Log in/Create account

Enterprise Cyber Risk Management Support Services

This position is no longer available

Industry

IT Services

Type

Contract

Country

Belgium

City

Brussels

Security

Needed

Company

NCIA

Essential Qualifications/Experience:

·       The candidate must possess a university degree in a relevant engineering or technical field such as computer science, systems science, or an equivalent technical qualification

·       The candidate must have comprehensive knowledge of the principles of computer communications security, networking, and the vulnerabilities of modern operating systems, applications and cloud

·       The candidate must have at least three (3) years of demonstrated experience working with national or international CIS and cyber security, including their application and auditing at both governance and operational levels

·       The candidate must have demonstrated experience in securing cloud-based environments

·       The candidate must have demonstrated experience in defining and implementing cyber security architectures, including Zero Trust principles

·       The candidate must have good knowledge of securing AI-enabled systems and data-driven capabilities

·       The candidate must have experience in the management or delivery of cybersecurity programs across multiple focus areas, including, but not limited to, incidents, risk, and cyber defence

·       The candidate shall have proven experience in cyber risk management, enterprise risk management, or security governance

·       The candidate shall have demonstrable experience in vulnerability analysis and risk assessment, including mapping technical findings to business or operational impact

·       The candidate must have experience working with risk management tools, portals, dashboards, or GRC platforms

·       The candidate must have strong understanding of:

ü  Vulnerability management and exposure analysis

ü  Risk registers, prioritization, and treatment workflows

ü  Enterprise CIS environments and dependencies

ü  Familiarity with AI concepts and AI-related risks

ü  Strong stakeholder coordination skills across technical, operational, and governance domains

·       The candidate must have demonstrated experience in operating in an environment with cross functional teams and complex reporting structures

·       The candidate must demonstrate strong English writing and speaking communication and presentation skills, including the ability to convey complex cyber security concepts to both technical and non-technical audiences

·       The candidate shall have demonstrated relevant project management skills and experience in industry or governmental cyber defence area

·       The candidate must demonstrate the ability to analyse complex cyber security specifications and translate them into clear, actionable requirements or artefacts

·       The candidate must demonstrate a strong security-focused and analytical mindset, with attention to detail and problem-solving capability

Desirable Qualifications/Experience:

·       Knowledge of NATO Security Policy and its supporting Directives

·       Knowledge of the NATO Digital Policy Committee (DPC) and its substructure

·       Knowledge of NATO CIS Security Accreditation processes, or equivalent national processes

·       Recognised professional certifications in cyber security and/or project management

DUTIES/ROLE:

·       Development of an Enterprise Risk Management Tool & Portal

ü  The contractor shall engage with relevant stakeholders, including NATO committees, Capability Panels, and national SMEs to expand and enhance the Enterprise Risk Management (ERM) tool prototype and portals supporting cyber, vulnerability, and AI risk management. This includes translating complex cyber security specifications, policies, and operational needs into clear, actionable, and testable requirements

ü  Develop and maintain core functionalities including:

o   Enterprise and operational cybersecurity risk registries

o   Vulnerability-driven cybersecurity risk assessment tools

o   Dashboards and decision-support views

o   High-Level Risk Management and Remediation plans

o   Up to date maps of CIS, services, dependencies, and AI-enabled capabilities

·       Develop, coordinate, and support the evolution of the Board of CISOA Portal

ü  The contractor shall develop, coordinate, review and maintain the evolution of the Board of CISOA Portal, ensuring alignment with NATO policies and internationally recognized frameworks such as NIST and ISO. This includes supporting the lifecycle of standardization artefacts within NATO governance processes

ü  Enable NATO CIS Operational Authorities to:

o   View enterprise-wide cyber, vulnerability and AI risks

o   Perform risk-based prioritization of CIS, services, and remediation activities

o   Support informed operational and strategic decisions

o   Collaborate and facilitate risk information exchange in support of decision-making

·       Artificial Intelligence Risk Analysis & Deployment Support

ü  The contractor shall support the risk assessment and governance of Artificial Intelligence solutions across NATO

ü  The contractor will identify and assess AI-related risks, including:

o   Security and resilience risks

o   Data protection, confidentiality, and integrity concerns

o   Explainability, trust, and operational risks

o   Ethical and governance considerations

·       Deployment of AI solutions

ü  The contractor shall define, document, and maintain cyber security conformance criteria and audit objectives supporting the controlled and secure deployment of AI solutions in NATO infrastructure

