Cyber Security Engineer (multiple positions) - European Space Agency (Noordwijk)

Contract TypeOther
Deadline17 August 2026

About this position

The summary below is published by European Space Agency on the official vacancy notice. Our own analysis — salary realism, comparable openings, career trajectory, language profile — follows further down the page.

Job Requisition ID:20364

Date Posted:3 August 2026

Closing Date:17 August 2026 23:59 CET/CEST

Publication:Internal & External

Directorate:Technology, Engineering and Quality

**Location**

ESTEC, Noordwijk, Netherlands

## **Description**

Cyber Security Engineer in the System Security Section (TEC-SES), End-to-End Systems Division, Systems Department, Directorate of Technology, Engineering and Quality.

The System Security Section is responsible for the end-to-end system security engineering of the Agency’s missions, projects and activities in the space, ground and user segments and communication links, as well as at system, subsystem, element and equipment level. It covers the missions from the study phase to the definition of requirements, design, development, security integration/verification and security service preparation, across the full stack, from the physical to the application layer.

To serve these functions, the System Security Section defines and executes the associated technology research and development (R&D) and studies, as well as the required security engineering standards.

Using security laboratory facilities, the System Security Section performs…

Excerpt shown; read the full notice on the official page. The structured breakdown below covers the key facts.

Key responsibilities

According to the vacancy notice, the role centres on the following duties:

  • Participate in programme reviews assessing security design, implementation, qualification and validation
  • Review design and proposed implementation, identify vulnerabilities and propose mitigations
  • Conduct authorised penetration tests and lead pen testing teams
  • Recommend remedial actions to strengthen defences
  • Provide recommendations on security best practices
  • Follow implementation of mitigation actions
  • Review and assess acceptability of cyber requests for waivers
  • Organise vulnerability assessment and penetration testing campaigns

Are you eligible?

Check these requirements from the notice before investing time in an application:

  • Education: Master's degree in computer science and/or cyber security
  • Key skills: Metasploit, Nmap, Nessus, Burp Suite, Wireshark, Fuzzing tools, Linux, Windows, Real-time OS, Active Directory/LDAP

Contract and working arrangements

Hiring unit: System Security Section (TEC-SES), End-to-End Systems Division, Systems Department, Directorate of Technology, Engineer….

Position details

Reference
1375434633
Last Verified
6 August 2026

Position overview

This is the official EU Careers listing for Cyber Security Engineer (multiple positions) at ESA based in Noordwijk (Other). The vacancy reference is 1375434633.

Job Requisition ID:20364

Date Posted:3 August 2026

Closing Date:17 August 2026 23:59 CET/CEST

Publication:Internal & External

Directorate:Technology, Engineering and Quality

Location

ESTEC, Noordwijk, Netherlands

## Description

Cyber Security Engineer in the System Security Section (TEC-SES), End-to-End Systems Division, Systems Department, Directorate of Technology, Engineering and Quality.

The System Security Section is responsible for the end-to-end system security engineering of the Agency’s missions, projects and activities in the space, ground and user segments and communication links, as well as at system, subsystem, element and equipment level. It covers the missions from the study phase to the definition of requirements, design, development, security integration/verification and security service preparation, across the full stack, from the physical to the application layer.

To serve these functions, the System Security Section defines and executes the associated technology research and development (R&D) and studies, as well as the required security engineering standards.

Using security laboratory facilities, the System Security Section performs vulnerability assessments at all levels of its responsibility, proposing detection methods and mitigation and protection measures using security assessment tools and equipment.

In this position, you will support ESA directorates and space projects and systems, reporting functionally to the corresponding space project/system management structure.

## Duties

Your tasks and responsibilities will include:

* participating in programme reviews of projects, assessing the security design, implementation, qualification and validation, to ensure development is in line with relevant * programme cyber security requirements; * reviewing the design, proposed implementation and technologies, identifying potential vulnerabilities, analysing their exploitability and their impact, and proposing the appropriate mitigations and required countermeasures; * conducting authorised hands-on penetration tests, leading a pen testing team, to identify security flaws; * recommending remedial actions to strengthen defences; * providing recommendations on security best practices; * following the implementation of the mitigation actions, either internally or with industry/partners; * reviewing and assessing the acceptability of cyber requests for waivers from industry; * organising vulnerability assessment and penetration testing campaigns, assessing the findings, proposing mitigations, and analysing collected evidence of fixed and mitigated vulnerabilities; * fostering new security application areas for multidisciplinary activities, placing emphasis on innovative concepts, cutting-edge technologies and system architectures in the field of cyber security; * proposing and supervising/following, as a technical officer, research and development activities in the area of security for space systems and missions; * supporting laboratory activities as required; * continuously following technological trends and evolutions in the scientific fields relevant for this position, and in particular the latest emerging threats, exploits and industry trends deployed to keep ahead of attackers.

## Technical competencies

Familiarity with tools like Metasploit, Nmap, Nessus, Burp Suite and Wireshark, as well as with fuzzing tools

General background and specific experience in the technical domains covered by the position

Deep understanding of Linux, Windows, real-time OS, Active Directory/LDAP and other IT enterprise software

Proficiency in scripting languages such as Python

Very good knowledge of security frameworks like OWASP

Understanding of related technologies, R&D trends and the industrial landscape

## Behavioural competencies

## Education

A master’s degree in computer science and/or cyber security is required for this post.

## Additional requirements

Application timeline

This vacancy was first listed on 4 August 2026, 2 days ago.

The application deadline is 17 August 2026, 10 days from today. Late applications are not accepted, so submit through the official EU Careers portal well in advance.

Last verified against the EU Careers feed on 6 August 2026.

Where to learn more

For headcount, mission, and other open vacancies at ESA see the ESA institution page; for the cost of living, correction coefficient, and other postings in Noordwijk see our Noordwijk location page.

New to EU careers? Our beginner's guide walks through entry routes, EPSO competitions, and what to prepare. For application logistics see application tips and EPSO competitions.

Career trajectory

Career progression for this grade staff is governed by Articles 44 to 46 of the Staff Regulations (consolidated text on EUR-Lex) and Annex IB on the promotion procedure. Step increases are automatic every two years (Art. 44); grade promotion is competitive, based on the appraisal exercise (Art. 45) and the Career Development Review. For roles at ESA, progression to the next grade typically takes three to five years on merit, with two-yearly step increases in between. Article 46 governs the classification at recruitment, which sets the starting step within the grade (usually step 1 for external recruits without prior EU service, step 2 or 3 where relevant professional experience is recognised).
Mobility within the institutions is encouraged via the inter-institutional and intra-institutional vacancy publication system: temporary agents who pass the probation period and reservists from EPSO laureate lists can typically apply to internal vacancies after one year of service. Lateral moves between Directorates-General reset the seniority clock for promotion only if the new post carries a different grade.

Language profile

Beyond the formal language requirements stated in the vacancy notice, the day-to-day working languages at this employer are English and French in roughly equal measure, with German appearing in some technical files. Internal meetings and most policy drafting in Brussels run in English; French remains the preferred internal language in Luxembourg-based services and parts of DG TRADE.

Application cadence

ESA has not advertised another comparable role with the same grade and subject signature in the past twenty-four months. This opening has rarely been seen on the EU Careers feed and may be the first such posting in our two-year window. Applicants who pass the eligibility checks should not assume the same profile will reopen on a predictable cadence.

Source: This job listing was sourced from the officialEU Careers portal (EPSO). First published: .

Remove ads and unlock all featuresGo Premium