Sr. Cyber Assurance Analyst, Data Centers
SpaceX
- Location
- Memphis, TN
- Work model
- Hybrid
- Level
- Senior
- Posted
- 4h ago
Skills
About this role
SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.
SR. CYBER ASSURANCE ANALYST, DATA CENTERS
Cyber Assurance is the practice of providing confidence that systems, products, and processes meet security, regulatory, and compliance obligations. It bridges governance with technical execution — validating that controls are in place, risks are managed, and requirements are met for both internal and customer-facing systems.
As a teammate on the Information Assurance team, you will own and scale cyber assurance for SpaceX data centers with a primary focus on ISO/IEC 27001, ISO/IEC 42001, and SOC 2. You will operate from an information security perspective: designing and validating controls, collecting and reviewing technical and operational evidence, driving remediation, and keeping the data center portfolio audit-ready across sites. You will partner closely with engineers and cross-functional operators so controls are implemented in the environment — not only documented after the fact.
The ideal candidate lives at the intersection of security, compliance, and critical infrastructure. You are comfortable translating ISO 27001, ISO 42001, and SOC 2 Trust Services Criteria into concrete control narratives; digging into access logs, configurations, and monitoring evidence; and explaining framework obligations to non-security partners. You are firm when it matters, flexible when alternative controls still meet the objective, and effective at running concurrent audit and remediation workstreams across a multi-site data center footprint.
RESPONSIBILITIES
• Own and execute information security compliance and certification for the data center portfolio across ISO/IEC 27001, ISO/IEC 42001, and SOC 2 (Type I/Type II), including control mapping, gap assessment, evidence collection, testing support, and remediation tracking.
• Build and maintain audit-ready evidence packages for data center information security controls — including logical and physical access control, logging and monitoring, change management, vulnerability management, media handling, and availability-related security controls — suitable for external assessors.
• Partner with engineering and system owners to gather and validate technical evidence (configurations, logs, designs, operational procedures) and to confirm controls operate as designed in production data center environments.
• Plan, coordinate, and support internal and external audits and assessments for owned and operated data centers; act as a primary information security liaison to auditors for ISO 27001, ISO 42001, and SOC 2 scopes that include data center operations.
• Perform information security and compliance risk assessments of data center systems, networks, and supporting processes; identify deviations from policy, standards, or framework requirements; advise on remediation; and drive timely closure with accountable owners.
• Develop, maintain, and continuously improve information security policies, standards, procedures, and control documentation that support the data center ISMS / AI management system / SOC 2 control environment.
• Identify and drive assurance efficiency through better evidence pipelines, tooling integration, reuse of control testing, and process improvement across sites so audit readiness scales with the portfolio rather than relying on point-in-time scrambles.
• Maintain an up-to-date understanding of emerging information security risks, changes to ISO 27001 / ISO 42001 / SOC 2 expectations for data center and AI-enabled environments, and new assurance techniques; propose pragmatic,