Senior Security Management- IRIS2

Hispasat

España

On-site

PHP 3,513,703 - 4,919,184

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hispasat is seeking a qualified individual to manage the Information Security Management System (ISMS) for the IRIS² programme in Romblon, España. The role will involve defining security policies, ensuring compliance with international security standards, and overseeing classified information management.

The ideal candidate will have at least 4 to 6 years of experience, a relevant degree, and certifications such as ISO/IEC 27001. Join us in promoting equal opportunities and innovation.

Qualifications

  • Bachelor's degree in a relevant technical discipline.
  • Specialization in cybersecurity or European space law is an advantage.
  • Recommended 4-6 years of experience in security management.

Responsibilities

  • Ensure compliance with safety requirements for the program.
  • Implement and maintain the Security Management System.
  • Develop security policies and procedures.

Skills

Planning and execution of security management systems
Security maturity assessment
Collaborating in secure-by-design security architectures
Management of the multi-tier supply chain
Compliance assessment of the EU regulatory framework
Independent judgement and integrity
Effective communication with technical and non-technical stakeholders
Leadership of multidisciplinary teams

Education

Bachelor of Industrial Engineering, Computer Science, Information Systems

Tools

ISO/IEC 27001 ISMS
ISO/IEC 27000 series
NIST SP 800-53
CIS CSC
ISO 22301
CISSP
CISM
CISA
CCSP
CEH

Job description

Definition, implementation and oversight of the Information Security Management System (ISMS) and the security measures of the IRIS² programme, in line with the security requirements set out in:

  • EU and ESA security policies
  • the concession contract
  • EUSPA security accreditation standards
  • International reference frameworks (ISO/IEC 27000 and 31000 series, NIST SP 800-53, CIS CSC, ISO 22301, NIST SSDF). This assessment must cover the entire multi-tier supply chain of the SpaceRISE consortium.
  • The specific requirements defined in the project documentation

Coordination and oversight of the management and protection of the project's classified information, in accordance with current regulations and legislation.

Definition and oversight of a security control system, with particular attention to the security requirements defined for the programme.

Main Responsibilities
  • Ensure compliance with legal and regulatory safety requirements associated with the program.
  • Implement and maintain the Security Management System for the IRIS² programme, in accordance with the requirements of the concession contract and the instructions of the European Commission, ESA and EUSPA.
  • Develop security policies and procedures, including the creation and continuous update of security guidelines, guides and manuals.
  • Coordinate the integration of protective measures (encryption, access control, alert monitoring) and oversee vulnerability remediation.
  • Establish the organization's priorities, limits, risk tolerances, and assumptions, and use them to support risk management decisions (both internal and supply chain-related).
  • Develop and oversee the operational risk matrix for the Program and its supply chain; identify and document internal and external threats. Identify strategies and plans to mitigate them.
  • Oversee operational resilience and ensure business continuity, reducing security incidents and minimizing disruptions.
  • Develop and coordinate the necessary business continuity plans, establishing resilience requirements for all operating states (under duress/attack, during recovery, normal operations).
  • Oversight of technical plans, design and coordination of incident response protocols, and ensuring compliance with NIS2 regulatory guidelines within the program.
  • Oversee audits, assess the impact of potential security breaches and define contingency plans.
  • Coordinate with other areas of the organisation on security/cybersecurity matters (SOC, etc.).
  • Oversee the management of classified information associated with the programme.
  • Ensure compliance with security requirements throughout the multi-tier supply chain of the SpaceRISE consortium: prime contractors, subcontractors and suppliers.
  • Coordinate with stakeholders and participate in projects to implement security measures, including coordination with programme stakeholders.
Academic Qualifications

Bachelor of Industrial Engineering, Computer Science, Information Systems or an equivalent technical discipline. A specialisation in cybersecurity or European space law will be an advantage.

Professional Certifications
  • ISO/IEC 27001 ISMS Lead Auditor
  • Specialist in the implementation of the National Security Scheme
  • Personal security clearance (Spain)
Other certifications
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CISA (Certified Information Systems Auditor)
  • CCSP / Cloud Security Specialty (AWS, Azure)
  • CEH / OSCP / CompTIA Security+
Professional Experience
  • A minimum of 4 to 6 years’ experience in the implementation and maintenance of security management systems, preferably in space programmes, government satellite communications or critical telecommunications infrastructure.
  • Practical expertise in the following frameworks: the ISO/IEC 27000 series, ISO/IEC 31000, NIST SP 800-53, CIS CSC, ISO 22301, NIST SSDF, OWASP and SAFECode.
  • Experience in managing classified information
  • Knowledge of the multi-tier supply chain in EU programmes (public procurement, satellite operators, satellite manufacturers, ground segment suppliers, technology subcontractors).
Skills
  • Planning and execution of security management systems
  • Security maturity assessment (NIST CSF, ISO 27001, ISO 22301, NIST SP 800-53, NIST SSDF).
  • Collaborating in secure-by-design security architectures in space and satcom systems.
  • Management of the multi-tier supply chain in European space programmes (SpaceRISE and the New Space ecosystem).
  • Compliance assessment of the EU regulatory framework applicable to critical government satcom infrastructure (NIS2, DORA, EU Secret, Regulation 2023/588).
  • Independent judgement and integrity — ability to act with complete impartiality vis‑a‑vis the SpaceRISE/ESA programme management authorities.
  • Effective communication with technical (systems engineers, cybersecurity) and non‑technical (European Commission, EUSPA, management boards) stakeholders.
  • Leadership of multidisciplinary teams and coordination of auditors across a pan‑European supply chain.
Equal Opportunity

At Hispasat we promote equal opportunities and an inclusive environment. All our selection processes are based on objective criteria, without distinction of gender, age, origin, sexual orientation, disability or other personal or social conditions. We value diversity as a driver of innovation and growth.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Project Manager Low LEO - IRIS2
Project Manager Low LEO - IRIS2

Hispasat • España

On-site
PHP 5,941,000 - 8,319,000
Procurement Manager - IRIS2
Procurement Manager - IRIS2

Hispasat • España

On-site
PHP 6,392,000 - 8,523,000
ISMS Lead for Space Programme & Critical Infrastructure
ISMS Lead for Space Programme & Critical Infrastructure

Hispasat • España

On-site
PHP 3,513,000 - 4,920,000
Ground Technical Lead Manager - IRIS2
Ground Technical Lead Manager - IRIS2

Hispasat • España

On-site
PHP 5,513,000 - 6,892,000
Security Architect for ISMS
Security Architect for ISMS

Airbus • España

On-site
PHP 3,699,000 - 5,549,000
Flexible work shift
Attractive salary and bonus
Health insurance
+2
IVV Engineer (Ground Segment) - IRIS2
IVV Engineer (Ground Segment) - IRIS2

Hispasat • España

On-site
PHP 4,216,444 - 5,973,295
IVV Lead for Space Ground Systems
IVV Lead for Space Ground Systems

Hispasat • España

On-site
PHP 4,216,000 - 5,974,000
Sr. Security Analyst
Sr. Security Analyst

Concentrix • Manila

On-site
PHP 2,460,000 - 4,306,000
Senior Space Projects & Procurement Manager
Senior Space Projects & Procurement Manager

Hispasat • España

On-site
PHP 6,392,000 - 8,523,000
OT Cyber Security Consultant
OT Cyber Security Consultant

Integrity360 • España

On-site
PHP 3,164,000 - 4,923,000
Coaching and skill development
Annual external training options
Vibrant company culture