Who we are:

For more than 70 years, NATO’s mission has been to preserve peace and security in the Alliancefor nearly one billion citizens. The NATO Communications and Information Agency (NCIA) and its predecessors have worked tirelessly in providing the means that enable the connectedness and togetherness that keep our Alliance strong. We are the NCIA, a team of 3000 civilian and military staff in 29 locations throughout Europe, North America and Asia.

Our technology and cyber experts allow NATO to conduct critical operations, protect NATO’s airspace, make data-driven decisions, defend against cyber-attacks, secure NATO networks and maintain superiority in space. This is all possible because of our greatest force, our people. In order to keep this edge we aim to hire, train and retain the very best staff.

Our staff members represent both the diversity and unity of our Alliance. When you join the NCIA, you will be part of an organization where you can contribute authentically to the mission and purpose of NATO and help us keep our technological edge.

About the job:

Based in Mons, Belgium, you will join the Agency as we embark on a journey to transform our IT services to support NATO’s Digital Endeavour. You will join NATO Cyber Security Centre (NCSC), which is responsible for planning and executing all lifecycle management activities for cyber security. In executing this responsibility, NCSC provides specialist cyber security-related services covering the spectrum of scientific, technical, acquisition, operations, maintenance, and sustainment support, throughout the lifecycle of NATO Communications and Information Systems (CIS).

The NCSC is part of the nucleus of the NATO Integrated Cyber Defence Centre (NICC).

We are looking for a driven and enthusiastic Red Team Technical Lead who will take on the following roles and responsibilities:

  • Lead and coordinate the design, development, and operation of red team infrastructure and R&D capabilities in direct support of red team operations;

  • Collaborate with Red Team Operator Leads to tailor infrastructure and tooling to mission needs;

  • Ensure operational security for the deployed infrastructure;

  • Manage Red Team research and development activities with the goal of developing and utilizing automation, custom tools, scripts, and malware to replicate sophisticated cyber threats and evade detection mechanisms;

  • Advise and mentor team members, and continuously evolve capabilities to reflect real-world threat actors and emerging technologies;

  • Maintain documentation and secure configurations for repeatable operations;

  • Provide and maintain red team operation infrastructure, offline automation and technical assistance (AI), C2, payloads;

  • Oversee the management and development of cyber range capability in support of operation / R&D.

For a full list of duties, please review the job description on the NCIA career site.

Note that internally the job title is Principal Cyber Security Infrastructure Specialist.

About you:

The valuable knowledge and experience that you bring to this role are:

  • A Master’s degree at a nationally recognised/certified University in a related discipline and 5 years post-related experience. Or a Bachelor’s degree with 8 years post related experience;

  • Cybersecurity oriented certification such as CRTP, GPEN, GWAPT, OSCP, OSCE, OSEE, GXPN, Red team operator related certification, GREM;

  • At least 5 years practical experience working in cybersecurity field (security analyst/engineer, vulnerability researcher, penetration testing, red teaming, security architect);

  • In-depth knowledge of adversary emulation, red teaming and purple teaming;

  • Understanding of tactics, techniques and procedures of threat actors based on MITRE ATT&CK Framework;

  • Understanding of the various types of detections available (defence in depth) and how to bypass them;

  • Ability to create and use custom tools to automate and optimize red team engagements;

  • Technical knowledge in system and network security, authentication and security protocols, cryptography and application security;

  • Proven experience leading interdisciplinary teams, preferably in international environment;

  • Knowledge of vulnerability assessment and penetration testing methodologies;

  • Proficiency in Red team tools and technologies;

  • Knowledge of the latest security trends and best practices;

  • Excellent communication and negotiation skills across technical, non-technical and Executive audience;

  • Strong analytical and problem-solving skills, with the ability to make data-driven decisions;

  • Fluency in English, both written and spoken.

What we offer:

  • Genuinely meaningful work as part of the most successful alliance in history;

  • 5 year contract with competitive tax-free salary and household and children’s allowances;

  • Privileges for expatriate staff including expatriation and education allowances (where appropriate) and additional home leave;

  • Excellent private health insurance scheme;

  • Generous annual leave of 30 days plus official holidays;

  • NATO Pension Scheme;

  • Development programs such as professional training, wellbeing, and more.

To learn more about NCIA and our work, please visit our website.

The NCIA prides itself on being an equal opportunity employer. We are committed to fostering an inclusive environment of mutual respect and value uniqueness and differences in gender, gender identity, race, ethnic or cultural origin, age, religion, sexual orientation and physical or neurocognitive ability.

Additional details on the conditions of application can be found via the NCIA career site.


At Impactpool we do our best to provide you the most accurate info, but closing dates may be wrong on our site. Please check on the recruiting organization's page for the exact info. Candidates are responsible for complying with deadlines and are encouraged to submit applications well ahead.
Before applying, please make sure that you have read the requirements for the position and that you qualify. Applications from non-qualifying applicants will most likely be discarded by the recruiting manager.