Project System Security Officer - European Space Agency (Noordwijk)

Contract Type Other
Deadline 16 August 2026

About this position

The summary below is published by European Space Agency on the official vacancy notice. Our own analysis — salary realism, comparable openings, career trajectory, language profile — follows further down the page.

Job Requisition ID:20696

Date Posted:14 July 2026

Closing Date:16 August 2026 23:59 CET/CEST

Publication:Internal & External

Directorate:Technology, Engineering and Quality

**Location**

ESTEC, Noordwijk, Netherlands

## **Description**

Project/System Security Officer (PSSO) in the System Security Section (TEC-SES), End-to-End Systems Division, Systems Department, Directorate of Technology, Engineering and Quality.

The System Security Section is responsible for the end-to-end system security engineering of the Agency’s missions, projects and activities in the space, ground and user segments and communication links, at system, subsystem, element and equipment level. It covers the missions from study phase to the definition of requirements, design, development, security integration/verification, and security service preparation, across the full stack, from the physical to the application layer. The System Security Section provides functional support to ESA missions and projects in the area of end-to-end security engineering and cyber security. To serve these functions, it also defines and carries out the associated technology research and development (R&D) and studies.

In…

Excerpt shown; read the full notice on the official page. The structured breakdown below covers the key facts.

Key responsibilities

According to the vacancy notice, the role centres on the following duties:

  • Create and implement comprehensive security policies, procedures and access control protocols in compliance with the ESA Security Framework
  • Ensure corporate information system and assets are secured, managed and accounted for in accordance with ESA Security Directives
  • Specify security standards and practices for system suppliers
  • Proactively identify, analyse and mitigate security threats to infrastructure
  • Contribute to definition, analyses and consolidation of system security requirements
  • Conduct security risk assessments and propose security mitigations and countermeasures
  • Produce or update security operating procedures (SECOPS)
  • Coordinate vulnerability assessment/penetration testing and ensure mitigations are implemented

Are you eligible?

Check these requirements from the notice before investing time in an application:

  • Education: Master's degree in Computer Science or Cybersecurity or relevant engineering discipline
  • Experience: At least 5 years of relevant professional experience
  • Key skills: Expertise in network security protocols for IT enterprise systems, Expertise in security controls and cyber security hardening for protecting IT infrastructure, Knowledge of access controls, firewalls, operating systems hardening, Experience with cloud environments and security monitoring, Proven experience in IT security implementations, Risk and vulnerability management, Compliance management, Knowledge of applied crypto

Contract and working arrangements

Hiring unit: System Security Section (TEC-SES), End-to-End Systems Division, Systems Department, Directorate of Technology, Engineer….

Position details

Reference
1414823033
Last Verified
24 July 2026

Position overview

This is the official EU Careers listing for Project System Security Officer at ESA based in Noordwijk (Other). The vacancy reference is 1414823033.

Job Requisition ID:20696

Date Posted:14 July 2026

Closing Date:16 August 2026 23:59 CET/CEST

Publication:Internal & External

Directorate:Technology, Engineering and Quality

Location

ESTEC, Noordwijk, Netherlands

## Description

Project/System Security Officer (PSSO) in the System Security Section (TEC-SES), End-to-End Systems Division, Systems Department, Directorate of Technology, Engineering and Quality.

The System Security Section is responsible for the end-to-end system security engineering of the Agency’s missions, projects and activities in the space, ground and user segments and communication links, at system, subsystem, element and equipment level. It covers the missions from study phase to the definition of requirements, design, development, security integration/verification, and security service preparation, across the full stack, from the physical to the application layer. The System Security Section provides functional support to ESA missions and projects in the area of end-to-end security engineering and cyber security. To serve these functions, it also defines and carries out the associated technology research and development (R&D) and studies.

In this role, you will support the Directorate of Technology, Engineering and Quality, or projects and systems as a Project/System Security Officer (PSSO).

