DESCRIPTION :
As part of the creation of a new position we are looking for a Corporate Security Coordinator who will be in charge of security activities impacting the assets designed, deployed, and operated by ESSP in support of the activities and services provided by ESSP to its customers. For these activities, we are looking for someone with at least 5 years' experience in operational IT security or SOC operation or Security Governance and of critical and/or complex technical systems in the space, aviation or industry sectors.
Your main responsibilities/activities will be:
As a Corporate Security Coordinator:
* Serve as the primary security point of contact (PoC) for security activities impacting the assets designed, deployed, and operated by ESSP, mainly on Madrid and Toulouse sites, ensuring all security requirements are identified, communicated, and met.
* Coordinate and oversee the planification, the execution, and closing of cybersecurity projects, ensuring they are delivered on time, within scope, and on budget.
* Facilitate the coordination with internal teams (Security Operations, Engineering/Evolutions, GRC, Internal Audit) to align security activities with project goals.
* Evaluate and follow project plans, including timelines, milestones, and resource allocation, while managing risks and issues.
* Facilitate communication between stakeholders, ensuring clarity on security objectives, timelines, and deliverables.
As a Security Specialist:
* Assess and address security risks specific to the project, proposing mitigation strategies and ensuring compliance with applicable frameworks.
* Design and validate security controls in collaboration with Security Engineering and GRC teams, or independently as needed.
* Conduct security reviews and audits for the project, ensuring adherence to internal policies and external regulations (for instance : PSSI, ISO 27001, NIST, GDPR)
* Analyse and address security measures and address findings from SOC, Internal Audit, or third-party assessments.
* Propose continuous improvement of security practices within the project scope, leveraging feedback and lessons learned.
As a Member of the Security Team:
* Represent the project's security interests in cross-functional meetings, working groups, and governance forums.
* Collaborate with other security teams to share project-specific insights, align on best practices, and support organizational security initiatives.
* Provide security guidance to project stakeholders, including business units, IT, and external partners.
* Support incident response by offering project-specific context and assisting in investigations if needed.
* Promote security awareness within the project team, ensuring all members understand their roles in maintaining security and compliance.
Code d'emploi : Consultant Sécurité (h/f)
Domaine professionnel actuel : Détectives et Experts en Sécurité
Temps partiel / Temps plein : Plein temps
Type de contrat : Contrat à durée indéterminée (CDI)
Compétences : Microsoft Word, Microsoft Excel, Sécurité Cloud Computing, Sécurité Informatique, Ms Office, Microsoft Visio, Microsoft PowerPoint, Cycle de Vie du Développement de Systèmes, Devsecops, Anglais, Capacité d'Analyse, Sens de la Communication, Leadership, Résolution de Problèmes, Réseautage, Sens de l'Organisation, Motivation Personnelle, Recherche, Génie Aérospatial, Aviation, Réalisation d'Audits, Amélioration des Processus d'Affaires, Conformité Réglementaire, Contrôles de Sécurité, Sécurité d'Entreprise, Planification de Projets, Systèmes Embarqués, Traitement des Incidents, Gouvernance, Gouvernance Gestion des Risques et Conformité, Ingénierie de la Sécurité, ISO/IEC 27001, Gestion de Projet, Allocation des Ressources, Sensibilisation à la Sécurité, Gestion de la Sécurité, Analyse des Besoins de Sécurité, Gestion des Parties Prenantes, Gouvernance et Gestion de l'Information, Réalisation d'Évaluations, Institut National des Normes et de la Technologie (NIST), Industrie Aérospatiale, Internet des Objets (IOT), KSEKOAOQ11HUY4LCLXGR, Budgétisation, Politiques Organisationnelles, Périmètre de Projet, RGPD, Applications des Règles et Consignes de Sécurité, Gestion des Risques
Type d'annonceur : Employeur direct