Über diese C005319 Type 3 Security Audit Remediation Support Engineer (NS) - MON 14 Sep Stelle bei EMW, Inc.
Deadline Date: Monday 14 September 2026
Requirement: Type 3 Security Audit Remediation Support Engineer
Location: Mons, BE
Full Time On-Site: Yes
Time On-Site: 100%
Total Scope of the request (hours): 395
Required Start Date: 19 October 2026
End Contract Date: 31 December 2026
Required Security Clearance: NATO SECRET
Duties & Role:
Under the direction of the Section Head, the contractor shall:
1. Perform vulnerability assessment and technical analysis, including but not limited to:
- Analyse the results of the vulnerability assessments when a new assessment is available.
- Prepare, for every assessment report, a remediation action plan and provide it to the appropriate technical point of contact not later than two working days after release of the assessment report;
- Interpret complex technical findings and provide remediation support to system administrators;
- Assess the technical impact of the vulnerabilities in order to prioritise remediation, for all remediation plans being tracked;
- Support vulnerability monitoring activities: review newly and publicly disclosed vulnerabilities and support the team in the preparation of NATO Security Bulletins.
2. Perform remediation tracking and site coordination, including but not limited to:
- Act as the technical point of contact for remediation towards site administrators and system owners;
- Monitor and maintain the tracking of remediation activities for all open findings;
- Produce weekly and monthly progress reports for the various stakeholders;
- Chair technical coordination meetings with site administrators in order to resolve remediation roadblocks.
3. Report on remediation status and support governance activities, including but not limited to:
- Brief the monthly Enterprise Vulnerability Assessment Plan (EVAP) meeting, presenting the progress of the remediation activities;
- Participate in status update meetings, activity planning meetings and other meetings as instructed, on site or via conference call capabilities;
- Provide, at the end of the period of performance, a closure report summarising at high level the activities carried out.
4. Execute coordination and information gathering activities within NCSC, NCIA and with stakeholders at the supported NATO sites, in support of the above activities.
Specific Working Conditions: Given the on-site and coordination nature of the duties, the work is not suitable for regular remote execution. Any occasional telework shall be subject to the NCIA teleworking policy and to prior approval by the Line Manager.
The service shall be provided during the Purchaser's business hours – Monday to Thursday from 08h30 until 17h30 and Friday from 08h30 until 15h30 – on all days except weekends and the Purchaser's site-specific official holidays
All deliverables shall be produced using NCIA templates, or in a format agreed with the point of contact, shall be peer reviewed within the delivery cycle and shall be stored under configuration management in the NCIA-provided tools.
It is crucial for the performance of the services to understand the rules, regulations and methods of work in NATO and in particular in NCSC; therefore frequent replacement of the contractor is not advised and the services shall be performed by one and the same individual for the entire period of performance.
Travel required: The contractor may be required to travel to other NCIA locations for in-person or department meetings. In such cases the contractor will be reimbursed for travel costs according to NATO regulations for traveling on NATO duty. Each travel will be a maximum of 2 days lengths and happening no more than twice per month. Contractors traveling for work purposes shall initiate travel requests from their designated duty station only.
Requirements
Skills, Knowledge & Experience:
- The candidate must have a currently active NATO SECRET security clearance
- A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience;
- Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work.
- At least 5 years of practical experience in vulnerability management, with proven experience within the last 6 months;
- At least 3 years of experience in testing and validating that contracted deliveries meet the security requirements and fulfil the intended use cases;
- General knowledge of cyber security principles, best practices, concepts and technology;
- Knowledge of cyber security architectures, including boundary protection, encryption, identity and access management, monitoring and detection, incident response, vulnerability assessments and risk management;
- Practical experience with vulnerability scanners and their output formats, such as Tenable Nessus, Qualys or OpenVAS;
- Demonstrated experience in producing remediation action plans and coordinating their implementation with system administrators across multiple sites.
- Ability to interpret complex technical findings and to translate them into actionable remediation guidance for system administrators;
- Scripting proficiency in Python (Pandas/NumPy) or PowerShell for parsing scan results and automating data handling;
- Ability to take ownership of tasks and strong motivation to accomplish them to the end, working both independently and within a team;
- Very good communication, analytical and writing skills;
- Language proficiency in English: meet or exceed the NATO STANAG 6001 Level 3 "Professional Proficiency".
- Relevant certifications in cyber security, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or GIAC Security certifications.
Desirable Experience:
- Familiarity with NATO security policy and supporting directives;
- Experience in working for or supporting a military or governmental organization.