Type 3 Security Audit Remediation Support Engineer
Main Responsibilities
The engineer will be responsible for vulnerability assessment, remediation and coordination across NATO/NCIA sites.
- Analyse vulnerability assessment results and identify security findings.
- Create remediation action plans within 2 working days of receiving assessment reports.
- Provide technical remediation guidance to system administrators.
- Assess the technical impact and severity of vulnerabilities and help prioritise remediation.
- Monitor newly disclosed vulnerabilities and support the preparation of NATO Security Bulletins.
- Track remediation progress for all open vulnerabilities.
- Act as the technical point of contact for remediation with site administrators and system owners.
- Coordinate remediation activities across multiple sites.
- Produce weekly and monthly remediation status reports.
- Lead technical coordination meetings and resolve remediation blockers.
- Present remediation progress during the monthly Enterprise Vulnerability Assessment Plan (EVAP) meeting.
- Coordinate with NCSC, NCIA and NATO stakeholders.
- Produce a final remediation/closure report.
Requirements
Essential:
- 5 years of practical vulnerability management experience
- Must have relevant vulnerability management experience within the last 6 months.
- 3 years of experience testing and validating security requirements and contracted deliveries.
- Hands-on experience with vulnerability scanners such as:
- Tenable Nessus
- Qualys
- OpenVAS
- Proven experience creating remediation action plans.
- Experience coordinating remediation with system administrators across multiple sites.
- Strong understanding of:
- Cybersecurity principles
- Security architectures
- IAM
- Encryption
- Boundary protection
- Monitoring & detection
- Incident response
- Vulnerability assessment
- Risk management
Technical Skills
- Ability to understand complex vulnerability findings and turn them into practical remediation instructions.
- Python with Pandas/NumPy or PowerShell.
- Ability to parse vulnerability scan results and automate data handling.
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication.
- Able to work independently and take ownership of tasks.
Education
Either:
- Bachelor's degree in a relevant field 3 years post-related experience
OR, exceptionally:
- No university degree but 10 years of extensive and progressive relevant experience.
Certifications — Desirable
- CISSP
- CISM
- GIAC
Additional Advantages
- Previous experience with NATO security policies and directives.
- Experience working with or supporting a military or government organisation.
- Previous NATO/NCIA/NCSC experience would obviously be highly relevant.