#NC25CSG180655 - SUPPORT TO CYBERSPACE OPERATIONS MALWARE AND DIGITAL FORENSICS - Closed
Deadline: July 6, 2025
Requester: NATO
Location: Mons, Belgium
Start date: September, 2025
Security clearance: NATO COSMIC TOP SECRET
SCOPE OF WORK / DUTIES / ROLES
- Based on a specific malware analysis task (TASK) received via the NCSC COMS system. Analyse what is required (malicious email, URL, binary…) and perform a comprehensive analysis using automated and manual approaches;
- Malware analysis research on samples of particular interest. When such a research is required, the provider will perform additional tasks to analyse in depth the sample and produce rules to better detect it;
- Create, update and modify existing SOI/SOPs to reflect the current best practices;
- Acquire and analyse digital forensics evidence following the forensics task (TASK) raised in NCSC COMS;
- Use and configure security tools such as Microsoft Defender for Endpoint, Fidelis Endpoint Security, F-Response as well as supporting scripting and tools;
- Brainstorm during weekly meetings with the rest of the Cyber Threat Investigation Team how to improve the services delivered by the team;
- Perform supporting activities around malware and digital forensics such as informing relevant stakeholders, liaising with other teams in the NATO enterprise, preparing administrative documents and technical implementation to assist with continuous service improvements.
REQUIRED SKILLS, KNOWLEDGE AND EXPERIENCE
- Experience of at least 2 years in:
- Malware analysis techniques and technologies;
- Analysis of digital forensic artefacts in the context of cyber security;
- Cyber security in cloud-based environments;
- Analysing Windows forensics artefacts such as Windows Event logs, UAL, MFT…;
- Writing scripts (Python, Powershell) and building automation workflows;
- Report writing about a technical task and communication with stakeholders.
- Excellent ability to recognise when an IT network/system has been attacked, be able to take immediate action to limit damage and to escalate the event to higher authority;
- Good knowledge of the principles of computer and communications security, networking, and vulnerabilities of modern operating systems and applications;
- Good understanding of the MITRE ATT&CK framework and its applicability in Cyber;
- Good knowledge of cyber security incident handling;
- Knowledge of Azure Sentinel, Microsoft Defender for endpoint;
- Good knowledge of networking protocols;
- Knowledge of Fidelis EDR is an asset;
- Language proficiency in English meet or exceed the NATO STANAG 6001 Level 3 “Professional Proficiency”;
- The contractor shall be dressed suitably for meetings with high ranked officials. No religious sign shall be worn during such meeting;
- The contractor shall actively collaborate during internal meeting and touch-points discussions to improve the quality of services;
- Strong reporting skills to various levels of seniority;
- Accuracy and attention to detail;
- Previous experience in working for or supporting a military or governmental organization is an asset.
This position is now closed.
We regularly add new positions. We suggest exploring other available opportunities and staying updated by following our LinkedIn page.
If you don’t find any suitable opportunities, you can send us your CV, as an open application. However, we will not submit you to any vacancies without your written consent.
