LOGO_ALLIED4_RVBLOGO_ALLIED4_RVBLOGO_ALLIED4_RVBLOGO_ALLIED4_RVB
  • ABOUT US
  • MISSION & VALUES
  • CONSULTANTS
  • OPPORTUNITIES
  • BUSINESS TO BUSINESS
  • CONTACT US
✕
DEADLINE: allied4eu March 30, 2025

#C25CSG178348 - CYBERSPACE OPERATIONS INCIDENT ANALYSIS - Closed

 Deadline: March 30, 2025

Requester: NATO

Location: Mons, Belgium

Job type: Contractor

Start date: May, 2025 

Security clearance: NATO SECRET or above

SCOPE OF WORK / DUTIES / ROLES

The aim of this SOW is to support NCSC with technical expertise specifically related to the Cyber Security Incident Detection.  

The following activities are expected to be performed under this SOW:

  • Conduct detailed investigation and research of security events within NATO Cyber Security Centre (NCSC) team:

- Analyse firewall, IDS, anti-virus and other sensor-produced system security events and present findings;

- Leverage the comprehensive extended toolset (e.g. Log Collection, Intrusion Detection, Packet Capture, VA, Network Devices etc.) to identify malicious activity;

- Triage, analysis and response to alerts;

- Deliver the analysis and reports in response to tasks associated with ongoing investigations and incidents.

  • Develop new Splunk alerts, searches and reports for security monitoring and detection:

- Identify security gaps in NATO infrastructure, develop, update and review custom content utilising available toolset;

- Propose possible optimisations and enhancements, which help to maintain and improve NATO’s Cyber Security posture. 

  • Collaborate with threat intelligence teams to incorporate threat indicators into detection systems:

- Work closely with the threat intelligence team to integrate the latest Indicators of Compromise (IOCs) and attack techniques into the detection environment;

- Implementation of at least 3 new threat intelligence-driven detections per quarter to stay ahead of emerging threats. 

  • Develop and maintain standard operating procedures (SOPs) and playbooks for incident detection and response:

- Ensure documentation is up-to-date and provides clear guidance for responding to common attack scenarios;

- Delivery of updated SOPs and playbooks quarterly, ensuring they reflect the latest threat landscape and detection capabilities.

  • Produce briefings in Microsoft PowerPoint or Word format to provide detailed technical reports in support of incidents and capability improvements. Report and/or briefing for the management team containing details on the detection capabilities, scope, and details. This may be requested in either Word, PowerPoint, or both depending on the briefing. 
  • Review reports and observables from threat hunting, red teaming, and purple teaming activities.  Detection gap analysis and recommendations for solutions, subsequently leading on the development, testing and implementation;
  • Brainstorm during weekly meetings with the rest of the Monitoring and Detection Team how to improve detection capability to increase detection coverage. Participation in meetings as reported and tracked in the meeting minutes which need to be prepared before the meeting and updated during the meeting (Confluence). 
  1.  
REQUIRED SKILLS, KNOWLEDGE AND EXPERIENCE

Delivery of the services within this SOW requires a contractor with the following qualifications and experience:

  • Bachelor's degree in Computer Science, Information Technology, or related field Or equivalent experience;
  • 3+ years of experience in IT security, with a focus on System Administration, Security Tools Management in large organisations;
  • Strong understanding of security best practices;
  • Expert level in at least three of the following areas and a high level of experience in several of the other areas:  

- Security Incidents Event Management products (SIEM) – e.g. Splunk.  

- Network Based Intrusion Detection Systems (NIDS) – e.g. SourceFire, Palo Alto Network Threat Prevention.  

- Host Based Intrusion Detection Systems (HIDS).  

- Full Packet Capture systems – e.g. Niksun, RSA/NetWitness.  

- A variety of Security Event generating sources (e.g. Firewalls, IDS, Routers, Security Appliances). o Cloud-specific security tools.  

- Splunk ES suite and Phantom SOAR.

  • Proficiency in Intrusion/Incident Detection and Handling;
  • Expert knowledge of malware families, network attack vectors and threat actor tools, techniques and procedures;
  • Experience in endpoint detection and analysis techniques;
  • Expert knowledge of the principles of computer and communications security, networking, and the vulnerabilities of modern operating systems and applications;
  • Comprehensive knowledge of the principles of computer and communications security, networking, and the vulnerabilities of modern operating systems and applications;
  • Very good communications skills and reporting experience with capacity to communicate to different types of audience (senior executive, middle management, technical and non-technical);
  • Very good understanding of the principles of Computer and Communication Security, networking, and the vulnerabilities of modern operating systems and applications acquired through a blend of academic or professional training coupled with practical professional experience.

Desirable:

  • Experience in working with NATO;
  • Experience of working with NATO Communications and Information Agency;
  • Experience of working with national Defence or Government entities.
  1.  

< go back to opportunities

Request more information
 

This position is now closed.

We regularly add new positions. We suggest exploring other available opportunities and staying updated by following our LinkedIn page.

If you don’t find any suitable opportunities, you can send us your CV, as an open application. However, we will not submit you to any vacancies without your written consent.

 

 

 
The website Allied4.eu is a registered communication web platform managed by Guardian Brigade Lmt,
a company incorporated under Portuguese law with its headquarters located in Parede,
within the municipality of Cascais.

Menu

  • ABOUT US
  • MISSION & VALUES
  • CONSULTANTS
  • OPPORTUNITIES
  • BUSINESS TO BUSINESS
  • CONTACT US

Useful Links

Privacy Policy
Terms & Conditions
Complaint Book

 

Reach Us

info@allied4.eu

  • linkedin
© 2023. All Rights Reserved. Desenvolvido por DOMINIOS.PT