Sr. Cyber Assurance Analyst, Data Centers

SpaceX

Memphis (TN)

On-site

USD 120,000 - 160,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SpaceX is seeking a Senior Cyber Assurance Analyst for our data centers. You will own and scale cyber assurance across ISO 27001, ISO 42001, and SOC 2, driving evidence collection, remediation, and audit readiness across a multi-site portfolio.

You will partner with engineering and operations teams to implement controls in production environments, while translating framework requirements into practical actions and reporting to leadership.

Qualifications

  • 5+ years in cybersecurity compliance, audits or security roles.
  • 5+ years in control testing, policy development, audits, or risk management.
  • Strong ability to translate frameworks (ISO27001/ISO42001/SOC 2) into actionable controls.

Responsibilities

  • Own and execute data center ISO27001, ISO42001 and SOC 2 compliance programs (Type I/II).
  • Build and maintain audit-ready evidence packages for security controls.
  • Collaborate with engineers to ensure controls operate as designed in production.
  • Coordinate internal and external audits; serve as primary liaison to auditors.
  • Perform risk assessments of data center systems and drive remediation with owners.
  • Develop and improve information security policies, standards and procedures.
  • Improve evidence pipelines and tooling to scale audit readiness across sites.
  • Stay updated on evolving ISO SOC expectations for data centers and AI environments.
  • Mentor teammates and contribute to their development.

Skills

Cybersecurity compliance
Controls testing
Audit coordination
Security risk management

Education

Leadership certifications (CISA/CISM/CISSP/CRISC) or ISO 27001 Lead Implementer/Auditor

Job description

SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal ofenabling human life on Mars.

SR. CYBER ASSURANCE ANALYST, DATA CENTERS

Cyber Assurance is the practice of providing confidence that systems, products, and processes meet security, regulatory, and compliance obligations. It bridges governance with technical execution — validating that controls are in place, risks are managed, and requirements are met for both internal and customer-facing systems.

As a teammate on the Information Assurance team, you will own and scale cyber assurance for SpaceX data centers with a primary focus on ISO/IEC 27001, ISO/IEC 42001, and SOC 2. You will operate from an information security perspective: designing and validating controls, collecting and reviewing technical and operational evidence, driving remediation, and keeping the data center portfolio audit-ready across sites. You will partner closely with engineers and cross-functional operators so controls are implemented in the environment - not only documented after the fact.

The ideal candidate lives at the intersection of security, compliance, and critical infrastructure. You are comfortable translating ISO 27001, ISO 42001, and SOC 2 Trust Services Criteria into concrete control narratives; digging into access logs, configurations, and monitoring evidence; and explaining framework obligations to non-security partners. You are firm when it matters, flexible when alternative controls still meet the objective, and effective at running concurrent audit and remediation workstreams across a multi-site data center footprint.

RESPONSIBILITIES:

  • Own and execute information security compliance and certification for the data center portfolio across ISO/IEC 27001, ISO/IEC 42001, and SOC 2 (Type I/Type II), including control mapping, gap assessment, evidence collection, testing support, and remediation tracking.
  • Build and maintain audit-ready evidence packages for data center information security controls - including logical and physical access control, logging and monitoring, change management, vulnerability management, media handling, and availability-related security controls - suitable for external assessors.
  • Partner with engineering and system owners to gather and validate technical evidence (configurations, logs, designs, operational procedures) and to confirm controls operate as designed in production data center environments.
  • Plan, coordinate, and support internal and external audits and assessments for owned and operated data centers; act as a primary information security liaison to auditors for ISO 27001, ISO 42001, and SOC 2 scopes that include data center operations.
  • Perform information security and compliance risk assessments of data center systems, networks, and supporting processes; identify deviations from policy, standards, or framework requirements; advise on remediation; and drive timely closure with accountable owners.
  • Develop, maintain, and continuously improve information security policies, standards, procedures, and control documentation that support the data center ISMS / AI management system / SOC 2 control environment.
  • Identify and drive assurance efficiency through better evidence pipelines, tooling integration, reuse of control testing, and process improvement across sites so audit readiness scales with the portfolio rather than relying on point-in-time scrambles.
  • Maintain an up-to-date understanding of emerging information security risks, changes to ISO 27001 / ISO 42001 / SOC 2 expectations for data center and AI-enabled environments, and new assurance techniques; propose pragmatic, business-enabling actions.
  • Mentor fellow teammates and take an active role in their development.

BASIC QUALIFICATIONS:

  • High school diploma or equivalency certificate.
  • 5+ years of experience in cybersecurity compliance, audit or technical security roles with strong knowledge in security compliance frameworks.
  • 5+ years of experience with control testing, security standards/policy development, security audits, or security risk management.

