#NC26CSG191808 - DCO Tracking Support
Deadline: September 20, 2026
Requester: NATO
Location: Mons, Belgium
Job type: Contractor
Start date: November, 2026
Security clearance: NATO SECRET
SCOPE OF WORK / DUTIES / ROLES
Under the direction of the Section Head, the contractor shall:
- Perform security assessment and technical analysis, including but not limited to:
- Analyse the results of the vulnerability assessments on a weekly basis;
- Prepare, for every assessment report, a remediation plan and provide it to the appropriate technical point of contact;
- Interpret complex technical findings and provide remediation support to system administrators;
- Assess the technical impact of the vulnerabilities in order to prioritise remediation;
- Provide technical guidance, on a weekly basis, on the hardening measures required at operating system, database and network level.
- Build and maintain the vulnerability data architecture and visualisation ecosystem, including but not limited to:
- Design, build and maintain a relational database or structured data repository aggregating raw vulnerability scan data from the various sources;
- Automate the ingestion of scan results into the central database (data pipeline);
- Develop and maintain dynamic dashboards, using data visualisation and analytics platform such as Power BI or Grafana;
- Create visualisations for vulnerability metrics supporting operational and management reporting;
- Maintain and update the database and the dashboards on a weekly basis.
- Perform remediation tracking and site coordination, including but not limited to:
- Act as the technical point of contact for remediation towards site administrators and system owners;
- Monitor and maintain the tracking of remediation activities;
- Produce weekly and monthly reports for the various stakeholders;
- Chair technical coordination meetings with site administrators in
order to resolve remediation roadblocks.
- Execute coordination and information gathering activities within NCSC, NCIA and with stakeholders in support of the above activities, and provide at the end of the period of performance a closure report summarising at high level the activities carried out.
REQUIRED SKILLS, KNOWLEDGE AND EXPERIENCE
- At least 5 years of practical experience in vulnerability management, with proven experience within the last 6 months;
- At least 3 years of experience in testing and validating that contracted deliveries meet the security requirements and fulfil the intended use cases;
- General knowledge of cyber security principles, best practices, concepts and technology;
- Knowledge of cyber security architectures, including boundary protection, encryption, identity and access management, monitoring and detection, incident response, vulnerability assessments and risk management;
- Practical experience with vulnerability scanners and their output formats, such as Tenable Nessus, Qualys or OpenVAS;
- Demonstrated experience in building and operating data repositories and reporting pipelines for large volumes of security scan data;
- Database skills: proficiency in SQL (e.g. PostgreSQL, MS SQL) for data modelling, querying and storing large datasets of scan results;
- BI tools: advanced proficiency in Microsoft Power BI (data modelling, DAX) OR Grafana (connecting to SQL data sources, visualising time-series data);
- Scripting proficiency in Python (Pandas/NumPy) or PowerShell for parsing scan logs and automating data entry;
- Ability to take ownership of tasks and strong motivation to accomplish them to the end, working both independently and within a team;
- Very good communication, analytical and writing skills;
- Language proficiency in English: meet or exceed the NATO STANAG 6001 Level 3 "Professional Proficiency";
- Relevant certifications in cyber security, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or GIAC Security certifications;
- Relevant certifications in data analytics or business intelligence, such as Microsoft Power BI Data Analyst Associate (PL-300) or Grafana Certified Professional, are an advantage;
- A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience;
- Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work.
Desirable:
- Familiarity with NATO security policy and supporting directives;
- Experience in working for or supporting a military or governmental organization.
APPLY TO THIS POSITION
