Security Audit Expert – F/M
ESSP, a private company with 7 major European Air Navigation Service Providers as shareholders, manages the operation and supports the adoption of the European Satellite Based Augmentation System to GPS: EGNOS.
ESSP Corporate Video: https://www.youtube.com/watch?v=ojO8TAitQoc
The adoption of this service is rapidly growing given it allows correcting the GPS signal and offers enhanced features with accurate positioning and integrity within safety-of-life services context such as public transportation.
ESSP Website: https://www.essp-sas.eu/human-resources/careers/
By joining us, you will be in charge of security audits on ESSP and its suppliers on its activities delivered to its clients. If you have 5 years’ of experience in IT security or in information systems and networks, preferably in a critical or complex systems (space, aviation, industry sectors), then this position is for you!
Under the authority of the CSO (Chief Security Officer), you will perform the following activities:
- Measure and evaluate the level of compliance by leading audits and verifications;
- Lead required accreditations of products and facilities across different sites in Europe;
- Conduct organizational audits, propose remediation plan and follow it up until implementation;
- Lead technical audits/pentests/vulnerabilities assessments, propose remediation plan and follow it ;
- Evaluate and monitor the implementation of security requirements across different sites in Europe;
- Propose/do required assessments or verifications: security-related processes, countermeasures, practices
- Propose security functions and solutions, contribute projects;
- Provide your expertise for example by participating to call for tenders;
- Participate in the analysis of security events and lead the implementation of mitigation actions;
- Contribute to the company's and clients' security dashboards;
You will contribute to the continuous improvement of ESSP security policies, specifically in the context of the ESSP ISO 27001 certified ISMS and Security Management System supporting the ESSP ANSP Certificate.
Consequently you will contribute to:
- Promoting good security practices to the personnel,
- Ensuring a security watch, both technological and regulatory,
- Improving enterprise processes and tools for security management,
- Developing fully integrated auditing services to be widely use across the company.
Very good working knowledge of:
- Organisational audits (Certification ISO27001 LA or CISA),
- Technical audits (Vulnerabilities Assessment, Pentests, CVE Database, CVSS classification),
- Project management,
- Information security standards (ISO27001, NIST, OWASP, ANSSI, ENISA, etc.),
Good practical knowledge:
- Enterprise IT and security organization aspects (ISMS, etc.),
- Technical security (information systems, networks, physical security, crypto, etc.) and of cybersecurity (threats, exploits, vulnerabilities, etc.),
- Familiar with critical systems and associated constraints (space, aviation, industry, etc.).
- Understand, analyse and reformulate users/customers/projects’ needs and requirements;
- Define and write technical documentation; have editorial capabilities;
- Act as consultant and facilitate the decision making process;
- Evaluate the impacts of technologies and solutions on information systems and operations.
- Team work,
- Rigor, pragmatism and discreetness
The knowledge of the following domains would be considered an advantage:
- Knowledge of EGNOS, GNSS and CNS technologies,
- European regulation applicable to Information System Security and to GNSS in particular.
Language: English (B2) – CEFR.
Engineering degree or equivalent.
Available for punctual travels in Europe.
Access to this position requires an EU Confidential Personal Security Clearance (PSC)
Human Resources information:
Element of package of remuneration:
Please send your application file only by e-mail to the following address: firstname.lastname@example.org
Job Location: Toulouse (France)
Type of Contract: Full time - Permanent Contract
ESSP is committed to cultural diversity, gender equality and the employment of disabled workers.