NATO offers you more than a job. It gives you a mission: building peace and security for one billion people in Europe and North America. The NATO Communications & Information Agency is leading NATO’s Digital Endeavour. We are NATO’s technology and cyber leaders, helping NATO Nations to communicate and work together in smarter ways. Our work is challenging and meaningful, and you will develop and apply your expertise as part of a dynamic international team of civilian and military professionals.
What do we offer?
· Genuinely meaningful work as part of the most successful alliance in history.
· 3 year contract with competitive tax-free salary and household and children’s allowances
· Privileges for expatriate staff including expatriation and education allowances (where appropriate) and additional home leave
· Excellent private health insurance scheme
· Generous annual leave of 30 days plus official holidays
· Pension Scheme
About the job
Based in Mons, Belgium you will join the Agency as we embark on a journey to transform our IT services to support NATO’s Digital Endeavour.
The NATO Cyber Security Centre (NCSC) is responsible for planning and executing all lifecycle management activities for cyber security. In executing this responsibility, NCSC provides specialist cyber security-related services covering the spectrum of scientific, technical, acquisition, operations, maintenance, and sustainment support, throughout the lifecycle of NATO Communications and Information Systems (CIS).
The Vulnerability Assessment (VA) Cell manages, coordinates and conducts in depth on-site technical vulnerability assessments to assess whether CIS Security measures are implemented and maintained in accordance with NATO Policies on CIS Security, with the objective to ascertain the susceptibility to compromise of NATO networks and systems.
You will prepare, lead and conduct Vulnerability Assessments, present, analyse, provide remediation advice and report on data gathered during the audits, perform senior level review of security audit reports; life-cycle manage supporting documentation such as auditor handbook, scoping document and assessment spreadsheets and databases. You will also periodically conduct non-standard system audits such as ICS/SCADA, participate in NCI Agency and NATO Project Working Groups (WGs) as a Subject Matter Expert (SME) and brief at both executive and technical levels on Vulnerability Assessment reports and testing outcome.
Please note that extensive travel (inclusive to NATO operation theatre) is required up to 170 days/ year.
For a full list of duties, please review the job description here .
About you
We are looking for a talented and knowledgeable Senior Engineer (Vulnerability Assessment) with a Bachelor’s degree and 3 years of post-related experience.
A different qualification coupled with particularly relevant experience may also be considered.
You should also have:
· Extensive knowledge of Active Directory security configuration and associated vulnerabilities
· Extensive experience in the execution of holistic technical Vulnerability Assessments, particularly in the threat-centric, contextual interpretation of Vulnerability Assessments results
· Experience in data processing automation using script languages (e.g. PowerShell, Python, JavaScript, etc.)
· Comprehensive understanding of the principles of computer and communications security, networking, and the vulnerabilities of modern operating systems and applications acquired through a blend of academic or professional training coupled with practical professional experience
· Extensive experience in leading a technical Vulnerability Assessment team for a large organisation, preferably at international level
· Excellent communication skills with respect to briefing/presenting, report writing & mediation
· Proven ability and experience to brief at executive level on security findings, reports and testing outcome
· Proven ability and experience to write clear and structured technical reports including executive summary, technical findings and remediation plan for several different audiences
Knowledge of English, both written and spoken, is essential.
To learn more about NCI Agency and our work, please visit our website.
The NATO Communications and Information Agency (NCI Agency) will not accept applications prepared, in whole or in part, by means of generative artificial-intelligence (AI) tools, including and without limitation to chatbots, such as Chat Generative Pre-trained Transformer (Chat GPT), or other language generating tools. All applications prepared, in whole or in part, by means of such generative or creative AI applications may be rejected without further consideration at the sole discretion of the NCI Agency.
Please note that ALL SELECTED CANDIDATES, with the exception of currently employed NATO International Civilians (NIC’s) will be appointed at the first Increment of the indicated NATO Grade, i.e. NATO Grade X, Increment 1.This is the salary referred to in this vacancy notice. Extra increments can only be considered for candidates from another Co-Ordinated Organisation.
Selected candidates who are not nationals of the host country and who have not been continuously resident in the host country for at least one year may be eligible for an expatriate allowance. For the purposes of determining continuous residence, NATO considers mainly the work location at the time recruitment started, independent of whether various ties were kept with the home country. For more information on our allowances click here.
All selected candidates are required to complete a Security Clearance, Medical Clearance and Pre-employment Screening process before joining the NCI Agency. This process will require time, so please keep in mind that you will not be able to start working with us right away.