Functiebeschrijving
X
Project System Security Officer
Job Requisition ID: 20696
Date Posted: 14 July 2026
Closing Date: 16 August 2026 23:59 CET/CEST
Publication: Internal & External
Type of Appointment : 4 years, extendable to indefinite
Directorate: Technology, Engineering and Quality
Workplace:
Noordwijk, NL
Location
ESTEC, Noordwijk, Netherlands
Description
Project/System Security Officer (PSSO) in the System Security Section (TEC-SES), End-to-End Systems Division, Systems Department, Directorate of Technology, Engineering and Quality.
The System Security Section is responsible for the end-to-end system security engineering of the Agency's missions, projects and activities in the space, ground and user segments and communication links, at system, subsystem, element and equipment level. It covers the missions from study phase to the definition of requirements, design, development, security integration/verification, and security service preparation, across the full stack, from the physical to the application layer. The System Security Section provides functional support to ESA missions and projects in the area of end-to-end security engineering and cyber security. To serve these functions, it also defines and carries out the associated technology research and development (R&D) and studies.
In this role, you will support the Directorate of Technology, Engineering and Quality, or projects and systems as a Project/System Security Officer (PSSO).
Duties
As a Project/System Security Officer (PSSO) you will be responsible for the design and successful implementation of all security measures designed as part of the overall system(s) you will be assigned to. The tasks to be accomplished will be defined and supervised by the ISO (Information Security Officer). Specifically, your tasks and responsibilities will include the following:
• Create and implement comprehensive security policies, procedures and access control protocols in compliance with the ESA Security Framework;
• Ensure that the entire corporate information system and all the assets for which the PSSO is responsible are secured, managed and accounted for in accordance with the ESA Security Directives;
• Specify the security standards and practices to be adhered to by the supplier of the system;
• Proactively identify, analyse and mitigate security threats to the infrastructure;
• Contribute to the definition, analyses and consolidation of system security requirements;
• Conduct security risk assessments and support security risk management by proposing suitable security mitigations and countermeasures;
• Produce or update as needed the security operating procedures (SECOPS);
• Coordinate vulnerability assessment/penetration testing on the infrastructure under your responsibility, and ensure required mitigations are put in place;
• Contribute to the authoring of the Information Security Management Plan;
• Provide support to the information security and cyber security activities related to the infrastructure under your responsibility, as needed;
• Monitor network activity for threats and manage the response, investigation and reporting of security breaches;
• Ensure compliance with data protection laws and industry regulations (e.g., ISO 27001), and perform regular security audits;
• Educate staff on security awareness, including how to recognise cyberattacks and follow security procedures;
• Collaborate with IT and management to design, implement and maintain required security tools, as well as disaster recovery plans;
• Collaborate with technical support, IT and management to scope, design, implement and support the certification/accreditation process (when applicable), in coordination with the ESA accreditation authority;
• Collaborate with the wider pool of PSSOs, ISOs and security officers on new security governance activities, cross-directorate processes, implementations, improvements and lessons learned;
• Maintain security-related tools and systems as well as their disaster and recovery plans;
• When needed, report to executives regarding the security posture and risk levels.
Technical competencies
Expertise in network security protocols for IT enterprise systems
Expertise in security controls and cyber security hardening for protecting IT infrastructure (access controls, devices such as firewalls, operating systems hardening, etc.), including cloud environments and security monitoring
Proven experience in IT security implementations, risk and vulnerability management, and compliance
Knowledge of applied crypto
Behavioural competencies
Result Orientation
Operational Efficiency
Fostering Cooperation
Relationship Management
Continuous Improvement
Forward Thinking
Education and professional experience
A master's degree in Computer Science or Cybersecurity or relevant engineering discipline is required for this post together with at least 5 years of relevant professional experience.