Original Advert

At SATLANTIS, we design advanced space technologies to tackle global challenges from above. Our satellites are conceived, designed, and built to deliver reliable, high-performance Earth observation data in demanding orbital environments.

As a Cybersecurity GRC Analyst, you will help strengthen the governance, risk management, and compliance foundations that protect our technology, information, and business operations. Working closely with IT, Cybersecurity, business stakeholders, suppliers, and external partners, you will contribute to ensuring that security requirements are effectively implemented, monitored, evidenced, and continuously improved.

What's in it for you

  • Real impact on cybersecurity governance: Your work will directly contribute to strengthening the security and resilience of a growing space technology organization.
  • Professional growth in a cutting-edge sector: Develop your expertise in cybersecurity governance, risk management, compliance, and information security within the space industry.
  • Flexible working hours: Because balance and trust are part of how we work.
  • Young, dynamic environment: Join a proactive team where autonomy, innovation, and collaboration drive our daily routine.
  • Private health insurance: Your wellbeing comes first, with comprehensive coverage.
  • Campus perks: Discounts at gym and restaurants on the UPV/EHU campus, plus fresh fruit, great coffee, and a motivating work atmosphere.

Your mission

Your mission will be to support the effective governance, risk management, and compliance of SATLANTIS' cybersecurity and information security environment.

Through structured coordination, monitoring, documentation, and continuous improvement, you will help ensure that security requirements are implemented, risks are tracked, audit commitments are addressed, and cybersecurity performance remains visible to decision-makers.

Your main responsibilities will be:

  • Support the maintenance and continuous improvement of ENS High compliance and the ISMS, including the statement of applicability, security policies, standards, procedures, records, and control evidence.
  • Support the oversight of the external SOC service and vulnerability management process, monitoring service performance, escalations, asset coverage, risk classification, remediation deadlines, and outstanding actions.
  • Coordinate internal and external audits, managing audit evidence and maintaining the register of findings, observations, and non-conformities, together with their corresponding corrective action plans and closure status.
  • Coordinate the maintenance and testing of IT continuity and disaster recovery plans with the relevant service and business owners.
  • Support supplier security assessments, contractual security reviews, supplier SLA monitoring, remediation activities, and customer cybersecurity questionnaires and evidence requests.
  • Conduct and maintain technology risk assessments, propose treatment actions, and monitor their implementation, while supporting the application and monitoring of the information classification scheme.
  • Support incident notification and regulatory deadline tracking related to ENS, NIS2, and GDPR.
  • Prepare periodic cybersecurity governance, risk, and compliance dashboards and reports for the Head of IT & Cybersecurity.

What will set you up for success

  • Technical foundation: You hold a Higher Vocational Qualification, University Degree, or equivalent professional experience in Cybersecurity, Information Technology, Telecommunications, Computer Science, Risk Management, Law with a technology specialization, or a related field.
  • Experience and knowledge:
    • Basic practical knowledge of security and compliance frameworks such as ENS, ISO 27001, NIS2, and GDPR.
    • Experience maintaining structured documentation, control evidence, risk registers, or audit records, together with a general technical understanding of IT infrastructure, networks, identity, endpoints, cloud services, and cybersecurity controls.
    • A working understanding of SOC operations, incident management, vulnerability management, and remediation processes will help you monitor performance, track actions, and challenge deviations when needed.
    • Basic understanding of technology risk assessment and supplier and supply-chain security assessment processes will help you contribute to managing cybersecurity risks across the organization.
  • Autonomy and Teamwork: Ability to work independently and in a team.
  • Communication skills: Native or equivalent Spanish and technical English.
  • Preferred skills:
    • Experience participating in ENS or NIS2 implementation, maintenance, or audit activities.
    • Familiarity with Microsoft 365 security and compliance technologies, including Entra ID, Intune, Defender, or Purview, and AWS.

Ready to strengthen cybersecurity in the space industry?

If you're excited about turning cybersecurity requirements into practical improvements and contributing to the security and resilience of space technologies, this is your chance.

Need a visa? No sponsorship mentioned here. Browse visa jobs