[6427] DCO Tracking Support
Start date: Negotiable
Clearance: NATO Secret
Location: Mons, Belgium
Requirements
• Active experience in vulnerability management, with at least 5 years of practical experience and proven experience within the last 6 months.
• At least 3 years of experience testing and validating that contracted deliveries meet security requirements and intended use cases.
• General knowledge of cybersecurity principles, best practices, concepts and technologies.
• Knowledge of cybersecurity architectures, including boundary protection, encryption, identity and access management, monitoring and detection, incident response, vulnerability assessments and risk management.
• Practical experience with vulnerability scanners and their output formats, such as Tenable Nessus, Qualys or OpenVAS.
• Demonstrated experience building and operating data repositories and reporting pipelines for large volumes of security scan data.
• Proficiency in SQL, such as PostgreSQL or MS SQL, for data modelling, querying and storing large datasets.
• Advanced proficiency in Microsoft Power BI, including data modelling and DAX, or Grafana, including SQL data sources and time-series visualisation.
• Scripting proficiency in Python, including Pandas/NumPy, or PowerShell for parsing scan logs and automating data entry.
• Ability to take ownership of tasks and work independently and as part of a team.
• Very good communication, analytical and writing skills.
• English language proficiency meeting or exceeding NATO STANAG 6001 Level 3 Professional Proficiency.
• Bachelor's degree from a nationally recognised/certified university in a related discipline with 3 years of post-related experience, or exceptionally, at least 10 years of extensive and progressive relevant experience in lieu of a degree.
Desirable
• Relevant cybersecurity certifications, such as CISM, CISSP or GIAC certifications.
• Relevant data analytics or business intelligence certifications, such as Microsoft Power BI Data Analyst Associate (PL-300) or Grafana Certified Professional.
• Familiarity with NATO security policy and supporting directives.
• Experience working for or supporting a military or governmental organisation.
Duties & Role
• Perform security assessments and technical analysis of vulnerability assessment results on a weekly basis.
• Prepare remediation plans for each assessment report and provide them to the appropriate technical points of contact.
• Interpret complex technical findings and provide remediation support to system administrators.
• Assess the technical impact of vulnerabilities and prioritise remediation activities.
• Provide weekly technical guidance on hardening measures required at operating system, database and network level.
• Design, build and maintain relational databases or structured data repositories aggregating raw vulnerability scan data from multiple sources.
• Automate the ingestion of vulnerability scan results into central databases through data pipelines.
• Develop and maintain dynamic dashboards using data visualisation and analytics platforms such as Power BI or Grafana.
• Create visualisations for vulnerability metrics supporting operational and management reporting.
• Maintain and update vulnerability databases and dashboards on a weekly basis.
• Act as the technical point of contact for remediation activities with site administrators and system owners.
• Monitor and maintain tracking of remediation activities.
• Produce weekly and monthly reports for relevant stakeholders.
• Chair technical coordination meetings with site administrators to resolve remediation roadblocks.
• Coordinate and gather information within NCSC and NCIA and with relevant stakeholders in support of vulnerability management and remediation activities.
• Provide a closure report at the end of the period of performance summarising the activities carried out.
• Support the coordination of security requirements, vulnerability remediation and technical activities across relevant stakeholders.
.png)

