Mission Security Manager

Il y a 2 jours

Toulouse, Occitanie, France Exotrail SA Temps plein 90 000 € - 120 000 €/an

At Exotrail, we are developing innovative space logistics solutions to make satellite operations more efficient, sustainable, and secure. As part of our In-Orbit Services (IoS) Business Unit, we are looking for a Mission Security Manager to implement and oversee cybersecurity activities across our space programs and products.

Working at the intersection of engineering, program management, and cybersecurity, you will ensure that security is embedded throughout the entire lifecycle of our systems, from risk assessment and architecture design to operations and continuous security monitoring.

Your Missions

Security Governance & Risk Management

  • Define, maintain, and manage product security documentation throughout the project lifecycle.

  • Develop and maintain:

    • Security Management Plan

    • Security Risk Assessment

    • Security Risk Register

    • Security Treatment Plan

    • Security Vulnerability Assessment

    • Security Monitoring and Incident Handling Plan

  • Ensure compliance with company policies, customer requirements, and applicable security standards.

Security Risk Analysis & Mitigation

  • Lead security working groups and coordinate risk assessment activities.

  • Perform and maintain security risk analyses for space systems and embedded products.

  • Work closely with system and product architects to define and implement cybersecurity mitigation strategies.

  • Ensure identified security controls are effectively deployed and verified.

Security Assurance & Validation

  • Support and coordinate security audit activities, including:

    • Static Application Security Testing (SAST)

    • Dynamic Application Security Testing (DAST)

    • Software Composition Analysis (SCA)

    • Penetration Testing

  • Monitor remediation actions and ensure vulnerabilities are properly addressed.

  • Contribute to product security reviews throughout development and qualification phases.

Security Operations & Continuous Improvement

  • Ensure the continued security posture of products and systems throughout their operational lifecycle.

  • Monitor emerging threats and vulnerabilities affecting Exotrail products and technologies.

  • Coordinate response activities and security incident management when required.

  • Promote a strong cybersecurity culture within engineering and project teams.

Cross-Functional Collaboration

  • Work closely with Program Managers, Product Architects, Engineering teams, Bid Managers, and the Corporate Information Security team.

  • Interface with customers, suppliers, and external stakeholders regarding security topics.

  • Support bid and proposal activities by contributing to cybersecurity requirements and compliance strategies.

  • Represent cybersecurity topics during project reviews and customer meetings.

About You

Required Experience

  • Master's degree in Engineering, Cybersecurity, Computer Science, or a related field.

  • At least 5 years of experience in cybersecurity, preferably within embedded systems, aerospace, defense, industrial systems, or other critical environments.

  • Strong experience conducting cybersecurity risk assessments and defining mitigation strategies.

  • Experience working in multidisciplinary engineering projects involving both hardware and software products.

  • Knowledge of space systems or regulated industries is highly valued.

Technical Skills

  • Strong knowledge of cybersecurity frameworks and regulations such as ISO 27001, NIS2, and cybersecurity best practices.

  • Experience performing security risk assessments using methodologies such as EBIOS Risk Manager (EBIOS RM) or equivalent.

  • Knowledge of vulnerability assessment techniques and security testing methodologies.

  • Familiarity with SAST, DAST, SCA, and penetration testing activities.

  • Understanding of secure-by-design principles for embedded and connected systems.

  • Experience working with standards and engineering frameworks such as ECSS, NPR, ISO, or equivalent.

  • Ability to define and maintain security documentation throughout the product lifecycle.

  • Understanding of vulnerability management and security monitoring processes.

Soft Skills

  • Strong analytical and risk assessment capabilities.

  • Excellent communication and stakeholder management skills.

  • Abili