Cyber Security Incident Responder

Mons, Belgium Deadline: 15-09-2026 Posted: 01-09-2026 #17468

Duties

  • Provision 24/7 Cyber Security Incident Response (Triage, Contain, Eradicate, Recover) activities, during normal working hours and occasional on-call duties, including weekends and holidays.
  • Deliver technical coordination, support, and assistance in respect of Cyber Security Incident Response to NATO CIS Operating Authorities, including but not limited to: NATO Nations, Partner Nations, non-Governmental Organisations and Industry Partners.
  • Lead, be a member of, or support Cyber Security Response Teams designated to extend the NCSC Incident Response coverage to one or multiple physical locations, including within the NATO Alliance Operations and Missions.
  • Build, manage the lifecycle of, and maintain the taxonomy related to the Branch's information.
  • Manage the content of different information portals within the agreed taxonomy.
  • Design, create and distribute a variety of reports, briefings and dashboards, to different communities, including: (Business owners, operational community, IT service management, cyber security).
  • Maintain a network of cyber security peers across and beyond the NATO Enterprise to facilitate communications and coordination of urgent actions when the need arises.
  • Research and identify, document and implement improvements to the Incident Response activities, in order to enhance and optimise current best practice to meet new and developing threats.
  • Produce Standard Operating Procedure and Instructions covering all aspects of Incident Response.
  • Participate in, and act as an Incident Response subject matter expert, in various meetings: within the CSIRT, across the sections in the Defend branch, across the NATO Enterprise, including within the NICC, CMAWG, CRMG and other Enterprise-level meetings, as well as within the context of a Cyber Incident Task force.
  • In case of a major Cyber Security Incident, the incumbent may be required to work extended hours and on shifts, including nights and weekends, to provide a 24/7 Cyber Security Incident Response.
  • The contractor may be required to travel to NCIA locations in Belgium for in-person or department meetings.

Requirement

  • At least 4 years practical experience in cyber security incident response, or a directly connected field such as network analysis, digital forensics, malware analysis or threat hunting.
  • Comprehensive understanding of the principles of Computer and Communication Security, networking, and the vulnerabilities of modern operating systems and applications acquired through a blend of academic or professional training coupled with practical professional experience.
  • Recent practical, hands-on experience of Intrusion Detection and Incident Response (TRIAGE, Contain, Eradicate, Recover) in an enterprise-level Computer Emergency Response Team, ideally making use of the MITRE ATT&CK framework.
  • At least 3 years experience in Information and Knowledge Management, ideally in the field of Cyber Security.
  • Experience in interfacing with IT Service Management.
  • Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work.
  • Relevant certifications in cyber security, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or GIAC Security.
  • A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience.

Preferences

  • Hold a University degree in Cyber Security or IT Security-related discipline or Information Management.
  • Practical experience working with, and/or formal research, of the use of AI/LLM within Cyber Security Defense (not from a red team / penetration testing perspective).
  • Practical experience in the management of vulnerabilities, from ingestion, scoring, assessing prioritization of, and potential impact to CIS.
  • Hold relevant certifications such as Certified Information Systems Security Professional (CISSP), GCIH or GIAC/GCIM Security (this list is not exhaustive).
  • Hold a professional certification on IT Service Management.
  • In-depth knowledge of potential security event sources and their interpretation and analysis in support of the incident detection and handling processes.
  • Practical hands-on experience in System and Network administration to include Network (TCP/IP) Engineering.
  • Experience in working for or supporting a military or governmental organization.
  • Recent experience in a large organisational CERT, especially within the Incident Response Team.
  • Experience in actively contributing to industry recognized communities for incident response, such as FIRST.org.

Apply for this position

Back