Log in/Create account

Enterprise Cloud Expert Support Services

Apply now
Industry

IT Services

Type

Contract

Country

Belgium

City

Brussels

Security

Needed

Company

NCIA

Essential Qualifications/Experience:

·       The candidate must possess a university degree in a relevant technical field such as computer science, systems science, or an equivalent technical qualification

·       The candidate must have comprehensive knowledge of the principles of computer communications security, networking, and the vulnerabilities of modern operating systems, applications and cloud

·       The candidate must have demonstrated experience in securing cloud-based environments

·       The candidate must have proven senior experience in cloud security engineering, including architecture and implementation of security controls in complex enterprise environments

·       The candidate must have demonstrated experience in defining and implementing cyber security architectures, including Zero Trust principles

·       The candidate must have experience in the management or delivery of cybersecurity programs across multiple focus areas, including, but not limited to, incidents, risk, and cyber defence

·       The candidate shall have proven experience in cyber risk management, enterprise risk management, or security governance

·       The candidate shall have demonstrable experience in vulnerability analysis and risk assessment, including mapping technical findings to business or operational impact

·       The candidate must have demonstrated experience in operating in an environment with cross functional teams and complex reporting structures

·       The candidate must demonstrate strong English writing and speaking communication and presentation skills, including the ability to convey complex cyber security concepts to both technical and non-technical audiences

·       The candidate shall have demonstrated relevant project management skills and experience in industry or governmental cyber defence area

·       The candidate must demonstrate the ability to analyse complex cyber security specifications and translate them into clear, actionable requirements or standards artefacts

·       The candidate must have proven experience coordinating work across multiple stakeholders (technical and executive), including facilitation, negotiation, prioritisation, and production of decision briefs

·       The candidate must have Knowledge of relevant risk/security frameworks and standards (e.g., ISO 27001/27005, NIST, or equivalent) and the ability to apply them pragmatically in cloud contexts

·       The candidate must demonstrate a strong security-focused and analytical mindset, with attention to detail and problem-solving capability

Desirable Qualifications/Experience:

·       Knowledge of NATO Security Policy and its supporting Directives

·       Knowledge of the NATO Digital Policy Committee (DPC) and its substructure

·       Knowledge of NATO CIS Security Accreditation processes, or equivalent national processes

·       Recognised professional certifications in cyber security and/or project management

·       CCSP (Certified Cloud Security Professional)

·       CISM or CRISC (ISACA)

DUTIES/ROLE:

·       Cloud Security Engineering and Architecture Support

ü  Support the secure design and implementation of cloud-based solutions (IaaS/PaaS/SaaS), including security architecture patterns, hardening baselines, secure connectivity, identity and access management, logging/monitoring, encryption/key management, and secure CI/CD practices

·       Accreditation Support and Delivery

ü  Support the end-to-end security accreditation process through coordination and oversight, ensuring the right stakeholders are engaged, activities are planned, dependencies are managed, and progress is tracked. Facilitate collection and consolidation of inputs and evidence from engineering/service teams, support resolution of issues and findings, and provide status reporting and decision-support to accreditation stakeholders

·       Cyber Risk Assessments and Risk Treatment Planning

ü  Conduct and/or coordinate cyber risk assessments for cloud services and supporting components, ensuring risks are clearly articulated, assessed, documented, and tracked with pragmatic risk treatment options

·       Continuous Assurance, Security Posture and Compliance Monitoring

ü  Define and support continuous assurance approaches for cloud environments (e.g., control monitoring, vulnerability management, configuration compliance, audit readiness), including reporting that enables operational and executive decision-making

ü  Support the controlled and secure deployment of Cloud solutions:

o   Oversee and support projects to implement Cloud solutions across the NATO Enterprise

o   Support assurance, accreditation, and lifecycle risk management enabling automation of compliance verification wherever feasible

o   Timely and accurate delivery of reports and products

·       Stakeholder Management and Coordination

ü  Engage and coordinate multiple stakeholders (technical teams, service owners, risk owners, operational authorities, security/accreditation stakeholders) across locations to align on security requirements, risk posture, and delivery priorities. Prepare and deliver briefings and decision-support materials

