Senior Architect, Cyber Security IRIS2
Munich (Unterföhring), DE Betzdorf, LU

Senior Architect, Cyber Security IRIS2
The job responsibilities outlined in this document are not exhaustive and may evolve over time and be reviewed according to business needs.
PROGRAMME DESCRIPTION
IRIS2 is the new European Union secure satellite constellation. This project is the European Union's answer to the pressing challenges of tomorrow to provide secure connectivity services and enhanced communication capacities to the EU and its Member States. In addition, governmental users, private companies and European citizens while benefiting from ensuring high-speed internet broadband to cope with connectivity dead zones.
SES, together with other consortium partners and core members, was selected by the European Commission to build and operate the IRIS2 multi-orbit satellite constellation.
As the IRIS2 team enters the next project phases, there is a strong need of support for all the activities around service provisioning and products that the system can offer in the future.
ROLE DESCRIPTION SUMMARY
The Cyber Security Architect, IRIS² will be responsible for shaping and assuring the programme’s cybersecurity architecture, ensuring that security-by-design principles are embedded across the end-to-end system.
The successful candidate will work closely with Programme leadership, System Engineering, Space and Ground segment teams, Security workgroups, Services and Operations, consortium partners and external stakeholders to ensure that the IRIS² solution is secure, certifiable, operable and resilient.
PRIMARY RESPONSIBILITIES / KEY RESULT AREAS
Security architecture and design authority
- Define, maintain and govern cybersecurity architecture across space, ground, network, service, operational and support environments.
- Act as a security design authority for cybersecurity decisions, design reviews and architecture trade-offs across the programme.
- Translate programme security objectives into architecture requirements, security controls, design patterns, and assurance activities.
- Ensure acquired, developed and integrated systems remain aligned with IRIS² security architecture guidelines and security-by-design principles.
- Lead architectural decisions related to cryptography, key management, identity and access management, secure interfaces, segmentation, multi-level security, GNSS resilience, and operational resilience.
Security governance, accreditation and assurance
- Drive cybersecurity governance activities supporting security accreditation, certification, and formal assurance expectations.
- Lead the preparation and review of accreditation and certification inputs, evidence packages, architecture justifications, and security governance material.
- Support compliance audits, penetration tests, security assessments, and assurance reviews from an architecture and risk perspective.
- Ensure security architecture, risk treatment decisions and accreditation evidence remain consistent and traceable.
- Contribute to the review and evolution of cybersecurity implementation, accreditation, certification, component security, and end-to-end risk documentation.
Security risk and resilience
- Lead or guide security risk assessments, threat modelling and security impact assessments for major programme design decisions.
- Define risk treatment approaches and mitigation strategies for cybersecurity threats affecting mission critical satellite communications systems.
- Provide expert guidance on security resilience, critical infrastructure protection, and secure mission operations.
- Advise on ISMS-related protection requirements and ensure alignment between security controls, operational needs and governance documentation.
Stakeholder and partner alignment
- Coordinate security architecture activities with Programme teams, System Engineering, Security workgroups, Services and Operations, Core Team subcontractors and managed service partners.
- Influence multidisciplinary stakeholders by explaining cyber risk, design implications and security trade-offs in a clear and pragmatic way.
- Support procurement and supplier engagement by reviewing cybersecurity requirements, security product strategies, and architectural dependencies.
- Provide technical leadership in an agile, international, and matrixed programme environment.
Qualifications and experience
- University degree in Cybersecurity, Engineering, Telecommunications, Computer Science, Information Security or a related technical discipline.
- Typically, 10+ years of experience in cybersecurity, security architecture, secure systems engineering, or secure solution design.
- Proven experience defining cybersecurity architecture in complex, regulated or mission-critical environments.
- Strong understanding of satellite communications, space and ground systems, telecom networks, datacenters, cloud or hybrid infrastructure, 5G / NTN, OSS / BSS or user terminal environments.
- Experience working with governmental, defense, EU, ESA, NATO or national security-related stakeholders is highly desirable.
- Experience supporting security accreditation, certification, compliance audits, penetration testing programmes or formal assurance activities.
- Experience in Common Criteria (ISI/IEC 15408), NIST Risk Management Framework, NIST Special publication 800-53.
- Fluency in written and spoken English; additional European languages are an asset.
Competencies
- Strategic thinker able to connect programme objectives, cyber risk and practical architecture decisions.
- Strong stakeholder management skills with the confidence to challenge, advise and align senior technical stakeholders.
- Structured and detail oriented, with the ability to produce high-quality architecture, governance, and assurance documentation.
- Collaborative and pragmatic, able to balance security ambition, delivery constraints and accreditation expectations.
- Comfortable operating independently in a fast-moving, complex and matrixed programme environment.
OTHER KEY REQUIREMENTS / COMMENTS
- Eligibility for ESA/EU/NATO SECRET personal security clearances is essential.
- Candidates must be prepared to undergo a security clearance procedure, as this position may require holding such a clearance
- Willing to work 60% onsite from office
- Travel as required for project realization purposes
SES and its Affiliated Companies are committed to providing fair and equal employment opportunities to all. We are an Equal Opportunity employer and will consider all qualified applicants for employment without regard to race, color, religion, gender, pregnancy, sex, sexual orientation, gender identity, national origin, age, genetic information, protected veteran status, disability, or any other basis protected by local, state, or federal law.
For more information on SES, click here.