Role description
SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.
SR. CYBER ASSURANCE ANALYST, DATA CENTERS
Cyber Assurance is the practice of providing confidence that systems, products, and processes meet security, regulatory, and compliance obligations. It bridges governance with technical execution — validating that controls are in place, risks are managed, and requirements are met for both internal and customer-facing systems.
As a teammate on the Information Assurance team, you will own and scale cyber assurance for SpaceX data centers with a primary focus on ISO/IEC 27001, ISO/IEC 42001, and SOC 2. You will operate from an information security perspective: designing and validating controls, collecting and reviewing technical and operational evidence, driving remediation, and keeping the data center portfolio audit-ready across sites. You will partner closely with engineers and cross-functional operators so controls are implemented in the environment — not only documented after the fact.
The ideal candidate lives at the intersection of security, compliance, and critical infrastructure. You are comfortable translating ISO 27001, ISO 42001, and SOC 2 Trust Services Criteria into concrete control narratives; digging into access logs, configurations, and monitoring evidence; and explaining framework obligations to non-security partners. You are firm when it matters, flexible when alternative controls still meet the objective, and effective at running concurrent audit and remediation workstreams across a multi-site data center footprint.
RESPONSIBILITIES:
- Own and execute information security compliance and certification for the data center portfolio across ISO/IEC 27001, ISO/IEC 42001, and SOC 2 (Type I/Type II), including control mapping, gap assessment, evidence collection, testing support, and remediation tracking.
- Build and maintain audit-ready evidence packages for data center information security controls — including logical and physical access control, logging and monitoring, change management, vulnerability management, media handling, and availability-related security controls — suitable for external assessors.
- Partner with engineering and system owners to gather and validate technical evidence (configurations, logs, designs, operational procedures) and to confirm controls operate as designed in production data center environments.
- Plan, coordinate, and support internal and external audits and assessments for owned and operated data centers; act as a primary information security liaison to auditors for ISO 27001, ISO 42001, and SOC 2 scopes that include data center operations.
- Perform information security and compliance risk assessments of data center systems, networks, and supporting processes; identify deviations from policy, standards, or framework requirements; advise on remediation; and drive timely closure with accountable owners.
- Develop, maintain, and continuously improve information security policies, standards, procedures, and control documentation that support the data center ISMS / AI management system / SOC 2 control environment.
- Identify and drive assurance efficiency through better evidence pipelines, tooling integration, reuse of control testing, and process improvement across sites so audit readiness scales with the portfolio rather than relying on point-in-time scrambles.
- Maintain an up-to-date understanding of emerging information security risks, changes to ISO 27001 / ISO 42001 / SOC 2 expectations for data center and AI-enabled environments, and new assurance techniques; propose pragmatic, business-enabling actions.
- Mentor fellow teammates and take an active role in their development.
BASIC QUALIFICATIONS:
- High school diploma or equivalency certificate.
- 5+ years of experience in cybersecurity compliance, audit or technical security roles with strong knowledge in security compliance frameworks.
- 5+ years of experience with control testing, security standards/policy development, security audits, or security risk management.
PREFERRED SKILLS AND EXPERIENCE:
- Experience liaising with Facility Operations, Physical Security, and Environmental, Health, and Safety (EHS) teams (including HVAC, fire detection/suppression, and related site systems) to obtain and validate information security-relevant evidence for ISO 27001, ISO 42001, and SOC 2 — while keeping the assurance focus on information security outcomes rather than facilities ownership.
- Hands-on experience implementing or operating controls against ISO/IEC 27001 & 420001 and/or SOC 2 or equivalent industry certifications — including evidence collection and audit support.
- Working knowledge of AI management systems and how AI-related controls intersect with data center and infrastructure assurance scopes.
- Demonstrated ability to evaluate control objectives against enterprise grade IT, network, and infrastructure configurations and to work with technical teams on remediation.
- Familiarity with data center information security control themes commonly in scope for ISO 27001 Annex A and SOC 2 (e.g., physical access and visitor management as security controls, environmental monitoring as availability/security evidence, secure media handling, and continuity interfaces) from an assurance and evidence perspective.
- Ability to interpret configurations, logs, and system/network designs for compliance implications; experience with security tooling such as vulnerability scanners, SIEM, and configuration baseline checks (e.g., CIS Benchmarks).
- Direct experience supporting external ISO 27001 certification audits and/or SOC 2 examinations for infrastructure or data center scopes.
- Experience with GRC or continuous compliance platforms and with improving evidence collection through automation or process redesign.
- Strong communication skills across organizational levels; able to explain framework requirements and risk tradeoffs to engineers, operators, and leadership in plain language.
- Project and program management experience delivering concurrent audit and remediation workstreams in highly fluid environments.
- Professional certifications such as CISA, CISM, CISSP, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent.
ADDITIONAL REQUIREMENTS:
- This position is based in Memphis, TN. This role requires you to be onsite; remote/hybrid work will not be considered.
- Must be willing to travel (<25%) domestically (and internationally as needed) in support of data center audits and other assurance activities.
- Must be willing to work extended hours and/or weekends as needed to support audit windows and critical remediation.
ITAR REQUIREMENTS:
- To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.
SpaceX is an Equal Opportunity Employer; employment with SpaceX is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.
Applicants wishing to view a copy of SpaceX’s Affirmative Action Plan for veterans and individuals with disabilities, or applicants requiring reasonable accommodation to the application/interview process should reach out to [email protected].