Cyber Security Engineer

Noordwijk, Netherlands  
negotiable Expired 1 year ago
This job has expired.

JOB DETAIL

Vacancy in the Directorate of Navigation.

ESA is an equal opportunity employer, committed to achieving diversity within the workforce and creating an inclusive working environment. We therefore welcome applications from all qualified candidates irrespective of gender, sexual orientation, ethnicity, beliefs, age, disability or other characteristics. Applications from women are encouraged.

This post is classified A2A4 on the Coordinated Organisations’ salary scale.

Location
ESTEC, Noordwijk, Netherlands

Description

Cyber Security Engineer in the Galileo G1 Cyber Security and Accreditation Unit in the Galileo G1 System Security Service, Galileo First Generation Project Office, Galileo and EGNOS Programme Department, Directorate of Navigation.

Duties

Reporting to the Head of Unit, your main tasks and responsibilities will include:

  • Managing the Ground Segment infrastructure contractor for cyber aspects, in particular ensuring proper implementation of the Galileo European Commission Cyber Security Requirements in the Ground Segment Infrastructure versions by defining Ground Segment cyber requirements including patching policy, hardening guideline, and applicable standards;
  • Assessing and processing the Cyber Requests for Waiver (RFWs) from the Ground Segment Infrastructure contractor, preparing higher level RFWs when needed in support of Galileo G1&G2 CCBs and Project/Programme Cyber Boards;
  • Following up and organising security audits, vulnerability assessments and penetration testing on the Ground Segment infrastructure versions;
  • Collecting and managing cyber vulnerability closure evidence to demonstrate that vulnerabilities identified in previous versions have been correctly mitigated/fixed for each new version of the Ground Segment infrastructure;
  • Reviewing and consolidating the Cyber Status of the Ground Segment Infrastructure versions and contributing to the overall Galileo infrastructure integrated report;
  • Contributing to segment version security accreditation milestones dossier providing cyber status reports, performing residual cyber vulnerability analysis, proposing mitigation, preparing correction reports and correction plans to the Galileo security accreditation authorities, SAP/SAB (Security Accreditation Panel / Security Accreditation Board);
  • Managing Ground Segment input related to cyber disaster recovery and contributing to the Galileo System infrastructure Cyber Disaster Recovery Plan;
  • Supporting the ESA Galileo Cyber Security Manager in the cyber decision process regarding the implementation of cyber corrections, mitigations, security monitoring and risk management.
  • Providing security design expertise to the Galileo G1&G2Project Office for the design and development of the G1&G2 system infrastructure in terms of security monitoring, network design, security treatment definition, vulnerability identification/correction, cyber countermeasures and operational procedure mitigation identification.

Duties may also include supporting other activities within your field of competence and the transfer of knowledge across the Agency

Technical competencies

Strong experience in cyber security management for large and complex systems
Experience in Cyber Vulnerability Assessment, Security Auditing and penetration testing
Demonstrated knowledge and experience in system security architecture
Knowledge and experience in security engineering and associated disciplines

Behavioural competencies

Result Orientation
Operational Efficiency
Fostering Cooperation
Relationship Management
Continuous Improvement
Forward Thinking

Education

A master’s degree in information systems is required for this post.

Additional requirements

The working languages of the Agency are English and French. A good knowledge of one of these is
required.

Knowledge of another Member State language would be an asset

Other information

For behavioural competencies expected from ESA staff in general, please refer to the ESA Competency Framework.

For further information please visit: Professionals, What we offer and FAQ

The working languages of the Agency are English and French. A good knowledge of one of these is required. Knowledge of another Member State language would be an asset.

Applicants must be eligible for security clearance by their national security administrations.

The Agency may require applicants to undergo selection tests.

At the Agency we value diversity and we welcome people with disabilities. Whenever possible, we seek to accommodate individuals with disabilities by providing the necessary support at the workplace. The Human Resources Department can also provide assistance during the recruitment process. If you would like to discuss this further please contact us email [email protected].


Please note that applications are only considered from nationals of one of the following States: Austria, Belgium, the Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Luxembourg, the Netherlands, Norway, Poland, Portugal, Romania, Spain, Sweden, Switzerland, the United Kingdom and Canada, Latvia, Lithuania, Slovakia and Slovenia.

According to the ESA Convention, the recruitment of staff must take into account an adequate distribution of posts among nationals of the ESA Member States*. When short-listing for an interview, priority will first be given to internal candidates and secondly to external candidates from under-represented Member States*.

In accordance with the European Space Agency’s security procedures and as part of the selection process, successful candidates will be required to undergo basic screening before appointment conducted by an external background screening service.

Recruitment will normally be at the first grade in the band (A2); however, if the candidate selected has little or no experience, the position may be filled at A1 level.

*Member States, Associate Members or Cooperating States.

Noordwijk, Netherlands

location

This job has expired.