412,234open jobs
14,465companies
72,289added this week
Browse all
Salary
$75k – $183k per year (Estimated)
Location
In office (Mons)
Seniority
Staff · 10+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Spektrum Group is a management consultancy and strategic advisory firm specializing in the defense, aerospace, government, and humanitarian sectors. The enterprise provides professional advisory, technology integration, supply chain management, market entry support, and specialized consulting services for apex purchasers -including NATO, the UN, EU, and national defense ministries - and their Tier 1 supplier ecosystem. Headquartered in Barcelona, Spain, it leverages a global network of subject matter experts to help organizations navigate complex international institutional markets.

Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.

Who we are supporting  

The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.

The NCIA provides a wide range of services, including:

  • Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.
  • Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.
  • Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
  • Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.
  • Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers.

Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities.

The program

Assistance and Advisory Service (AAS)

The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.

To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.

Role ID -C005302

Role Duties and Responsibilities

Under the direction of the Section Head of the CSIRT, the contractor shall:

  • Provision 24/7 Cyber Security Incident Response (Triage, Contain, Eradicate, Recover) activities, during normal working hours and occasional on-call duties, including weekends and holidays
  • Deliver technical coordination, support, and assistance in respect of Cyber Security Incident Response to NATO CIS Operating Authorities, including but not limited to: NATO Nations, Partner Nations, non-Governmental Organisations and Industry Partners.
  • Lead, be a member of, or support Cyber Security Response Teams designated to extend the NCSC Incident Response coverage to one or multiple physical locations, including within the NATO Alliance Operations and Missions.
  • Build, manage the lifecycle of, and maintain the taxonomy related to the Branch's information.
  • Manage the content of different information portals within the agreed taxonomy.
  • Design, create and distribute a variety of reports, briefings and dashboards, to different communities, including: (Business owners, operational community, IT service management, cyber security)
  • Maintain a network of cyber security peers across and beyond the NATO Enterprise to facilitate communications and coordination of urgent actions when the need arises.
  • Research and identify, document and implement improvements to the Incident Response activities, in order to enhance and optimise current best practice to meet new and developing threats.
  • Produce Standard Operating Procedure and Instructions covering all aspects of Incident Response.
  • 1Participate in, and act as an Incident Response subject matter expert, in various meetings: within the CSIRT, across the sections in the Defend branch, across the NATO Enterprise, including within the NICC, CMAWG, CRMG and other Enterprise-level meetings, as well as within the context of a Cyber Incident Task force.

Essential Skills, Experience and Certifications

  • At least 4 years practical experience in cyber security incident response, or a directly connected field such as network analysis, digital forensics, malware analysis or threat hunting. It is noted that Industry often separates responsibilities in such a way that personnel in these roles may also be performing incident response;
  • Comprehensive understanding of the principles of Computer and Communication Security, networking, and the vulnerabilities of modern operating systems and applications acquired through a blend of academic or professional training coupled with practical professional experience;
  • Recent practical, hands-on experience of Intrusion Detection and Incident Response (TRIAGE, Contain, Eradicate, Recover) in an enterprise-level Computer Emergency Response Team, ideally making use of the MITRE ATT&CK framework;
  • At least 3 years experience in Information and Knowledge Management, ideally in the field of Cyber Security
  • Experience in interfacing with IT Service Management

Desirable Skills, Experience, Education and Certifications

  • Hold a University degree in Cyber Security or IT Security-related discipline or Information Management and 3 years post-related experience;
  • Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work.
  • Practical experience working with, and/or formal research, of the use of AI/LLM within Cyber Security Defense (not from a red team / penetration testing perspective)
  • Practical experience in the management of vulnerabilities, from ingestion, scoring, assessing prioritization of, and potential impact to CIS
  • Hold relevant certifications such as Certified Information Systems Security Professional (CISSP), GCIH or GIAC/GCIM Security (this list is not exhaustive)
  • Hold a professional certification on IT Service Management.
  • In-depth knowledge of potential security event sources and their interpretation and analysis in support of the incident detection and handling processes
  • Practical hands-on experience in System and Network administration to include Network (TCP/IP) Engineering
  • Very good communication and analytical skills.
  • Knowledge of vulnerability assessment and scoring (CVSS, SSVC, CVD)
  • Relevant certifications in cyber security, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or GIAC Security.
  • Experience in working for or supporting a military or governmental organization.
  • Recent experience in a large organisational CERT, especially within the Incident Response Team.
  • Experience in actively contributing to industry recognized communities for incident response, such as FIRST.org.

