RFQ C004731 Cyber Security Assessor (Vulnerability Assessment)
Requirements Description
The contracted individual will support the development of one or more technical deliverables. They must be capable of working effectively and efficiently with minimal supervision.
- Frequent travel to NATO and national (NATO and non-NATO) facilities is required.
- Duties are performed within government or military installations, adhering to strict security protocols and operational requirements.
- The position is primarily on-site, with very limited opportunities for teleworking.
Duties & Role
The individual will be responsible for:
- Planning and executing technical On-site CIS Security Audits (Type-3) for networks, systems, and applications, ensuring accuracy of results
- Analysing collected assessment data to identify security weaknesses
- Writing detailed Security Audit reports with findings and recommendations
- Delivering briefings and supporting remediation and mitigation efforts
- Contributing to the development of in-house tools for data collection and analysis
- Performing additional duties as required
Skills, Knowledge & Experience
The ideal candidate must have extensive knowledge and experience (3 years, except AI) in the following areas:
Core Security & Networking
- Strong understanding of computer and communications security, enterprise networking, and system vulnerabilities
- Ability to assess security controls aligned with best practices (e.g., Zero Trust Architecture, Data-Centric Security)
- Expertise in executing vulnerability scans across large, complex networks without affecting performance
Tools & Technical Expertise
- Hands-on experience with Tenable Nessus, including advanced configuration and customization
- Proficiency in developing and deploying Nessus audit files for compliance checks
- Strong knowledge of Active Directory security configurations and vulnerabilities
Cloud & Modern Infrastructure
- Advanced knowledge of:
- Microsoft Azure AD / Entra ID / Office 365
- AWS Cloud Security
- Experience securing hybrid and cloud environments
- Familiarity with DevSecOps practices and CI/CD security integration
Systems & Security Implementation
- Experience with:
- System hardening and endpoint protection
- Antimalware configurations
- Ability to benchmark systems against standards (e.g., CIS Benchmarks, NIST)
Advanced & Emerging Technologies
- Applied expertise in Artificial Intelligence, including assessing Large Language Models (LLMs)
- Proficiency in securing Ansible deployments
- Expertise in:
- Software Defined Networking (SDN)
- Service-Oriented Architecture (SOA)
- Ability to integrate modern architectures with enterprise security frameworks
Automation & Scripting
- Strong scripting skills (PowerShell, Python, Bash)
- Ability to create repeatable workflows and checklists to improve efficiency and reduce errors
Communication & Collaboration
- Excellent communication skills:
- Briefing senior stakeholders
- Delivering presentations
- Producing high-quality reports
- Leading technical discussions
- Strong interpersonal skills with proven ability to work:
- Independently
- Within multidisciplinary teams