Security Management

HISPASAT S.A.
Madrid, Spain
3 days ago
Apply on www.adzuna.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
4 years minimum
Working hours
Regular working hours
Languages
English, Spanish
Job source

Tech stack

Cloud Computing Security CompTIA Security+ Cyber Security Information Systems Open Web Application Security Software Vulnerability Management Information Security Management System Information Technology SAP Ariba CIS Benchmarks

Job description

Hispasat, as part of the SpaceRISE consortium, is responsible for the technical implementation and ensuring the success of the IRIS² project, leveraging its extensive experience in satellite communications. This collaboration is essential to provide secure and reliable high-performance communication solutions to the European Union and its member states. To be part of this project, we are looking for Security Management (SM). The responsibilities of the position are as follows: Responsibilities

  • Define, implement and oversee the Information Security Management System and the comprehensive security measures required for the IRIS² programme.
  • Ensure alignment with EU and ESA security policies, the Concession Agreement, EUSPA security-accreditation standards, applicable project documentation and international frameworks including ISO/IEC 27000 and 31000, NIST SP 800-53, CIS Controls, ISO 22301 and NIST SSDF.
  • Coordinate and oversee the management and protection of classified programme information in accordance with applicable legislation and regulations.
  • Define and oversee the programme security-control system, with particular attention to the security requirements established for IRIS².
  • Ensure compliance with the legal and regulatory security requirements associated with the programme and with instructions from the European Commission, ESA and EUSPA.
  • Develop and maintain security policies, procedures, guidelines, secure-installation guides and manuals.
  • Coordinate the integration of protection measures, including encryption, access control and alert monitoring, and oversee vulnerability remediation.
  • Develop and oversee the programme and supply-chain security-risk matrix, identify internal and external threats, and define and monitor mitigation strategies and plans.
  • Establish organisational priorities, limits, risk tolerances and assumptions to support internal and supply-chain risk-management decisions.
  • Oversee operational resilience and business continuity and coordinate continuity plans for normal operations, operations under attack and recovery scenarios.
  • Oversee technical security plans and the design and coordination of incident-response protocols, ensuring compliance with NIS2 and the programme control framework.
  • Oversee audits, assess the impact of potential security breaches and define contingency plans.
  • Coordinate security and cybersecurity activities with other organisational areas, including the Security Operations Centre.
  • Ensure compliance with security requirements throughout the SpaceRISE consortium’s multi-tier supply chain, including prime contractors, subcontractors and suppliers.
  • Coordinate with programme stakeholders and participate in projects implementing security measures.

Requirements

  • Bachelor’s Degree in Industrial Engineering, Computer Science, Information Systems or an equivalent technical discipline; specialisation in cybersecurity or European space law is considered an asset.
  • 4 to 6 years of experience in the implementation and maintenance of security-management systems, preferably in space programmes, governmental satellite communications or critical telecommunications infrastructure.
  • ISO/IEC 27001 ISMS Lead Auditor certification is required.
  • Specialist certification in implementation of the Spanish National Security Scheme is required.
  • CISSP or CISM certification is highly valued; CISA, CCSP, Cloud Security, CEH, OSCP or CompTIA Security+ certifications are considered assets.
  • Practical expertise in ISO/IEC 27000, ISO/IEC 31000, NIST SP 800-53, CIS Controls, ISO 22301, NIST SSDF, OWASP and SAFECode.
  • Experience managing classified information.
  • Knowledge of multi-tier supply chains in European Union programmes, including public procurement, satellite operators, satellite manufacturers, Ground Segment suppliers and technology subcontractors.
  • Experience assessing security maturity and collaborating on secure-by-design architectures for space and satellite-communications systems.
  • Knowledge of the EU regulatory framework applicable to critical governmental satellite-communications infrastructure, including NIS2, DORA, EU Secret requirements and Regulation (EU) 2023/588.
  • Independent judgement, integrity and the ability to act impartially in relation to programme-management authorities.
  • Strong communication and leadership skills and experience coordinating multidisciplinary teams, auditors and technical and non-technical stakeholders across a pan-European supply chain.
  • Nationality of an EU Member State and willingness to undergo an EU Secret clearance process.
  • Fluency in English, both written and spoken; any other European language is considered an asset.

About the company

Volver a la última búsqueda Trabajos ) Security Management- IRIS2 ( volver a la última búsqueda Recibir ofertas similares por correo electrónico No gracias, llévame a la oferta de empleo Al crear una alerta, aceptas nuestros Términos y condiciones y Política de privacidad, y el uso de cookies. Inscribirse en esta oferta

Profesiones

  • Técnico
  • Recepciónista
  • Administrador
  • Ventas
  • Enfermero

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:00 min

Exploring defensibility and data sovereignty in space technology

Frank Seehaus Frank Seehaus +3 · World Congress 2026 Europe

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all