DCO Tracking Suppor

Mons, Belgium Deadline: 22-09-2026 Geplaatst: 08-09-2026 #17524

Duties

  • Review vulnerability-assessment results weekly and assess their technical impact.
  • Prepare remediation plans for every assessment report.
  • Explain complex findings and support system administrators with remediation.
  • Prioritize vulnerabilities according to technical risk.
  • Provide weekly hardening guidance for operating systems, databases, and networks.
  • Design, build, and maintain a central relational database or structured repository for vulnerability-scan data.
  • Automate the ingestion and processing of scan results.
  • Develop and maintain Power BI or Grafana dashboards.
  • Produce visualizations and metrics for operational and management reporting.
  • Update databases, pipelines, and dashboards weekly.
  • Serve as the technical remediation contact for site administrators and system owners.
  • Track remediation progress and produce weekly and monthly stakeholder reports.
  • Chair technical coordination meetings and help resolve remediation roadblocks.
  • Coordinate and gather information across NCSC, NCIA, and other stakeholders.
  • Deliver a final closure report summarizing work performed.

Mandatory experience and knowledge

  • At least five years of practical vulnerability-management experience, including relevant work within the previous six months.
  • At least three years’ experience testing and validating that contracted deliveries satisfy security requirements and intended use cases.
  • Strong knowledge of cybersecurity principles, practices, technologies, and risk management.
  • Knowledge of security architectures covering:
    • Boundary protection
    • Encryption
    • Identity and access management
    • Monitoring and detection
    • Incident response
    • Vulnerability assessment
  • Practical experience with scanners such as Tenable Nessus, Qualys, or OpenVAS and their output formats.
  • Proven experience building data repositories and reporting pipelines for large volumes of security-scan data.

Required technical and professional skills

  • Strong SQL skills, such as PostgreSQL or Microsoft SQL Server, including data modelling and large-dataset management.
  • Advanced proficiency in either:
    • Microsoft Power BI, including data modelling and DAX; or
    • Grafana, including SQL connections and time-series visualization.
  • Python skills, particularly Pandas/NumPy, or PowerShell skills for parsing scan logs and automating data entry.
  • Ability to take ownership and complete tasks independently and collaboratively.
  • Very good communication, analytical, and writing skills.
  • English at NATO STANAG 6001 Level 3 or higher.

Education

Either:

  • A bachelor’s degree from a nationally recognized university in a related discipline, plus at least three years of relevant post-degree experience; or
  • At least ten years of extensive and progressive relevant experience demonstrating abilities of particular interest to NCIA.

Certifications

Relevant cybersecurity certifications are expected, such as:

  • CISSP
  • CISM
  • GIAC security certifications

The following are advantageous:

  • Microsoft Power BI Data Analyst Associate (PL-300)
  • Grafana Certified Professional
  • Other relevant data analytics or business-intelligence certifications

Desirable background

  • Familiarity with NATO security policies and supporting directives.
  • Experience working for or supporting a military or government organization.

Working conditions and deliverables

  • Work takes place in a Class II Security Area.
  • Standard hours:
    • Monday–Thursday: 08:30–17:30
    • Friday: 08:30–15:30
  • Regular remote work is unsuitable; occasional telework requires prior managerial approval and must follow NCIA policy.
  • NCIA will provide the required equipment, workspace, REACH laptop, and NATO-site access.
  • Deliverables must:
    • Use NCIA templates or an agreed format.
    • Be peer-reviewed.
    • Be stored under configuration management in NCIA tools.
  • Databases, pipelines, and dashboards must:
    • Run on NCIA-provided infrastructure.
    • Be fully documented.
    • Be maintainable independently by NCSC personnel.
  • The same contractor should perform the work throughout the engagement because continuity and knowledge of NATO/NCSC procedures are important.

Travel

  • Occasional travel may be required, mainly to Brussels for stakeholder meetings.
  • Expected frequency: no more than once per month.
  • Maximum duration: two days per trip.
  • Travel must begin from the designated duty station.

Reageren op aanvraag

Terug