordination of incident response protocols, and ensuring compliance with NIS2 regulatory guidelines within the program. /li liOversee audits, assess the impact of potential security breaches and define contingency plans. /li liCoordinate with other areas of the organisation on security/cybersecurity matters (SOC, etc.). /li liOversight of the management of classified information associated with the programme. /li liEnsure compliance with security requirements throughout the multi-tier supply chain of the SpaceRISE consortium: prime contractors, subcontractors and suppliers. /li liCoordinate with stakeholders and participate in projects to implement security measures, including coordination with programme stakeholders. /li /ul h3Academic Qualifications /h3 pBachelor of Industrial Engineering, Computer Science, Information Systems or an equivalent technical discipline. A specialisation in cybersecurity or European space law will be an advantage. /p h3Professional Certifications /h3 ul liISO/IEC 27001 ISMS Lead Auditor /li liSpecialist in the implementation of the National Security Scheme /li liPersonal security clearance (Spain) /li /ul h3Other certifications /h3 ul liCISSP (Certified Information Systems Security Professional) /li liCISM (Certified Information Security Manager) /li liCISA (Certified Information Systems Auditor) /li liCCSP / Cloud Security Specialty (AWS, Azure)
/li liCEH / OSCP / CompTIA Security+ /li /ul h3Professional Experience /h3 ul liA minimum of 4 to 6 years’ experience in the implementation and maintenance of security management systems, preferably in space programmes, government satellite communications or critical telecommunications infrastructure. /li liPractical expertise in the following frameworks: the ISO/IEC 27000 series, ISO/IEC 31000, NIST SP 800-53, CIS CSC, ISO 22301, NIST SSDF, OWASP and SAFECode. /li liExperience in managing classified information /li liKnowledge of the multi-tier supply chain in EU programmes (public procurement, satellite operators, satellite manufacturers, ground segment suppliers, technology subcontractors). /li /ul h3Skills /h3 ul liPlanning and execution of security management systems /li liSecurity maturity assessment (NIST CSF, ISO 27001, ISO 22301, NIST SP 800-53, NIST SSDF). /li liCollaborating in secure‑by‑design security architectures in space and satcom systems. /li liManagement of the multi-tier supply chain in European space programmes (SpaceRISE and the New Space ecosystem). /li liCompliance assessment of the EU regulatory framework applicable to critical government satcom infrastructure (NIS2, DORA, EU Secret, Regulation 2023/588). /li liIndependent judgement and integrity — ability to act with complete impartiality vis‑to‑vis the SpaceRISE/ESA programme management authorities. /li liEffective communication with technical (systems engineers, cybersecurity) and non-technical (European Commission, EUSPA, management boards) stakeholders. /li liLeadership of multidisciplinary teams and coordination of auditors across a pan-European supply chain. /li /ul pAt Hispasat we promote equal opportunities and an inclusive environment. All our selection processes are based on objective criteria, without distinction of gender, age, origin, sexual orientation, disability or other personal or social conditions. We value diversity as a driver of innovation and growth. /p /p #J-18808-Ljbffr
📌 Senior Security Management- I (Madrid)
🏢 Hispasat
📍 Madrid