Working Location

  • Mons, Belgium

Working Policy

  • Full time On-site
    • Occasional on-call duties after working hours, on weekends or holidays are required
    • In case of a major Cyber Security Incident, the incumbent may be required to work extended hours and on shifts, including nights and weekends, to provide a 24/7 Cyber Security Incident Response

Travel

  • Some travel to other NATO sites in Belgium may be required for in-person or department meetings. In such cases the contractor will be reimbursed for travel costs according to NATO regulations for traveling on NATO duty.
  • Each travel will be a maximum of 2 days lengths and happening no more than once per 2 months.

Security Clearance

  • Valid National or NATO Secret personal security clearance
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
412,234 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Mons
$93k – $184k per year (Estimated) • Remote • Full-Time • 6+ years exp
Python
Bash
Databases
Google BigQuery
BigQuery
AI/ML
LLM
DevOps
GCP
VMWare
Azure
AWS
Amazon EC2
Amazon CloudWatch
Cybersecurity
FortiGate
ISO 27001
Microsoft Defender
Microsoft Entra ID
Apply
$190k – $260k per year • Equity 0.2–0.4% • In office • Full-Time • 1+ year exp • San Francisco
JavaScript
AI/ML
LangChain
LLM
Anthropic
Frontend
Next.js
React.js
Design
Figma
Webflow
Management
Slack
Dropbox
Intercom
Apply
In office • Bachelor's Degree
Python
C
C
FFmpeg
AI/ML
CUDA Toolkit
Triton Inference Server
Embeddings
Multimodal AI
Function Calling
Computer Vision
VLM
TensorRT
PyTorch
LLM
RAG
CUDA
Triton
NVIDIA NeMo
Structured Outputs
DevOps
AWS
Docker
Robotics
GStreamer
Apply
$80k – $203k per year (Estimated) • Remote/Hybrid • Singapore
Apex
Apex
MuleSoft
AI/ML
LangChain
LlamaIndex
Vertex AI
LiteLLM
Portkey
AWS Bedrock
LLM
RAG
OpenAI
Anthropic
DevOps
Terraform
Ansible
GCP
Kong
Azure
ArgoCD
Jenkins
AWS
Docker
Kubernetes
Platform Engineering
Vector
GitHub
GitLab
Apply
$231k – $340k per year • Remote/Hybrid • Full-Time • 7+ years exp • San Francisco
Python
Java
Rust
C++
Databases
Apache Kafka
Kafka
AI/ML
Spark
AI Agents
Flink
LLM
OpenAI
Anthropic
Baseten
DevOps
Azure
Kubernetes
Service Mesh
Apply
$20k – $48k per year (Estimated) • In office • Secret • 2+ years exp
Apply
$47k – $103k per year (Estimated) • Remote • Secret • 5+ years exp
Apply
$47k – $103k per year (Estimated) • Remote • Secret • 5+ years exp
Apply
$54k – $143k per year (Estimated) • In office • Secret • 10+ years exp • Master's Degree
SQL
DevOps
Splunk
Apply
$49k – $124k per year (Estimated) • In office • Top Secret • 3+ years exp • Bachelor's Degree
Apply
$57k – $127k per year (Estimated) • Remote • Secret • 10+ years exp • Bachelor's Degree • Mons
Python
SQL
PowerShell
Databases
MS SQL
DevOps
Splunk
Terraform
Azure DevOps
Azure
CI/CD
Windows Server
Configuration Management
Bicep
Bitbucket
IAM
Cybersecurity
Microsoft Entra ID
Analytics
Power BI
Management
Confluence
Jira
SharePoint
Apply
$41k – $87k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Mons
Apply
$71k – $175k per year (Estimated) • In office • Top Secret • Full-Time • 10+ years exp • Bachelor's Degree • Mons
Python
PowerShell
Bash
DevOps
Ansible
Red Hat
Azure
Windows Server
Cybersecurity
Microsoft Defender
Least Privilege
Management
Confluence
Jira
Apply
$68k – $153k per year (Estimated) • In office • Secret • Full-Time • 5+ years exp • Bachelor's Degree • Mons
DevOps
Splunk
Kibana
Azure
AWS
Cybersecurity
Wireshark
Crowdstrike
Tcpdump
Snort
FortiGate
Microsoft Sentinel
Suricata
Zeek
SentinelOne
Microsoft Defender
Sysmon
Apply
$68k – $153k per year (Estimated) • In office • Secret • Full-Time • 5+ years exp • Bachelor's Degree • Mons
DevOps
Splunk
Kibana
Azure
AWS
Cybersecurity
Wireshark
Crowdstrike
Tcpdump
FortiGate
Microsoft Sentinel
Zeek
SentinelOne
Sysmon
Apply
See all jobs
This is one of many
412,234 more open roles from verified company boards, updated every day.