ü  Support the controlled and secure deployment of AI solutions:

o   Oversee and support the embedding of AI risks into NATO enterprise risk registers

o   Support assurance, accreditation, and lifecycle risk management enabling automation of compliance verification wherever feasible

o   Align AI deployments with NATO policies and principles

o   Timely and accurate delivery of reports and products

·       Enterprise Risk Awareness & Information Sharing

ü  The contractor shall improve coherence, situational awareness, and information sharing across NATO in the areas of cyber, vulnerability, and AI-enabled risk management

o   Support enterprise-level reporting and dashboards for the CDT

o   Weekly updates of the CDT senior management

o   Contribute to common risk taxonomies, metrics, and reporting standards across the Alliance

·       Support to Security Accreditation process

ü  The contractor shall support the conduction of activities and development of documents in support of the security accreditation process and relevant task force activities for cloud-based environments and AI-enabled systems, ensuring that emerging technologies are aligned with NATO cyber security standards and best practices

ü  Support organisation, reporting and inputs to the CDT Security Accreditation Task Force

o   Weekly updates to the Task Force and relevant boards

o   Contribute to risk analysis and products on AI (where applicable) and security accreditation

·       Reporting, Briefings, and Technical Communication

ü  The contractor shall prepare and deliver briefings, presentations, and reports to NATO committees, Capability Panels, and working groups, clearly communicating technical concepts, progress, and recommendations related to cyber security standards

ü  Success will be measured by the timely delivery of high-quality reports and presentations, documented briefings, and stakeholder feedback demonstrating clarity, relevance, and effectiveness of communication

·       Support to Unforeseen and Ad Hoc Requirements

ü  The contractor shall provide support to unforeseen or ad hoc requirements within the scope of AI and cyber security as requested and prioritised by CDT. Such support shall be subject to mutual agreement on scope, effort, and priority

ü  Success will be measured by the timely and effective delivery of agreed support activities, as documented in tasking requests, and acceptance of outputs by CDT

Job requirements

All the mandatory requirements have to be met in order to apply.

• The candidate must possess a university degree in a relevant engineering or technical field such as computer science, systems science, or an equivalent technical qualification (Mandatory)
• The candidate must have comprehensive knowledge of the principles of computer communications security, networking, and the vulnerabilities of modern operating systems, applications and cloud (Mandatory)
• The candidate must have at least three (3) years of demonstrated experience working with national or international CIS and cyber security, including their application and auditing at both governance and operational levels (Mandatory)
• The candidate must have demonstrated experience in securing cloud-based environments (Mandatory)
• The candidate must have demonstrated experience in defining and implementing cyber security architectures, including Zero Trust principles (Mandatory)
• The candidate must have good knowledge of securing AI-enabled systems and data-driven capabilities (Mandatory)
• The candidate must have experience in the management or delivery of cybersecurity programs across multiple focus areas, including, but not limited to, incidents, risk, and cyber defence (Mandatory)
• The candidate shall have proven experience in cyber risk management, enterprise risk management, or security governance (Mandatory)
• The candidate shall have demonstrable experience in vulnerability analysis and risk assessment, including mapping technical findings to business or operational impact (Mandatory)
• The candidate must have experience working with risk management tools, portals, dashboards, or GRC platforms (Mandatory)
• The candidate must have strong understanding of: (Mandatory)
 Vulnerability management and exposure analysis (Mandatory)
 Risk registers, prioritization, and treatment workflows (Mandatory)
 Enterprise CIS environments and dependencies (Mandatory)
 Familiarity with AI concepts and AI-related risks (Mandatory)
 Strong stakeholder coordination skills across technical, operational, and governance domains (Mandatory)
• The candidate must have demonstrated experience in operating in an environment with cross functional teams and complex reporting structures (Mandatory)
• The candidate must demonstrate strong English writing and speaking communication and presentation skills, including the ability to convey complex cyber security concepts to both technical and non-technical audiences (Mandatory)
• The candidate shall have demonstrated relevant project management skills and experience in industry or governmental cyber defence area (Mandatory)
• The candidate must demonstrate the ability to analyse complex cyber security specifications and translate them into clear, actionable requirements or artefacts (Mandatory)
• The candidate must demonstrate a strong security-focused and analytical mindset, with attention to detail and problem-solving capability (Mandatory)
• Knowledge of NATO Security Policy and its supporting Directives (Nice to have)
• Knowledge of the NATO Digital Policy Committee (DPC) and its substructure (Nice to have)
• Knowledge of NATO CIS Security Accreditation processes, or equivalent national processes (Nice to have)
• Recognised professional certifications in cyber security and/or project management (Nice to have)
Overview
Details
Requirements