• Function title: Cyber Security Expert
  • Reference: NOC-MA-2026-AD/1156
  • Location: Maastricht
  • In accordance with the Service Regulations, staff are required to reside either at their place of employment or at such distance from it as is compatible with the proper performance of their duties.
  • Information about living in Maastricht
  • Nature of competition: Internal and external competition
  • Applicable regulations: General conditions of employment governing servants at the EUROCONTROL Maastricht Centre
  • Type of post: Administrator
  • Job level: AD6-AD9 - Check salary simulations for the basic grade
  • Generic job title: Expert
  • Number of posts: 1
  • Duration of appointment: 5 Year(s) - renewal or conversion of the contract is possible under certain conditions see “Useful information” section
  • Security clearance: Security vetting may be required in accordance with the relevant EUROCONTROL security provisions
  • Directorate/Service: MUAC/SQCS/CS - The Corporate Security Team
  • Working arrangement: EUROCONTROL operates a hybrid working model, combining onsite presence with teleworking opportunities. Teleworking is subject to the applicable internal rules and is granted in line with business needs and managerial approval.
    Teleworking must not exceed 50% of the days worked in a month when performed at the official place of residence as defined above.
    In addition, all staff may telework from a location of their choice for up to 20 working days per calendar year, with line manager authorisation. These 20 days do not count towards the 50% monthly limit.
  • Competition publication date: 10/09/2026
  • Competition closing date: 08/10/2026 (23:59 Brussels time)
  • Reserve list: Applicable - See details in the "Useful information" section

Your team

Within the The Directorate Maastricht Upper Area Control Centre, The Safety, Quality, Compliance and Security Management (SQCS) unit manages MUAC's safety, quality, compliance and security processes. The unit is also responsible for the overall management of the integrated MUAC Management System including the assurance of its effective and efficient operation. Furthermore, the MUAC Security Operations Center (SOC) is part of SQCS.

Your role

Your role will be to:

  • Provide technical expertise, guidance and contributions to the definition of security requirements, the development and the execution of security-related policies, procedures, and action plans to ensure the protection of mission critical networks, systems and services, on site and/or in the cloud. 
  • Contribute to the development of methods, tools, and guidance to support a harmonised approach to security management, ensuring alignment with the regulatory framework and international standards. 
  • Solve cyber security incidents, participate in crisis management activities, and ensure the organisation is prepared to handle emergencies effectively. 
  • Audit and monitor the effectiveness of security measures and service providers, ensuring compliance with internal policies and external regulations. 
  • Collaborate with internal teams on cyber security and serve as a subject matter expert to advise management and stakeholders on cyber security issues, including regulatory compliance and operational impact. 
  • Conduct security (risk) assessments, including critical supplier risk assessments, analyse vulnerabilities and identify solutions and corrective actions, and report on findings. Conduct activities addressing fraudulent cyber activities affecting the Agency as well as stakeholders. 
  • Monitor and analyse the aviation cyber threat landscape, conduct cyber threat intelligence (CTI) analyses and produce CTI reports. 
  • Provide technical oversight on the effectiveness of cyber security related controls and tools and identify potential technical and procedural gaps for further development and/or enhancements.   
  • Develop the content of training programs and deliver courses providing guidance and support in cyber security. Develop and deliver security awareness related activities. 
  • Collaborate with internal and external partners, and participate to events, workshops, meetings, etc and projects to share expertise and contribute to initiatives in cyber security.   
  • Produce and/or contribute to technical documents to document analyses, findings and recommendations.  
  • Contribute to tender specifications and evaluation of offers. Monitor contracts’ performance, identifying issues and ensuring adherence to contractual requirements. 
  • Stay updated on latest technological developments/methods/best practices/trends and share them within the internal community to enhance organisational knowledge.  
  • Carry out any other task in line with the main purpose of the job.

