Job Posting Organization: The NATO Communications and Information Agency (NCIA) has been operational for over 70 years, dedicated to preserving peace and security" style="border-bottom: 1px dotted #007bff !important;">security within the NATO Alliance, which serves nearly one billion citizens. The agency comprises a diverse team of approximately 3000 civilian and military personnel, spread across 29 locations in Europe, North America, and Asia. The NCIA plays a crucial role in enabling NATO's connectedness and operational capabilities, focusing on technology and cyber expertise to support critical operations, defend against cyber threats, and maintain superiority in space. The organization is committed to hiring, training, and retaining top talent to ensure its technological edge and operational effectiveness.
Job Overview: The Senior CIS Security Officer position is based in Mons, Belgium, and is part of the NATO Cyber Security Centre (NCSC). This role is pivotal as NATO embarks on a transformative journey to enhance its IT services in alignment with NATO's Digital Endeavour. The NCSC is tasked with comprehensive lifecycle management for cyber security, providing specialized services that encompass scientific, technical, acquisition, operations, maintenance, and sustainment support for NATO Communications and Information Systems (CIS). The successful candidate will be responsible for developing and overseeing security awareness and training programs, monitoring and analyzing security incidents, and collaborating with the Incident Management Team to implement effective incident response plans. Additionally, the role involves building relationships with key stakeholders, assisting in disaster recovery and business continuity planning, and managing third-party vendors to ensure compliance with security requirements.
Duties and Responsibilities: The Senior CIS Security Officer will undertake a variety of responsibilities, including but not limited to:
Developing and overseeing security awareness and training programs to ensure all employees understand their roles in maintaining information security.
Monitoring and analyzing security incidents and threats, and collaborating with the Incident Management Team to develop and implement incident response plans.
Establishing and maintaining relationships with key stakeholders, including senior management, external auditors, and regulatory authorities.
Assisting in the development and maintenance of disaster recovery and business continuity plans.
Managing and overseeing third-party vendors and service providers to ensure they meet established security requirements.
Conducting security audits, risk assessments, and regulatory reporting.
Developing and maintaining security frameworks such as ISO 27001, NIST, and CIS.
Enforcing organization-wide security policies and defining security awareness programs.
Collaborating cross-functionally with other business and functional areas within the organization. 1
Acting as a liaison between technical teams and business units. 1
Supporting testing, disaster recovery, and business continuity capabilities. 1
Responding to security investigations and initial response capabilities.
Required Qualifications: Candidates must possess a Bachelor’s degree from a nationally recognized or certified university in a related discipline, along with a minimum of 3 years of post-related experience. Alternatively, candidates may qualify without a university degree if they can demonstrate at least 10 years of extensive and progressive expertise in duties relevant to the position. Comprehensive knowledge of computer and communication security principles, networking, and the vulnerabilities of modern operating systems and applications is essential. Experience in implementing and integrating CIS Security protective measures in enterprise environments, governance, risk, and compliance (GRC), leading security audits, and developing security frameworks is also required. Candidates should have a proven track record of enforcing organization-wide policies and defining security awareness programs, as well as cross-functional collaboration skills.
Educational Background: The educational requirement for this position is a Bachelor’s degree from a nationally recognized or certified university in a relevant field. In exceptional cases, significant professional experience may substitute for formal education, provided the candidate can demonstrate relevant abilities or experience that align with the needs of the NCIA.
Experience: The ideal candidate should have a minimum of 3 years of relevant experience in the field of cyber security. However, candidates lacking a university degree may compensate with at least 10 years of extensive and progressive experience in duties related to the function of the post. This experience should encompass a broad range of responsibilities, including security audits, risk assessments, and the implementation of security measures in enterprise environments.
Languages: Fluency in English, both written and spoken, is mandatory for this position. Proficiency in additional languages may be considered an asset, enhancing communication within the diverse NATO environment.
Additional Notes: This position offers a 5-year contract with a competitive tax-free salary, along with household and children's allowances where applicable. Expatriate staff may receive additional benefits, including expatriation and education allowances, as well as generous annual leave of 30 days plus official holidays. The role includes participation in the NATO Pension Scheme and access to development programs such as professional training and wellbeing initiatives. The NCIA is committed to fostering an inclusive environment and is an equal opportunity employer.
Info
Job Posting Disclaimer
This job posting is provided for informational purposes only. The accuracy of the job description, qualifications, and other details mentioned is the sole responsibility of the employer or the organization listing the job. We do not guarantee the validity or legitimacy of this job posting. Candidates are advised to conduct their own due diligence and verify the details directly with the employer before applying.
We are not liable for any decisions or actions taken by applicants in response to this job listing. By applying, you agree that all application processes, interviews, and potential job offers are managed exclusively by the listed employer or organization.
Beware of fraudulent job offers. Do not provide sensitive personal information or make any payments to secure a job.