## Duties

As a Project/System Security Officer (PSSO) you will be responsible for the design and successful implementation of all security measures designed as part of the overall system(s) you will be assigned to. The tasks to be accomplished will be defined and supervised by the ISO (Information Security Officer). Specifically, your tasks and responsibilities will include the following:

* Create and implement comprehensive security policies, procedures and access control protocols in compliance with the ESA Security Framework; * Ensure that the entire corporate information system and all the assets for which the PSSO is responsible are secured, managed and accounted for in accordance with the ESA Security Directives; * Specify the security standards and practices to be adhered to by the supplier of the system; * Proactively identify, analyse and mitigate security threats to the infrastructure; * Contribute to the definition, analyses and consolidation of system security requirements; * Conduct security risk assessments and support security risk management by proposing suitable security mitigations and countermeasures; * Produce or update as needed the security operating procedures (SECOPS); * Coordinate vulnerability assessment/penetration testing on the infrastructure under your responsibility, and ensure required mitigations are put in place; * Contribute to the authoring of the Information Security Management Plan; * Provide support to the information security and cyber security activities related to the infrastructure under your responsibility, as needed; * Monitor network activity for threats and manage the response, investigation and reporting of security breaches; * Ensure compliance with data protection laws and industry regulations (e.g., ISO 27001), and perform regular security audits; * Educate staff on security awareness, including how to recognise cyberattacks and follow security procedures; * Collaborate with IT and management to design, implement and maintain required security tools, as well as disaster recovery plans; * Collaborate with technical support, IT and management to scope, design, implement and support the certification/accreditation process (when applicable), in coordination with the ESA accreditation authority; * Collaborate with the wider pool of PSSOs, ISOs and security officers on new security governance activities, cross-directorate processes, implementations, improvements and lessons learned; * Maintain security-related tools and systems as well as their disaster and recovery plans; * When needed, report to executives regarding the security posture and risk levels.

## Technical competencies

Expertise in network security protocols for IT enterprise systems

Expertise in security controls and cyber security hardening for protecting IT infrastructure (access controls, devices such as firewalls, operating systems hardening, etc.), including cloud environments and security monitoring

Proven experience in IT security implementations, risk and vulnerability management, and compliance

Knowledge of applied crypto

## Behavioural competencies

## Education and professional experience

A master's degree in Computer Science or Cybersecurity or relevant engineering discipline is required for this post together with at least 5 years of relevant professional experience.

## Additional requirements

Certifications in the area of the job description (such as CISSP, SANS) would be a plus.

Application timeline

This vacancy was first listed on 14 July 2026, 12 days ago.

The application deadline is 16 August 2026, 19 days from today. Late applications are not accepted, so submit through the official EU Careers portal well in advance.

Last verified against the EU Careers feed on 24 July 2026 (2 days ago).

Where to learn more

For headcount, mission, and other open vacancies at ESA see the ESA institution page; for the cost of living, correction coefficient, and other postings in Noordwijk see our Noordwijk location page.

New to EU careers? Our beginner's guide walks through entry routes, EPSO competitions, and what to prepare. For application logistics see application tips and EPSO competitions.

Career trajectory

Career progression for this grade staff is governed by Articles 44 to 46 of the Staff Regulations (consolidated text on EUR-Lex) and Annex IB on the promotion procedure. Step increases are automatic every two years (Art. 44); grade promotion is competitive, based on the appraisal exercise (Art. 45) and the Career Development Review. For roles at ESA, progression to the next grade typically takes three to five years on merit, with two-yearly step increases in between. Article 46 governs the classification at recruitment, which sets the starting step within the grade (usually step 1 for external recruits without prior EU service, step 2 or 3 where relevant professional experience is recognised).
Mobility within the institutions is encouraged via the inter-institutional and intra-institutional vacancy publication system: temporary agents who pass the probation period and reservists from EPSO laureate lists can typically apply to internal vacancies after one year of service. Lateral moves between Directorates-General reset the seniority clock for promotion only if the new post carries a different grade.

Language profile

Beyond the formal language requirements stated in the vacancy notice, the day-to-day working languages at this employer are English and French in roughly equal measure, with German appearing in some technical files. Internal meetings and most policy drafting in Brussels run in English; French remains the preferred internal language in Luxembourg-based services and parts of DG TRADE.

Application cadence

ESA has not advertised another comparable role with the same grade and subject signature in the past twenty-four months. This opening has rarely been seen on the EU Careers feed and may be the first such posting in our two-year window. Applicants who pass the eligibility checks should not assume the same profile will reopen on a predictable cadence.

Source: This job listing was sourced from the official EU Careers portal (EPSO). First published: .

Remove ads and unlock all features Go Premium