IT Services
Contract
Belgium
Mons
Needed
NCIA
Essential Qualifications/Experience:
· At least 5 years of practical experience in vulnerability management, with proven experience within the last 6 months
· At least 3 years of experience in testing and validating that contracted deliveries meet the security requirements and fulfil the intended use cases
· General knowledge of cyber security principles, best practices, concepts and technology
· Knowledge of cyber security architectures, including boundary protection, encryption, identity and access management, monitoring and detection, incident response, vulnerability assessments and risk management
· Practical experience with vulnerability scanners and their output formats, such as Tenable Nessus, Qualys or OpenVAS
· Demonstrated experience in building and operating data repositories and reporting pipelines for large volumes of security scan data
· Database skills: proficiency in SQL (e.g. PostgreSQL, MS SQL) for data modelling, querying and storing large datasets of scan results
· BI tools: advanced proficiency in Microsoft Power BI (data modelling, DAX) OR Grafana (connecting to SQL data sources, visualising time-series data)
· Scripting proficiency in Python (Pandas/NumPy) or PowerShell for parsing scan logs and automating data entry
· Training/certifications:
ü Relevant certifications in cyber security, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or GIAC Security certifications
ü Relevant certifications in data analytics or business intelligence, such as Microsoft Power BI Data Analyst Associate (PL-300) or Grafana Certified Professional, are an advantage
Desirable Qualifications/Experience:
· Familiarity with NATO security policy and supporting directives
· Experience in working for or supporting a military or governmental organization
· A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience
· Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work
DUTIES/ROLE:
· Perform security assessment and technical analysis, including but not limited to:
ü Analyse the results of the vulnerability assessments on a weekly basis
ü Prepare, for every assessment report, a remediation plan and provide it to the appropriate technical point of contact
ü Interpret complex technical findings and provide remediation support to system administrators
ü Assess the technical impact of the vulnerabilities in order to prioritise remediation
ü Provide technical guidance, on a weekly basis, on the hardening measures required at operating system, database and network level
· Build and maintain the vulnerability data architecture and visualisation ecosystem, including but not limited to:
ü Design, build and maintain a relational database or structured data repository aggregating raw vulnerability scan data from the various sources
ü Automate the ingestion of scan results into the central database (data pipeline)
ü Develop and maintain dynamic dashboards, using data visualisation and analytics platform such as Power BI or Grafana
ü Create visualisations for vulnerability metrics supporting operational and management reporting
ü Maintain and update the database and the dashboards on a weekly basis
· Perform remediation tracking and site coordination, including but not limited to:
ü Act as the technical point of contact for remediation towards site administrators and system owners
ü Monitor and maintain the tracking of remediation activities
ü Produce weekly and monthly reports for the various stakeholders
ü Chair technical coordination meetings with site administrators in order to resolve remediation roadblocks
· Execute coordination and information gathering activities within NCSC, NCIA and with stakeholders in support of the above activities, and provide at the end of the period of performance a closure report summarising at high level the activities carried out
All the mandatory requirements have to be met in order to apply.