Required qualifications, experience & competencies

  • Completion of relevant third level studies (IT and/or security studies), meeting European Qualifications Framework (EQF) Level 6 followed by at least 4 years relevant professional experience to carry out the advertised responsibilities.
  • Completion of relevant third level studies (IT and/or security studies) meeting EQF Level 7 followed by at least 3 years relevant professional experience to carry out the advertised responsibilities.
  • Internal candidates can check on the intranet to see what level of in-house experience is considered equivalent to educational qualifications where appropriate.
  • Experience in conducting cyber security risk assessments, including threat and vulnerability analysis, control evaluation, risk treatment definition, and reporting of findings.
  • Experience in analysis of technical systems, applications, and architectures from a security and risk perspective, and identify weaknesses, attack paths, and mitigating controls.
  • Knowledge of governance, risk and compliance frameworks, including the practical application of standards and regulatory requirements such as ISO 27001, NIST CSF (National Institute of Standards and Technology Cybersecurity framework), CIS (Center for Internet Security), or equivalent.
  • Hands-on cyber security expertise in one or more cybersecurity domains such as penetration testing, incident response, secure coding or application security.
  • Technical drafting skills in English.
  • Quality focus: You set and foster high-quality standards.
  • Influencing: You tailor style and approach to impact others.
  • Problem solving: You anticipate and solve business issues.
  • Communication: You are able to foster two-way communication.
  • Analytical thinking: You analyse information and are able to identify relationships.
  • Ability to work in a multinational and multicultural environment.
  • Professional conduct in line with the corporate behaviours of the Agency, i.e. result-driven, readiness to change, customer focus, integrity and team-player approach.
  • The working languages of the Agency are English and French. For this particular job, candidates must be proficient users of English at level C1. The levels relate to the Common European Framework of References for languages (CEFR).

Useful information

  • Applications will be accepted from nationals of EUROCONTROL Member States only.
  • The selected candidate may be required to provide documentary evidence confirming they meet the minimum education requirements. They will be informed if and when specific evidence is needed. Please note that no offer (for external candidates) or appointment (for internal candidates) will be made until the necessary evidence, if required, is validated.
  • The selected candidate will be appointed in accordance with the provisions of the General conditions of employment governing servants at the EUROCONTROL Maastricht Centre. This appointment may be renewed several times, but its total duration, including all renewal periods, may not exceed nine (9) years. A conversion to an undetermined duration appointment is possible where all of the following cumulative conditions are met: the post is confirmed as being of a lasting nature; the staff member has completed at least five years of service; the staff member’s performance has been satisfactory; and the conversion is in the interests of the service. Conversion is therefore not automatic.
  • Conditions depending on current type of engagement
    Internal staff appointed for a determined period
    • Retain their current type of appointment duration.
    • Continue under their existing appointment duration, as appointment durations are not cumulative.
    • The duration of their appointment will therefore not restart upon selection to the new post, i.e. the remaining duration of their current determined appointment continues to apply.
    • Renewal(s): This appointment may be renewed several times, but its total duration, including all renewal periods, may not exceed nine (9) years.
    • Conversion: Conversion to an undetermined duration appointment is possible where all of the following cumulative conditions are met: the post is confirmed as being of a lasting nature; the staff member has completed at least five years of service; the staff member’s performance has been satisfactory; and the conversion is in the interests of the service. Conversion is therefore not automatic.
    Internal staff appointed for an undetermined period
    • Retain their current type of appointment duration.
    At the end of the 5 Year period of the post for which they were selected:
    • If the assignment is extended, they will continue in the post in accordance with the applicable rules.
    • If the assignment is not extended and/or the duties are not confirmed as being of a lasting nature, they will be transferred to another post corresponding to their “previous” type of post, job level, and function group.
  • The selected candidate must successfully complete a probationary period of nine (9) months before being established in the post.
  • The selected candidate shall be appointed at the grade set out in this vacancy notice, or if a group of grades has been published for a job level, in principle at the basic grade of the published job level.
  • Candidates declared suitable who are not selected for the post will be placed on a reserve list for similar roles. The reserve list will be valid for one year from the closing date of applications.
  • Information on salary and benefits can be found on our Careers site
  • EUROCONTROL is an equal opportunities employer. We are committed to equality and diversity. In the event of equal merit, preference may be given to the applicant from the under-represented diversity characteristics in order to complement diversity of teams and rebalance the workforce.
  • Candidates should go to our Careers site and .

At Impactpool we do our best to provide you the most accurate info, but closing dates may be wrong on our site. Please check on the recruiting organization's page for the exact info. Candidates are responsible for complying with deadlines and are encouraged to submit applications well ahead.
Before applying, please make sure that you have read the requirements for the position and that you qualify. Applications from non-qualifying applicants will most likely be discarded by the recruiting manager.