About the company
SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.
Job Summary
RESPONSIBILITIES:
šLead, plan, prepare for, schedule, and coordinate security assessments and audits and identify where security controls deviate from acceptable configurations, policy or standards. Drive necessary corrective actions with suppliers or internal partners with urgency and efficiency. šGain a comprehensive understanding of our key suppliers, identify the types of data they maintain, and determine the most effective processes for driving corrective actions. šAct as one of the key Assurance points of contacts for supply chain cybersecurity activities to assist suppliers with mitigating risk to SpaceX data. šContinuously monitor changes in supplier risk profiles and support cross-functional investigations to address both immediate and root causes, aiming to reduce risk and enhance the security of company data. šSupport supplier incident investigations, including identifying data loss, and work with Reliability Engineers or Buyers to assess potential impact. Coordinate root cause analysis and ensure a clear implementation plan for corrective actions is established. šCommunicate assessment results, track corrective action plans to ensure progress, and escalate issues when progress stalls or is blocked. šDevelop and promote cybersecurity and information security awareness and training for internal teams and suppliers. šDevelop, maintain, monitor, and improve appropriate internal controls and policies to protect SpaceX systems and data. šContribute and enhance to continuous improvement of information assurance processes and systems. šStay informed on regulatory changes, compliance guidelines, assessment methods, and emerging tactics; assist with updates to controls, policies, and procedures accordingly.
BASIC QUALIFICATIONS:
šHigh school diploma or equivalency certificate. š5+ years of experience (can be concurrent) in utilizing security relevant tools, systems, and applications in support of cyber/ information security or third-party/supplier risk management, vulnerability management, or continuous monitoring, e.g.: NESSUS, Tenable.io, Qualys, DISA STIGs, SCAP, or other vulnerability or vendor risk rating type tools. š5+ years of experience (can be concurrent) with control testing, security standards/policy implementation, security audits, or security risk management.
The crypto industry is evolving rapidly, offering new opportunities in blockchain, web3, and remote crypto roles ā donāt miss your chance to be part of it.