Senior Cyber Security Specialist 4
Main duties
The specialist will support NATO’s Cyber Enablement Service by:
- Gathering, analysing and documenting technical and operational requirements for cyber and CIS monitoring capabilities.
- Translating operational needs into engineering, system, functional and non-functional requirements.
- Producing engineering documentation such as:
- Requirements and system specifications
- Use cases, user stories and operational scenarios
- State, workflow and system-context diagrams
- Interface, capability and service descriptions
- Conceptual and logical architectures
- Testable acceptance criteria
- Supporting CIS capability design across hardware, software, networking and security architecture.
- Advising on monitoring technologies, including sensors, packet capture, SIEM, logging, telemetry, analytics and detection engineering.
- Defining hardware needs for servers, storage, appliances, taps, packet brokers, network devices and virtual infrastructure.
- Preparing roadmaps, options papers, decision briefs and engineering recommendations.
- Planning and facilitating workshops, requirements sessions, design reviews and stakeholder meetings.
- Supporting procurement documentation, including Invitations for Bid, statements of work, technical specifications, compliance criteria and clarification responses.
- Translating NATO requirements into clear, industry-understandable documentation.
- Supporting purple-team activities, adversary emulation and validation of monitoring and detection effectiveness.
- Identifying visibility gaps, detection opportunities and monitoring improvements.
- Coordinating work among project managers, engineers, security architects, operational teams and suppliers.
- Supporting operational handover, knowledge transfer, training and documentation.
Essential experience and knowledge
Candidates should have:
- At least five years of practical experience in cybersecurity, systems/CIS engineering, capability development or a related field.
- Strong experience across the full capability lifecycle: requirements, design, integration, testing, validation, acceptance and operational transition.
- Proven ability to create technical requirements, specifications, diagrams, use cases and operational scenarios.
- Experience gathering and prioritising requirements with customers and stakeholders.
- Experience preparing procurement and technical evaluation documentation.
- Strong cybersecurity and cyber-defence monitoring knowledge.
- Strong understanding of monitoring platforms, sensors, packet capture, logging, telemetry and analytics infrastructure.
- Relevant hardware expertise involving servers, storage, network equipment, security appliances, taps and aggregation devices.
- Working knowledge of routing, switching, segmentation, firewalls, virtualisation and enterprise infrastructure.
- Experience solving complex technical problems and developing corrective or preventive measures.
- Experience coordinating multidisciplinary technical teams and supplier activities.
- Excellent English communication, analytical and technical-writing skills.
- Ability to work independently and collaboratively.
Highly desirable experience
- SIEM, security analytics and cyber-monitoring tools.
- Purple teaming, adversary emulation, detection validation or cyber-exercise support.
- Delivering systems for government, defence, military or other operational organisations.
- NATO or national military implementation projects.
- Deployment or operation of technology in military environments.
- Previous work supporting a governmental or military organisation.
Education
Either:
- A bachelor’s degree in a related discipline plus at least three years of relevant post-degree experience; or
- At least ten years of extensive and progressive relevant experience where no university degree is held.
Working conditions and travel
- Normal office environment with NCIA equipment provided for restricted information.
- Remote work may be permitted for up to 20% of total working time, subject to prior approval.
- Home working within the duty location may be allowed under NCIA teleworking policy.
- Personal equipment may be required for public or unclassified remote work and Microsoft-based video meetings.
- Travel may be required within Belgium and to other NATO or mission locations.
- Approved NATO-duty travel is reimbursed under NATO regulations.
- Work travel must begin from the designated duty station.