Senior Security Management- IRIS2

Hispasat

Madrid

Presencial

EUR 90.000 - 130.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Hispasat is seeking a senior Information Security Manager to lead the ISMS for the IRIS² programme in Spain. You will define, implement and oversee security controls, ensuring compliance with EU, ESA, EUSPA, and international standards across the multi-tier SpaceRISE supply chain.

You will coordinate security policies, risk assessments and incident response, working with stakeholders across the organisation to protect classified information and maintain business continuity in a challenging space

Formación

  • 4–6 years in security management for space, government satellite comms or critical infrastructure.
  • Hands-on with ISO/IEC 27000 series, ISO 31000, NIST SP 800-53, CIS CSC, ISO 22301, NIST SSDF, OWASP.
  • Experience handling classified information and EU programme supply chains.

Responsabilidades

  • Define, implement and oversee the ISMS for the IRIS² programme.
  • Develop security policies, guidelines and incident response procedures.
  • Coordinate encryption, access control, monitoring and vulnerability remediation.
  • Oversee risk management, business continuity and resilience for all states.
  • Ensure compliance with NIS2 and related EU regulations across multi-tier supply chain.

Conocimientos

Security governance
Risk assessment
Supply chain mgmt
ISO 27001
NIST SP 800-53
NIS2 compliance
Auditing
Stakeholder comms
Leadership

Educación

Bachelor in Industrial Engineering
Computer Science background
Cybersecurity specialization

Descripción del empleo

Definition, implementation and oversight of the Information Security Management System (ISMS) and the security measures of the IRIS² programme, in line with the security requirements set out in:

  • EU and ESA security policies
  • the concession contract,
  • EUSPA security accreditation standards
  • International reference frameworks (ISO/IEC 27000 and 31000 series, NIST SP 800-53, CIS CSC, ISO 22301, NIST SSDF). This assessment must cover the entire multi-tier supply chain of the SpaceRISE consortium.
  • The specific requirements defined in the project documentation

Coordination and oversight of the management and protection of the project's classified information, in accordance with current regulations and legislation.

Definition and oversight of a security control system, with particular attention to the security requirements defined for the programme.

Main Responsibilities
  • Ensure compliance with legal and regulatory safety requirements associated with the program.
  • Implement and maintain the Security Management System for the IRIS² programme, in accordance with the requirements of the concession contract and the instructions of the European Commission, ESA and EUSPA.
  • Develop security policies and procedures, including the creation and continuous update of security guidelines, guides and manuals.
  • Coordinate the integration of protective measures (encryption, access control, alert monitoring) and oversee vulnerability remediation.
  • Establish the organization's priorities, limits, risk tolerances, and assumptions, and use them to support risk management decisions (both internal and supply chain-related).
  • Develop and oversee the operational risk matrix for the Program and its supply chain; identify and document internal and external threats. Identify strategies and plans to mitigate them.
  • Oversee operational resilience and ensure business continuity, reducing security incidents and minimizing disruptions.
  • Develop and coordinate the necessary business continuity plans, establishing resilience requirements for all operating states (under duress/attack, during recovery, normal operations).
  • Oversight of technical plans, design and coordination of incident response protocols, and ensuring compliance with NIS2 regulatory guidelines within the program.
  • Oversee audits, assess the impact of potential security breaches and define contingency plans.
  • Coordinate with other areas of the organisation on security/cybersecurity matters (SOC, etc.).
  • Oversight of the management of classified information associated with the programme.
  • Ensure compliance with security requirements throughout the multi-tier supply chain of the SpaceRISE consortium: prime contractors, subcontractors and suppliers.
  • Coordinate with stakeholders and participate in projects to implement security measures, including coordination with programme stakeholders.
Academic Qualifications

Bachelor of Industrial Engineering, Computer Science, Information Systems or an equivalent technical discipline. A specialisation in cybersecurity or European space law will be an advantage.

Professional Certifications
  • ISO/IEC 27001 ISMS Lead Auditor
  • Specialist in the implementation of the National Security Scheme
  • Personal security clearance (Spain)
Other certifications
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CISA (Certified Information Systems Auditor)
  • CCSP / Cloud Security Specialty (AWS, Azure)
  • CEH / OSCP / CompTIA Security+
Professional Experience
  • A minimum of 4 to 6 years’ experience in the implementation and maintenance of security management systems, preferably in space programmes, government satellite communications or critical telecommunications infrastructure.
  • Practical expertise in the following frameworks: the ISO/IEC 27000 series, ISO/IEC 31000, NIST SP 800-53, CIS CSC, ISO 22301, NIST SSDF, OWASP and SAFECode.
  • Experience in managing classified information
  • Knowledge of the multi-tier supply chain in EU programmes (public procurement, satellite operators, satellite manufacturers, ground segment suppliers, technology subcontractors).
Skills
  • Planning and execution of security management systems
  • Security maturity assessment (NIST CSF, ISO 27001, ISO 22301, NIST SP 800-53, NIST SSDF).
  • Collaborating in secure‑by‑design security architectures in space and satcom systems.
  • Management of the multi-tier supply chain in European space programmes (SpaceRISE and the New Space ecosystem).
  • Compliance assessment of the EU regulatory framework applicable to critical government satcom infrastructure (NIS2, DORA, EU Secret, Regulation 2023/588).
  • Independent judgement and integrity — ability to act with complete impartiality vis‑to‑vis the SpaceRISE/ESA programme management authorities.
  • Effective communication with technical (systems engineers, cybersecurity) and non-technical (European Commission, EUSPA, management boards) stakeholders.
  • Leadership of multidisciplinary teams and coordination of auditors across a pan-European supply chain.

At Hispasat we promote equal opportunities and an inclusive environment. All our selection processes are based on objective criteria, without distinction of gender, age, origin, sexual orientation, disability or other personal or social conditions. We value diversity as a driver of innovation and growth.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Security Management IRIS2
Security Management IRIS2

Hispasat • Arganda del Rey

Presencial
EUR 50.000 - 70.000
Senior Information Security Lead – Space Programme
Senior Information Security Lead – Space Programme

Hispasat • Madrid

Presencial
EUR 90.000 - 130.000
Product Assurance Engineer - IRIS2
Product Assurance Engineer - IRIS2

Hispasat • Arganda del Rey

Presencial
EUR 70.000 - 90.000
Secure Connectivity Low LEO Lead Ground Segment Engineer
Secure Connectivity Low LEO Lead Ground Segment Engineer

European Space Agency - ESA • Villanueva de la Cañada

Presencial
EUR 70.000 - 90.000
Security Architect for ISMS
Security Architect for ISMS

Airbus Defence and Space • Getafe

Híbrido
EUR 60.000 - 80.000
Flexible workshift
Competitive salary and bonus
Health insurance
+3
Security Engineer: Satellite Communications & Cybersecurity
Security Engineer: Satellite Communications & Cybersecurity

Hispasat • Arganda del Rey

Presencial
EUR 50.000 - 70.000
System Engineer - IRIS2
System Engineer - IRIS2

Hispasat • Arganda del Rey

Presencial
EUR 60.000 - 80.000
Senior Cyber security engineer - Spain or France
Senior Cyber security engineer - Spain or France

Cetra Base • España

Presencial
EUR 70.000 - 110.000
Permanent contract
Competitive salary
EU Space Network
IVV Manager
IVV Manager

Hispasat • Madrid

Presencial
EUR 60.000 - 90.000
GSMC Operations Support Engineer - Spain or France
GSMC Operations Support Engineer - Spain or France

Cetra Base • Madrid

Presencial
EUR 65.000 - 95.000