The opportunity
SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.
What you'll do
Lead and support security audits and certification (ISO 27001, NIST, PCI, etc.) efforts.
Partner with engineers to gather and validate technical evidence (configs,: code snippets, logs, system designs, etc.).
Support product security certification efforts (e.g. telecom, CPE, or: country-specific regulatory requirements).
Perform technical security and risk assessments of systems and networks: within our environment and identify where they deviate from security policy, standards or regulations.
Identify security control and compliance gaps, advise on remediation, and: drive timely resolution with engineers.
Maintain necessary documentation of controls, processes and audits.
What they're looking for
- Identify and drive assessments and audit efficiency through system: integration, data utilization, and process improvement.
- Support third-party risk management efforts including supplier onboarding and periodic cyber assessments.
- Identify and propose business enabling actions by maintaining an up-to-date: understanding of emerging trends in information security risks, changes in standards, and new compliance/assurance techniques and trends.
- Mentor fellow teammates and take an active role in their development.