Über diese Senior Cyber Security Specialist Stelle bei Spektrum
Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.
Who we are supporting
The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.
The NCIA provides a wide range of services, including:
- Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.
- Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.
- Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
- Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.
- Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers.
Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities.
The program
Assistance and Advisory Service (AAS)
The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.
To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.
Role ID – C005378
Role Duties and Responsibilities
- Under the direction of the Section Head of Cyber Enablement Service (CES) the contractor shall:
- Support the development, refinement and management of technical and operational requirements for cyber and CIS monitoring capabilities;
- Engage with NATO stakeholders, customers, users, technical authorities and operational representatives to solicit, analyse and document technical requirements;
- Translate operational needs into clear engineering requirements, system requirements, functional requirements and non-functional requirements;
- Develop and maintain engineering artefacts, including but not limited to:
- Requirements specifications;
- Use cases;
- User stories and operational scenarios;
- State diagrams;
- Workflow diagrams / WFDs;
- System context diagrams;
- Interface descriptions;
- Capability and service descriptions;
- Conceptual and logical architecture products;
- Testable acceptance criteria;
- Support the development of CIS capability designs, including hardware, software, network and security architecture considerations;
- Provide technical input on cyber monitoring technologies, including network monitoring, security monitoring, packet capture, sensor platforms, logging, telemetry collection, detection engineering, analytics platforms and supporting infrastructure;
- Support the identification, analysis and documentation of hardware requirements for CIS capabilities, including appliances, sensors, servers, storage, network taps, aggregation devices, packet brokers, virtualised infrastructure and supporting network components;
- Support the development of capability roadmaps, technical options papers, decision briefs and engineering recommendations;
- Support stakeholder management activities, including planning and facilitating technical workshops, requirements sessions, design reviews and coordination meetings;
- Work with customers and operational users to ensure that requirements are complete, realistic, technically feasible and aligned with NATO operational needs;
- Support the preparation of acquisition and procurement documentation, including Invitations for Bid, statements of work,
technical specifications, evaluation criteria and clarification
responses;
- Translate NATO technical and operational needs into language that can be understood by industry while preserving the required capability outcomes;
- Support purple team activities to validate monitoring capability effectiveness, including collaboration with red team, blue team, detection engineering and operational cyber defence stakeholders;
- Assist in identifying visibility gaps, detection opportunities and monitoring improvements based on adversary emulation, attack scenarios and operational use cases;
- Provide technical advice on cyber security architecture, monitoring architecture, system integration, tool configuration and operational improvements;
- Coordinate with project managers, system engineers, network engineers, security architects, operational teams, industry representatives and other stakeholders to ensure successful delivery of cyber capabilities;
- Support handover to operations, including knowledge transfer, training support and preparation of operational documentation;
- Participate in technical meetings, reviews, workshops and coordination activities with NATO, national and industry stakeholders
Essential Skills, Experience and Certifications
- At least 5 years of practical experience in cyber security, systems engineering, CIS engineering, capability development or a related technical field;
- Strong engineering experience across the capability lifecycle, from requirements development through design, integration, testing, validation, acceptance and transition to operations;
- Proven experience developing technical requirements, system specifications, use cases, state diagrams, workflow diagrams, operational scenarios and other engineering artefacts;
- Demonstrated experience working with customers and stakeholders to solicit, analyse, prioritise and document technical and operational requirements;
- Experience supporting or developing procurement documentation, including Invitations for Bid, statements of work, technical specifications, compliance matrices and technical evaluation criteria;
- Proven ability to translate complex customer needs and operational requirements into clear, structured and industry-understandable technical documentation;
- Strong background in cyber security, including familiarity with cyber defence operations, monitoring concepts, detection capabilities and security operations environments;
- Strong understanding of CIS monitoring capabilities, including the deployment and integration of monitoring tools, sensors, appliances, network capture platforms, log collection, telemetry, analytics and supporting infrastructure;
- Strong hardware background relevant to CIS and cyber monitoring environments, including servers, storage, network devices, security appliances, packet capture systems, taps, aggregation devices and associated infrastructure;
- Working knowledge of routing, switching, network segmentation, firewalls, virtualisation and enterprise infrastructure;
- Experience with problem analysis and resolution in complex systems and services, including the development and implementation of corrective or preventative measures;
- Experience coordinating technical work with project managers, engineers, security architects, operational users and industry teams;
- Practical experience with cyber security tools, monitoring platforms, SIEM or security analytics technologies is highly desirable;
- Experience with purple team activities, including adversary emulation, detection validation, cyber exercise support, collaboration between offensive and defensive teams, or validation of monitoring effectiveness;
- Experience in the delivery of technologies, systems, solutions or capabilities for industry, government, defence or military organisations;
- Experience with implementation projects within NATO and/or national military organisations is desirable;
- Experience supporting deployment or operation of technical capabilities in operational military environments is desirable;
- Ability to work independently and as part of a team to achieve agreed objectives;
- Ability to monitor, coordinate and support work performed by industry teams;
- Excellent communication and technical writing skills in English.
- Skills:
- Very good communication and analytical skills.
- Language proficiency in English: meet or exceed the NATO STANAG 6001 Level 3 "Professional Proficiency".
- Desirable Experience:
- Experience in working for or supporting a military or governmental organization.
- Education:
- A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience;
- Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work.
Working Location
- Mons, BE
Working Policy
- On-site
Travel
- Some travel to other NATO sites may be required
Security Clearance
- Valid National or NATO Secret personal security clearance