Who we are:
For more than 70 years, NATO’s mission has been to preserve peace and security in the Alliancefor nearly one billion citizens. The NATO Communications and Information Agency (NCIA) and its predecessors have worked tirelessly in providing the means that enable the connectedness and togetherness that keep our Alliance strong. We are the NCIA, a team of 3000 civilian and military staff in 29 locations throughout Europe, North America and Asia.
Our technology and cyber experts allow NATO to conduct critical operations, protect NATO’s airspace, make data-driven decisions, defend against cyber-attacks, secure NATO networks and maintain superiority in space. This is all possible because of our greatest force, our people. In order to keep this edge we aim to hire, train and retain the very best staff.
Our staff members represent both the diversity and unity of our Alliance. When you join the NCIA, you will be part of an organization where you can contribute authentically to the mission and purpose of NATO and help us keep our technological edge.
About the job:
Based in Mons, Belgium, you will join the Agency as we embark on a journey to transform our IT services to support NATO’s Digital Endeavour. You will join NATO Cyber Security Centre (NCSC), which is responsible for planning and executing all lifecycle management activities for cyber security. In executing this responsibility, NCSC provides specialist cyber security-related services covering the spectrum of scientific, technical, acquisition, operations, maintenance, and sustainment support, throughout the lifecycle of NATO Communications and Information Systems (CIS).
The NCSC is part of the nucleus of the NATO Integrated Cyber Defence Centre (NICC).
We are looking for driven and enthusiastic Red Team Operators who will take on the following roles and responsibilities:
Participate to the planning, design, and execution of red team engagements that simulate adversarial tactics, techniques and procedures against enterprise systems, covering network, applications and cloud domains;
Conduct reconnaissance, open-source intelligence (OSINT) gathering, vulnerability scanning, exploitation, lateral movement, persistence installation, and command & control management during offensive security operations;
Perform research and development activities with the goal of developing and utilizing custom tools, scripts, and malware to replicate sophisticated cyber threats and evade detection mechanisms;
Perform social engineering and phishing campaigns to assess the effectiveness of human and process defences;
Create clear and actionable reports for both technical teams and executive stakeholders.
Note that internally the job title is Cyber Security Assessor.
We have two different roles available:
Principal Cyber Security Assessor (G20) - for a full list of duties, please review the job description on the NCIA career site. The pay scale is 9604.83 EURO/ month.
Senior Cyber Security Assessor (G17) - for a full list of duties, please review the job description on the NCIA career site; The pay scale is 8,273.12 EURO/ month.
About you:
The valuable knowledge and experience that you bring to this role are:
A Master’s degree at a nationally recognised/certified University in a related discipline and 5 years post-related experience or a Bachelor’s degree with 8 years post related experience (for the G20 role) OR A Bachelor’s degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience (for the G17 role). Exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate’s particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to the function of the post;
Cybersecurity oriented certification such as GRTP, GPEN, GWAPT, OSCP, OSCE, OSEE, GXPN, Red team operator related certification, GREM;
At least 5/3 years practical experience working in cybersecurity or a related field, such as information technology, network administration, or software development;
Extensive knowledge and experience (at least 5/3 years) in the following areas:
üWeb application penetration testing;
üIT infrastructure penetration testing;
üNetwork security architecture design;
üAssessing security vulnerabilities within OS, software, protocols & networks;
üResearching and evaluating security products & technologies;
üKnowledge in system and network administration of UNIX and Windows systems;
üUse of penetration testing tools, techniques, and recognized testing methodologies;
üScripting skills in at least one of the following: Perl, Python, Ruby, shell (bash, sh).
Relevant practical experience identifying vulnerabilities and discovering potential 0days;
Proven experience in penetration testing, adversary emulation or Red teaming for at least 3 years;
Understanding of the principles of adversary emulation;
Understanding of tactics, techniques and procedures of threat actors based on MITRE ATT&CK Framework;
Ability to create and execute custom scripts to simulate attack activities;
Understanding of the various types of detections available (defence in depth) and how to bypass it;
Knowledge of the latest security trends and best practices;
Ability to create and use custom tools to automate and optimize red team engagements;
Experience with security testing tools and methodologies, such as fuzzing, static and dynamic application security testing, and penetration testing;
Use of penetration testing tools, techniques, and recognized testing methodologies;
Technical knowledge in system and network security, authentication and security protocols, cryptography and application security;
Proven ability to write clear and structured technical reports including executive summary, technical findings and remediation plan for several different audiences;
Fluency in English, both written and spoken.
What we offer:
Genuinely meaningful work as part of the most successful alliance in history;
5 year contract with competitive tax-free salary and household and children’s allowances;
Privileges for expatriate staff including expatriation and education allowances (where appropriate) and additional home leave;
Excellent private health insurance scheme;
Generous annual leave of 30 days plus official holidays;
NATO Pension Scheme;
Development programs such as professional training, wellbeing, and more.
To learn more about NCIA and our work, please visit our website.
The NCIA prides itself on being an equal opportunity employer. We are committed to fostering an inclusive environment of mutual respect and value uniqueness and differences in gender, gender identity, race, ethnic or cultural origin, age, religion, sexual orientation and physical or neurocognitive ability.
Additional details on the conditions of application can be found via the NCIA career site.