[6321] Security Support Engineer
Start date: Negotiable
Clearance: NATO Secret or equivalent
Location: Mons, BE
Skill, Knowledge & Experience:
• At least 5 years of practical experience in vulnerability management, with proven experience within the last 6 months;
• At least 3 years of experience in testing and validating that contracted deliveries meet the security requirements and fulfill the intended use cases;
• General knowledge of cyber security principles, best practices, concepts and technology;
• Knowledge of cyber security architectures, including boundary protection, encryption, identity and access management, monitoring and detection, incident response, vulnerability assessments and risk management;
• Practical experience with vulnerability scanners and their output formats, such as Tenable Nessus, Qualys or OpenVAS;
• Demonstrated experience in producing remediation action plans and coordinating their implementation with system administrators across multiple sites.
• Ability to interpret complex technical findings and to translate them into actionable remediation guidance for system administrators;
• Scripting proficiency in Python (Pandas/NumPy) or PowerShell for parsing scan results and automating data handling;
• Relevant certifications in cyber security, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or GIAC Security certifications.
Duties:
• Analyse the results of the vulnerability assessments when a new assessment is available.
• Prepare, for every assessment report, a remediation action plan and provide it to the appropriate technical point of contact not later than two working days after release of the assessment report;
• Interpret complex technical findings and provide remediation support to system administrators;
• Assess the technical impact of the vulnerabilities in order to prioritise remediation, for all remediation plans being tracked;
• Support vulnerability monitoring activities: review newly and publicly disclosed vulnerabilities and support the team in the preparation of NATO Security Bulletins.
• Act as the technical point of contact for remediation towards site administrators and system owners;
• Monitor and maintain the tracking of remediation activities for all open findings;
• Produce weekly and monthly progress reports for the various stakeholders;
• Chair technical coordination meetings with site administrators in order to resolve remediation roadblocks.
• Brief the monthly Enterprise Vulnerability Assessment Plan (EVAP) meeting, presenting the progress of the remediation activities;
• Participate in status update meetings, activity planning meetings and other meetings as instructed, on site or via conference call capabilities;
• Provide, at the end of the period of performance, a closure report summarizing at high level the activities carried out.
.png)

