NATO offers you more than a job. It gives you a mission: building peace and security for one billion people in Europe and North America. The NATO Communications & Information Agency is leading NATO’s Digital Endeavour. We are NATO’s technology and cyber leaders, helping NATO Nations to communicate and work together in smarter ways. Our work is challenging and meaningful, and you will develop and apply your expertise as part of a dynamic international team of civilian and military professionals.
What do we offer?
· Genuinely meaningful work as part of the most successful alliance in history.
· 3 year contract with competitive tax-free salary and household and children’s allowances
· Privileges for expatriate staff including expatriation and education allowances (where appropriate) and additional home leave
· Excellent private health insurance scheme
· Generous annual leave of 30 days plus official holidays
· Pension Scheme
About the job
Based in Mons, Belgium you will join the Agency as we embark on a journey to transform our IT services to support NATO’s Digital Endeavour.
The NATO Cyber Security Centre (NCSC) is responsible for planning and executing all lifecycle management activities for cyber security. In executing this responsibility, NCSC provides specialist cyber security-related services covering the spectrum of scientific, technical, acquisition, operations, maintenance, and sustainment support, throughout the lifecycle of NATO Communications and Information Systems (CIS).
You will support the Penetration Testing Cell which manages and conducts tailored penetration testing and red teaming activities against NATO networks and systems, with the objective to assess the impact of current cyber threats, as well as, their likelihood and difficulty of exploitation on NATO CIS, a NATO Mission or NATO’s cyber defences by emulating an intermediate or advanced cyber adversary.
You will provide web, infrastructure and application level penetration testing, security consultancy and advice to projects, plans, and other entities, brief at both executive and technical levels on security reports and testing outcome and provide security design reviews to ensure compliance with NATO policies and directives. You will also build and sustain effective communications with different stakeholders and lead and/or be part of the Red/Blue Team during NATO military exercises.
Some remote work/teleworking is possible.
For a full list of duties, please review the job description here .
About you
We are looking for a talented and knowledgeable Senior Engineer (Penetration Testing) with a Bachelor’s degree and 3 years of post-related experience.
A different qualification coupled with particularly relevant experience may also be considered.
You should also have:
· Extensive knowledge and experience (at least 3 years) in the following areas:
ü Web application penetration testing
ü IT infrastructure penetration testing
ü Network security architecture design
ü Assessing security vulnerabilities within OS, software, protocols & networks
ü Researching and evaluating security products & technologies
ü Knowledge in system and network administration of UNIX and Windows systems
ü Use of penetration testing tools, techniques, and recognized testing methodologies
ü Scripting skills in at least one of the following: Python, Go, PowerShell, shell (bash, ksh, csh)
· Technical knowledge in system and network security, authentication and security protocols, cryptography, application security, as well as, malware infection techniques and protection technologies
· Ability to evaluate risks and formulate mitigation plans
· Proven ability to brief at executive level on security findings, reports and testing outcome
· Proven ability and experience writing clear and structured technical reports including executive summary, technical findings and remediation plan for several different audiences
Knowledge of English, both written and spoken, is essential.
To learn more about NCI Agency and our work, please visit our website.
The NATO Communications and Information Agency (NCI Agency) will not accept applications prepared, in whole or in part, by means of generative artificial-intelligence (AI) tools, including and without limitation to chatbots, such as Chat Generative Pre-trained Transformer (Chat GPT), or other language generating tools. All applications prepared, in whole or in part, by means of such generative or creative AI applications may be rejected without further consideration at the sole discretion of the NCI Agency.
Please note that ALL SELECTED CANDIDATES, with the exception of currently employed NATO International Civilians (NIC’s) will be appointed at the first Increment of the indicated NATO Grade, i.e. NATO Grade X, Increment 1.This is the salary referred to in this vacancy notice. Extra increments can only be considered for candidates from another Co-Ordinated Organisation.
Selected candidates who are not nationals of the host country and who have not been continuously resident in the host country for at least one year may be eligible for an expatriate allowance. For the purposes of determining continuous residence, NATO considers mainly the work location at the time recruitment started, independent of whether various ties were kept with the home country. For more information on our allowances click here.
All selected candidates are required to complete a Security Clearance, Medical Clearance and Pre-employment Screening process before joining the NCI Agency. This process will require time, so please keep in mind that you will not be able to start working with us right away.