·       Support to Security Accreditation process

ü  The contractor shall support the conduction of activities and development of documents in support of the security accreditation process and relevant task force activities for cloud-based environments and AI-enabled systems, ensuring that emerging technologies are aligned with NATO cyber security standards and best practices

ü  Support organisation, reporting and inputs to the CDT Security Accreditation Task Force

o   Weekly updates to the Task Force and relevant boards

o   Contribute to risk analysis and products on AI (where applicable) and security accreditation

·       Reporting, Briefings, and Technical Communication

ü  The contractor shall prepare and deliver briefings, presentations, and reports to NATO committees, Capability Panels, and working groups, clearly communicating technical concepts, progress, and recommendations related to cyber security standards

·       Support to Unforeseen and Ad Hoc Requirements

ü  The contractor shall provide support to unforeseen or ad hoc requirements within the scope of cyber security, Cloud, AI, and interoperability as requested and prioritised by CDT. Such support shall be subject to mutual agreement on scope, effort, and priority

Job requirements

All the mandatory requirements have to be met in order to apply.

• The candidate must possess a university degree in a relevant technical field such as computer science, systems science, or an equivalent technical qualification (Mandatory)
• The candidate must have comprehensive knowledge of the principles of computer communications security, networking, and the vulnerabilities of modern operating systems, applications and cloud (Mandatory)
• The candidate must have demonstrated experience in securing cloud-based environments (Mandatory)
• The candidate must have proven senior experience in cloud security engineering, including architecture and implementation of security controls in complex enterprise environments (Mandatory)
• The candidate must have demonstrated experience in defining and implementing cyber security architectures, including Zero Trust principles (Mandatory)
• The candidate must have experience in the management or delivery of cybersecurity programs across multiple focus areas, including, but not limited to, incidents, risk, and cyber defence (Mandatory)
• The candidate shall have proven experience in cyber risk management, enterprise risk management, or security governance (Mandatory)
• The candidate shall have demonstrable experience in vulnerability analysis and risk assessment, including mapping technical findings to business or operational impact (Mandatory)
• The candidate must have demonstrated experience in operating in an environment with cross functional teams and complex reporting structures (Mandatory)
• The candidate must demonstrate strong English writing and speaking communication and presentation skills, including the ability to convey complex cyber security concepts to both technical and non-technical audiences (Mandatory)
• The candidate shall have demonstrated relevant project management skills and experience in industry or governmental cyber defence area (Mandatory)
• The candidate must demonstrate the ability to analyse complex cyber security specifications and translate them into clear, actionable requirements or standards artefacts (Mandatory)
• The candidate must have proven experience coordinating work across multiple stakeholders (technical and executive), including facilitation, negotiation, prioritisation, and production of decision briefs (Mandatory)
• The candidate must have Knowledge of relevant risk/security frameworks and standards (e.g., ISO 27001/27005, NIST, or equivalent) and the ability to apply them pragmatically in cloud contexts (Mandatory)
• The candidate must demonstrate a strong security-focused and analytical mindset, with attention to detail and problem-solving capability (Mandatory)
• Knowledge of NATO Security Policy and its supporting Directives (Nice to have)
• Knowledge of the NATO Digital Policy Committee (DPC) and its substructure (Nice to have)
• Knowledge of NATO CIS Security Accreditation processes, or equivalent national processes (Nice to have)
• Recognised professional certifications in cyber security and/or project management (Nice to have)
• CCSP (Certified Cloud Security Professional) (Nice to have)
• CISM or CRISC (ISACA) (Nice to have)
Apply to the job
Overview
Details
Requirements
Apply