LOGO_ALLIED4_RVBLOGO_ALLIED4_RVBLOGO_ALLIED4_RVBLOGO_ALLIED4_RVB
  • ABOUT US
  • MISSION & VALUES
  • CONSULTANTS
  • OPPORTUNITIES
  • BUSINESS TO BUSINESS
  • CONTACT US
✕
DEADLINE: allied4eu April 2, 2025

#NC25ICT178452 - Active Directory Security Assessment Data Analysis and Reporting - Closed

 Deadline: April 2, 2025

Requester: NATO

Location: Mons, Belgium

Job type: Contractor

Start date: May, 2025 

Security clearance: NATO SECRET

SCOPE OF WORK / DUTIES / ROLES

Under the direction / guidance of the NCSC Point of Contact, a contractor will be the part of the NCSC Team supporting the following activities:

Ensuring data accuracy and up-to-date data for Active Directory (AD) Security issues:

  • Ensure accurate and up-to-date AD data is collected from the different Domains in scope;
  • Security baselines are configured based on industry best practice and NATO policies;
  • Review existing policies, fine tune and improve them at the same time;
  • Report to the Tool Managers any technical issues, such as connectivity problems between Tenable Identity Exposure and other integrated systems or errors in scans or reports;
  • Follow up the new releasing of the security solutions to consider the implementation of new features or capabilities.

Monitoring, analysing the collected data, prioritizing based on risk assessment for Active Directory (AD) Security issues:

  • Monitor the solution daily;
  • Identify the potential security issues;
  • Ensure that the collected data is analysed;
  • Prioritize the remediation actions based on the previous point.

Reporting Active Directory (AD) Security issues:

  • Critical vulnerabilities will be reported within 4 hours since identified;
  • High vulnerabilities will be reported within 8 hours since identified;
  • Deliver a comprehensive vulnerability report to each stakeholder under you area of responsibility taking into account all vulnerabilities posing a security risk, remediation actions recommended to the system/application owners and the status of the recommended actions. The weekly report is expected to be delivered each Wednesday/Thursday before Close of Business;
  • Ensure that the reported information is also available via PowerBI dashboard (or similar);
  • Report to the corresponding AD management teams the prioritized remediation actions based on the analysis done on point 2.c/2.d);
  • Record the defined KPIs to follow up the trend of AD Security issues 4 / 8.

Remediation actions for Active Directory (AD) Security issues:

  • Follow up and verify that the reported security issues have been remediated;
  • Follow the escalation process in case the reported security issues have not been fixed.

Documentation:

  • Document configuration and changes: Keep up-to-date documentation of all configurations, baselines, troubleshooting procedures;
  • Keep a lessons learnt document.

User access Management:

  • Review the list of users with access to the security solution;
  • Verify that only the required users have access to the solution;
  • Coordinate with the Tool Managers any issue with the User access management.

Automation and Scripting:

  • Improve processes efficiency: Identify areas where automation could reduce manual intervention and improve operational efficiency.
REQUIRED SKILLS, KNOWLEDGE AND EXPERIENCE

The contractor(s) that is going to perform the identified tasks as an Operation and Maintenance Expert of Active Directory Security Assessment Tool must have demonstrated skills, knowledge and experience as listed below:

  • Bachelor's degree in Computer Science, Information Technology, or related field O equivalent experience;
  • 3+ years of experience in IT security, with a focus on Active Directory security, System Administration, and hands-on on Security Assessment Tools in large organisations;
  • Experience with Active Directory Management,
  • Strong understanding of security best practices and experience with Tenable products especially with Tenable Identity Exposure;
  • Comprehensive experience and hands-on on administering Microsoft Windows Domain based networks;
  • Systems administration, ideally both with Windows and Linux;
  • Good engineering skills including programming and/or scripting knowledge (python, shell scripting, PowerShell);
  • Demonstrable experience of analysing, prioritizing and reporting in the field of vulnerabilities assessment;
  • Strong analytical and problem-solving skills;
  • Excellent communication abilities, both written and verbal, with the ability to clearly and successfully articulate complex issues to a variety of audiences and teams;
  • Database management skills, preferably MS SQL.

Desirable:

  • Experience in working with NATO;
  • Experience of working with NATO Communications and Information Agency;
  • Experience of working with national Defence or Government entities.

< go back to opportunities

Request more information
 

This position is now closed.

We regularly add new positions. We suggest exploring other available opportunities and staying updated by following our LinkedIn page.

If you don’t find any suitable opportunities, you can send us your CV, as an open application. However, we will not submit you to any vacancies without your written consent.

 

 

 
The website Allied4.eu is a registered communication web platform managed by Guardian Brigade Lmt,
a company incorporated under Portuguese law with its headquarters located in Parede,
within the municipality of Cascais.

Menu

  • ABOUT US
  • MISSION & VALUES
  • CONSULTANTS
  • OPPORTUNITIES
  • BUSINESS TO BUSINESS
  • CONTACT US

Useful Links

Privacy Policy
Terms & Conditions
Complaint Book

 

Reach Us

info@allied4.eu

  • linkedin
© 2023. All Rights Reserved. Desenvolvido por DOMINIOS.PT