Cyber Security Defender (SIEM/Splunk)

Cyber Security Defender (SIEM/Splunk)

North Atlantic Treaty Organization (NATO)

September 2, 2026September 28, 2026MonsBelgium
Job Description
Job Posting Organization:
The NATO Communications and Information Agency (NCIA) has been a pivotal part of NATO's mission for over 70 years, dedicated to preserving peace and security" style="border-bottom: 1px dotted #007bff !important;">security for nearly one billion citizens. Established to enhance the connectedness and operational capabilities of NATO, the NCIA comprises a diverse team of approximately 3000 civilian and military personnel across 29 locations in Europe, North America, and Asia. The agency focuses on providing advanced technology and cyber expertise to support NATO's critical operations, protect airspace, and maintain superiority in cyberspace and space. The NCIA is committed to hiring, training, and retaining top talent to ensure NATO's technological edge, fostering a diverse and inclusive workforce that reflects the unity of the Alliance.

Job Overview:
As a Cyber Security Defender based in Mons, Belgium, you will play a crucial role in transforming NATO's IT services to support its Digital Endeavour. You will be part of the NATO Cyber Security Centre (NCSC), which is tasked with managing all lifecycle activities related to cyber security. Your role will involve providing specialist services that encompass scientific, technical, acquisition, operations, maintenance, and sustainment support for NATO Communications and Information Systems (CIS). You will be expected to act as a Subject Matter Expert (SME) for SIEM and log collection services, offering technical advice and assistance to stakeholders while maintaining awareness of new technologies. Your responsibilities will include managing and developing data security systems, ensuring compliance with ITIL standards, and supporting operations and service delivery management throughout the data security systems lifecycle.

Duties and Responsibilities:
  • Serve as a primary engineer and Subject Matter Expert (SME) for SIEM and log collection services.
  • Provide technical advice and assistance to stakeholders, maintaining expertise in new technologies.
  • Manage and further develop data security systems.
  • Support Operations and Service Delivery management in accordance with ITIL standards, covering all stages of the data security systems lifecycle, including Service Design, Transition, Operations, Change Management, and Continual Service Improvement.
  • Ensure proper installation, configuration, and operation of data security systems, ensuring alignment with other systems and applications.
  • Analyze and interpret system, security, and application logs to diagnose faults and identify abnormal behaviors.
  • Develop clear and concise technical documentation, including procedures.
  • Work autonomously and proactively, understanding the chain of command and following internal processes.
  • Communicate complex issues effectively to various audiences and teams.

Required Qualifications:
  • A Bachelor’s degree from a nationally recognized/certified university in a related discipline, along with 2 years of post-related experience.
  • Alternatively, a candidate may compensate for the lack of a university degree with at least 6 years of extensive and progressive expertise in relevant duties.
  • At least 1 year of practical experience as a SIEM administrator in a large enterprise environment, including deployment, installation, configuration, and maintenance.
  • Hands-on experience in designing and maintaining distributed Splunk architectures.
  • Expert-level experience in SIEM and log collection management activities with Splunk Enterprise for at least 2 years.
  • Comprehensive knowledge of computer and communication security principles, networking, and vulnerabilities of modern operating systems and applications.
  • Practical skills in writing Bash, Python, or Ansible scripts for task automation.
  • Solid Linux system and application administration and troubleshooting skills.
  • Strong understanding of regular expressions. 1
  • Good communication abilities, both written and verbal, to articulate complex issues clearly.

Educational Background:
A Bachelor’s degree from a nationally recognized/certified university in a related discipline is required. In exceptional cases, extensive experience (at least 6 years) in relevant duties may substitute for formal education. The educational background should ideally align with the technical and operational aspects of cyber security and IT services.

Experience:
Candidates should possess at least 2 years of post-related experience, with a minimum of 1 year of extensive practical experience as a SIEM administrator in a large enterprise environment. Experience should include deployment, installation, configuration, and maintenance of SIEM systems, particularly with Splunk Enterprise, as well as hands-on experience in analyzing system and security logs.

Languages:
Fluency in English, both written and spoken, is mandatory. Additional language skills may be beneficial but are not specified as requirements.

Additional Notes:
The position offers a 5-year contract with a competitive tax-free salary, household and children's allowances, and privileges for expatriate staff, including expatriation and education allowances where applicable. Employees will benefit from excellent private health insurance, 30 days of annual leave plus official holidays, and participation in the NATO Pension Scheme. The NCIA is committed to fostering an inclusive environment and is an equal opportunity employer.
Apply now
Similar Jobs