Jobs and Careers
EU

Project / System Security Officer (PSSO)

European Space Agency - ESA
Italyfull_timeVerifiedPosted 9 May 2025

About the role

<p> </p> <p><span><b>Location</b></span><br/> <span>ESRIN, Frascati, Italy</span>  </p> <h2><b>Description</b></h2> <p><b>Project/System Security Officer (PSSO) in the Space Transportation Security and Compliance Office, Infrastructure and Value Chain, Directorate of Space Transportation.</b><br/> The ESA Space Transportation (STS) mission is to provide and implement a <a href="http://www.esa.int/Enabling_Support/Space_Transportation/Space_Transportation_strategy">space transportation strategy</a> that gives institutional and commercial actors in ESA’s Member States an autonomous gateway to space.<br/> The STS programmes managed at ESA/ESRIN and at ESA/HQ-Daumesnil require the support of a PSSO who is responsible for the daily management of all IT and cyber-related security aspects. This position is currently based at ESA/ESRIN (Frascati), but could also be located at ESA/HQ (Paris), and is under the responsibility of the Head of the Space Transportation Security and Compliance Office.</p> <h2><b>Duties</b></h2> <p>Your tasks and responsibilities will include:</p> <p> </p> <ul> <li>Supervising and ensuring the security of the Directorate’s communication and information systems (CIS) at corporate and space project level;</li> <li>Implementing the security of the CIS in accordance with an information security management system based on a security risk assessment conducted throughout the project’s or programme’s lifetime, either directly by you or under your supervision and verification; </li> <li>Following up security risk management for programmes and projects; </li> <li>Defining, maintaining and ensuring the implementation of the system-specific security requirements statements (SSRS/SISRS) of the CIS and any interconnections with external CIS, at corporate and space project level, for endorsement by the ESA Security Accreditation Authority;</li> <li>Ensuring the acceptance tests for implemented CIS security measures are performed, and certifying the CIS installation and deployment; </li> <li>Specifying and documenting the system security operations procedures for approval by the ESA Security Accreditation Authority; </li> <li>Defining and proposing the Cyber Security Implementation Policy and supporting the implementation plan;</li> <li>Implementing, or verifying the correct implementation of, the relevant security operations procedures; </li> <li>Advising the relevant Configuration Control and Management Boards on the security implications of proposed changes to CIS software, hardware, firmware and/or operating procedures; </li> <li>Providing reports and recommendations for security improvements and lessons learned; </li> <li>Preparing the relevant data protection notification records in coordination with the ESA Data Protection Officer Service and following up the correct implementation of the recommendations provided;</li> <li>Reporting any security breaches, vulnerabilities or anomalies in accordance with the Security Directives and policy on security management;</li> <li>Taking any necessary action to contain security breaches in the event of a security incident concerning the CIS for which you are responsible;</li> <li>Participating in the Agency-wide network of PSSOs coordinated by the ESA INFOSEC Policy Officer;</li> <li>Participating as auditor or inspector in the ESA Security Office’s audits or inspections of CIS for which you are not responsible (only when requested);</li> <li>Acting as STS sub-registry registrar (or deputy registrar) for ESRIN Zone 5;</li> <li>Providing operational security support, as relevant, to the activities linked to the agreement regarding ESA’s assistance to Italy concerning space transportation and in-orbit servicing (known as the PNRR programme).</li> </ul> <h2><b>Technical competencies</b></h2> You must have at least 10 years of professional experience in the field.Knowledge of ESA Security Directives, ECSS standards, export control laws (ITAR and EAR) and GDPR would be an asset.Experience of security accreditation processes, compliance audits and certification frameworks for space programmes.In-depth knowledge of ESA space programmes such as Space Rider, Vega and Ariane (with proven experience of having supported space programmes in security-related matters).Professional qualifications/certification such as ISO 27001/22301/31000 Auditor, CISSP, CISM, CRISC or TOGAF would be highly beneficial.<h2><b>Behavioural competencies</b></h2> <p>Result Orientation<br/> Operational Efficiency<br/> Fostering Cooperation<br/> Relationship Management<br/> Continuous Improvement<br/> Forward Thinking</p> <p><br/> For more information, please refer to <u><a href="https://esamultimedia.esa.int/docs/careers/ESA_Competency_Framework.pdf" target="_blank">ESA Core Behavioural Competencies guidebook</a></u></p> <h2><b>Education</b></h2> <p>A master’s degree preferably in the IT engineering/cyber security domain.</p> <h2><b>Additional requirements</b></h2> <p>You will have to undergo a sec

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

European Space Agency - ESA

View company profile →