ESA Cyber Security and INFOSEC Manager

Job Requisition ID:  20879
Date Posted:  22 September 2026
Closing Date:  13 October 2026 23:59 CET/CEST
Publication Method:  Internal & External
Type of Appointment (learn more) 4 years, extendable to indefinite
Directorate:  Resources and Services
Workplace: 

Noordwijk, NL Paris, FR Frascati, IT

Grade Band:  A2 - A4

Location
ESTEC, Noordwijk, Netherlands, or ESA Headquarters, Paris, France, or ESRIN, Frascati, Italy

Description

The ESA Cyber Security and INFOSEC Manager is in the ESO Corporate Security Assurance Management Office, ESA Security Office, Directorate of Resources and Services.


Reporting to the Head of the ESO Corporate Security Assurance Management Office, you will be responsible for leading all activities related to the cyber security assurance of ESA corporate and directorate systems in accordance with the requirements of the ESA Security Directives. You will, in addition, be responsible for the coordination of a dedicated team supporting cyber security, system certification and accreditation activities. You will carry out your duties in coordination with the relevant representatives of the various ESA directorates, and in synergy with the lnfosec Panel Member State representatives.

Duties

The ESA Cyber Security and INFOSEC Manager's tasks and responsibilities will include:

  • the coordination and management of all ESA Corporate and Directorate Cyber Security Audits;
  • the regular review and updating of the ESA Cyber Security Policy;
  • supervising correct ESA-wide implementation of the ESA Security Regulations and Directives in the domains of communications and information systems and security accreditation and certification policy and procedures;
  • ensuring the correct ESA-wide implementation of the Information Protection Policy and Directive;
  • supporting activities to be presented before the ESA Member State lnfosec Panel and before the Industrial Security Panel.


Your duties will be performed coordinating a dedicated team within ESO and with the support of specialised industry.

In particular:

  • managing the future Cyber Ramp-Up Security Assurance programme;
  • maintaining and executing a programme of cyber security governance audits and technical assessments for corporate and directorate systems in line with a Council-approved ESA Security Master Plan;
  • supporting the delivery of operational and strategic level cyber threat landscape and intelligence reports;
  • management and execution of lnfosec certification and accreditation activities for unclassified and classified networks, systems and applications at corporate and directorate level;
  • independently evaluating security dossiers and drafting formal certification and accreditation statements for approval by the ESA Security Accreditation Authority;
  • defining and maintaining security policy and process guidelines in support of information protection, certification and accreditation processes and baseline security assurance specifications in response to an evolving cyber security threat landscape;
  • supporting corporate and directorate programme and system security risk assessments and delivering risk appraisal recommendations for approval by the ESA Security Accreditation Authority;
  • supporting, in full coordination with CSOC Operations and ESACERT, cyber incident notification, containment, eradication, recovery, remediation and reporting activities;
  • delivering security training programmes, briefings and awareness sessions in the domains of INFOSEC (COMSEC, ITSEC, CYBERSEC), information protection, security risk and business continuity management;
  • supporting the establishment, evolution and continuous improvement of an ESA-wide Cyber Security Maturity Model programme;
  • supporting the definition of classified procurement packages including Programme Security Instructions and Security Classification Guides.


You will also be responsible for identifying, assessing, managing and reporting the health and safety risks in your area of responsibility.

Technical competencies

In-depth knowledge of high-security assurance requirements for classified systems and programmes
Extensive experience as a security certifier or accreditor for complex systems
Knowledge of ESA and EU accreditation processes
Knowledge and application experience of cyber security and risk management standards and frameworks
Substantial experience in cyber security policy and system security engineering
Experience in conducting cyber security audits

Behavioural competencies

Result Orientation
Operational Efficiency
Fostering Cooperation
Relationship Management
Continuous Improvement
Forward Thinking


For more information, please refer to the ESA Core Behavioural Competencies guidebook 

Education and professional experience

A master's in engineering, computer science, or cyber security is required for this post together with, in principle, 4 years of relevant professional experience. Alternatively, candidates with a bachelor's degree, complemented by an additional four (4) years of relevant professional experience may be considered.

Additional requirements

  • The potential to manage individuals or a team of experts;
  • The ability to organise their activities and ensure a motivating work environment;
  • Strong leadership capabilities, with proven relationship management and communication skills;
  • The ability to drive your team's performance, developing your people by encouraging learning, delegating responsibility and giving regular and constructive feedback;
  • Strong problem-solving skills to deal with day-to-day operational challenges, together with demonstrated planning and organisational skills;
  • Strong result orientation with the ability to set priorities and present practical solutions both orally and in writing;
  • The ability to manage challenging situations proactively and constructively and to be customer-focused.
  • People management experience is an asset, as is international experience, i.e. outside your home country, as well as experience in diverse functional areas relevant to ESA activities.
  • Excellent organisational and stakeholder management skills;
  • Willingness to travel;
  • International experience including interfacing with international and intergovernmental organisations’ security frameworks or national security authorities;
  • Professional certifications in cyber security would be an asset.

Diversity, Equity and Inclusiveness 
ESA is an equal opportunity employer, committed to achieving diversity within the workforce and creating an inclusive working environment. We therefore welcome applications from all qualified candidates irrespective of gender, sexual orientation, ethnicity, religious beliefs, age, disability or other characteristics. 

At the Agency we value diversity, and we welcome people with disabilities. Whenever possible, we seek to accommodate individuals with disabilities by providing the necessary support at the workplace. The Human Resources Department can also provide assistance during the recruitment process. If you would like to discuss this further, please contact us via email at contact.human.resources@esa.int.
 
Important Information and Disclaimer
In principle, recruitment will be within the advertised grade band (A2-A4). However, if the selected candidate has less than four years of relevant professional experience following the completion of the master’s degree, the position may be filled at A1 level.

Applicants must be eligible to access information, technology, and hardware which is subject to European or US export control and sanctions regulations & eligible to acquire the security clearance by their national security administrations.

During the recruitment process, the Agency may request applicants to undergo selection tests. Additionally, successful candidates will need to undergo basic screening before appointment, which will be conducted by an external background screening service, in compliance with the European Space Agency's security procedures.

Note that ESA is in the process of transitioning to a Matrix setup, which could lead to organisational changes affecting this position.

The information published on ESA’s careers website regarding working conditions is correct at the time of publication. It is not intended to be exhaustive and may not address all questions you would have. 

Nationality and Languages 
Please note that applications are only considered from nationals of one of the following States: Austria, Belgium, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Luxembourg, the Netherlands, Norway, Poland, Portugal, Romania, Slovenia, Spain, Sweden, Switzerland, the United Kingdom and Canada, Cyprus, Latvia, Lithuania and Slovakia. 

According to the ESA Convention, staff shall be recruited on the basis of their qualifications, taking into account an adequate distribution of posts among nationals of the Member States.

The working languages of the Agency are English and French. A good knowledge of one of these is required. Knowledge of another Member State language would be an asset.  


At Impactpool we do our best to provide you the most accurate info, but closing dates may be wrong on our site. Please check on the recruiting organization's page for the exact info. Candidates are responsible for complying with deadlines and are encouraged to submit applications well ahead.
Before applying, please make sure that you have read the requirements for the position and that you qualify. Applications from non-qualifying applicants will most likely be discarded by the recruiting manager.