PREFERRED SKILLS AND EXPERIENCE:

  • Experience liaising with Facility Operations, Physical Security, and Environmental, Health, and Safety (EHS) teams (including HVAC, fire detection/suppression, and related site systems) to obtain and validate information security-relevant evidence for ISO 27001, ISO 42001, and SOC 2 - while keeping the assurance focus on information security outcomes rather than facilities ownership.
  • Hands-on experience implementing or operating controls against ISO/IEC 27001 & 420001 and/or SOC 2 or equivalent industry certifications - including evidence collection and audit support.
  • Working knowledge of AI management systems and how AI-related controls intersect with data center and infrastructure assurance scopes.
  • Demonstrated ability to evaluate control objectives against enterprise grade IT, network, and infrastructure configurations and to work with technical teams on remediation.
  • Familiarity with data center information security control themes commonly in scope for ISO 27001 Annex A and SOC 2 (e.g., physical access and visitor management as security controls, environmental monitoring as availability/security evidence, secure media handling, and continuity interfaces) from an assurance and evidence perspective.
  • Ability to interpret configurations, logs, and system/network designs for compliance implications; experience with security tooling such as vulnerability scanners, SIEM, and configuration baseline checks (e.g., CIS Benchmarks).
  • Direct experience supporting external ISO 27001 certification audits and/or SOC 2 examinations for infrastructure or data center scopes.
  • Experience with GRC or continuous compliance platforms and with improving evidence collection through automation or process redesign.
  • Strong communication skills across organizational levels; able to explain framework requirements and risk tradeoffs to engineers, operators, and leadership in plain language.
  • Project and program management experience delivering concurrent audit and remediation workstreams in highly fluid environments.
  • Professional certifications such as CISA, CISM, CISSP, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent.

ADDITIONAL REQUIREMENTS:

  • This position is based in Memphis, TN. This role requires you to be onsite; remote/hybrid work will not be considered.
  • Must be willing to travel (<25%) domestically (and internationally as needed) in support of data center audits and other assurance activities.
  • Must be willing to work extended hours and/or weekends as needed to support audit windows and critical remediation.

ITAR REQUIREMENTS:

  • To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.

SpaceX is an Equal Opportunity Employer; employment with SpaceX is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.

Applicants wishing to view a copy of SpaceX's Affiant Action Plan for veterans and individuals with disabilities, or applicants requiring reasonable accommodation to the application/interview process should reach out to EEOCompliance@spacex.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Cyber Assurance Analyst, Data Centers
Sr. Cyber Assurance Analyst, Data Centers

SPACE EXPLORATION TECHNOLOGIES CORP • Memphis (TN), Northern (KY)

Hybrid
USD 120,000 - 180,000
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

InvestedintheMission • Hawthorne (CA)

On-site
USD 130,000 - 195,000
Stock options
Long-term incentives
Medical, vision, dental coverage
+5
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

SpaceX • Redmond (WA)

On-site
USD 130,000 - 200,000
Stock options
Medical, vision & dental
401(k) plan
+4
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

SPACE EXPLORATION TECHNOLOGIES CORP • Hawthorne (CA)

On-site
USD 130,000 - 195,000
Medical, Vision, Dental coverage
401(k) retirement plan
Paid parental leave
+2
Sr. Cyber Assurance Analyst, Starlink
Sr. Cyber Assurance Analyst, Starlink

SpaceX • Hawthorne (CA)

On-site
USD 130,000 - 180,000
Medical, vision, and dental coverage
401(k) retirement plan
Paid parental leave
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

SpaceX • Union Hill-Novelty Hill (WA)

On-site
USD 130,000 - 200,000
Company shuttles
Medical, vision, dental coverage
401(k) retirement plan
+1
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

InvestedintheMission • Redmond (WA)

On-site
USD 130,000 - 200,000
Medical coverage
Vision coverage
Dental coverage
+2
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

SPACE EXPLORATION TECHNOLOGIES CORP • Redmond (WA)

On-site
USD 130,000 - 200,000
Stock options
Long-term incentives
Employee stock purchase plan
+4
Sr. Cyber Assurance Analyst, Starlink
Sr. Cyber Assurance Analyst, Starlink

SPACE EXPLORATION TECHNOLOGIES CORP • Hawthorne (CA)

On-site
USD 130,000 - 180,000
Comprehensive medical, vision, and dental coverage
401(k) retirement plan
Paid parental leave
+1
Sr. Cyber Assurance Analyst, Finance
Sr. Cyber Assurance Analyst, Finance

SpaceX • Hawthorne (CA)

On-site
USD 130,000 - 195,000
Company stock
401(k) plan
Medical, vision, dental
+2