EMW

C005302 Cyber Security Incident Responder (NS) - MON 14 Sep

EMW  •  Mons, BE (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Deadline Date: Monday 14 September 2026

Requirement: Cyber Security Incident Responder

Location: Mons, BE

Full Time On-Site: Yes

Time On-Site: 100%

Total Scope of the request (hours): 395

Required Start Date: 20 October 2026

End Contract Date: 31 December 2026

Required Security Clearance: NATO SECRET

Duties & Role:

Under the direction of the Section Head of the CSIRT, the contractor shall:

  • Provision 24/7 Cyber Security Incident Response (Triage, Contain, Eradicate, Recover) activities, during normal working hours and occasional on-call duties, including weekends and holidays
  • Deliver technical coordination, support, and assistance in respect of Cyber Security Incident Response to NATO CIS Operating Authorities, including but not limited to: NATO Nations, Partner Nations, non-Governmental Organisations and Industry Partners.
  • Lead, be a member of, or support Cyber Security Response Teams designated to extend the NCSC Incident Response coverage to one or multiple physical locations, including within the NATO Alliance Operations and Missions.
  • Build, manage the lifecycle of, and maintain the taxonomy related to the Branch's information.
  • Manage the content of different information portals within the agreed taxonomy.
  • Design, create and distribute a variety of reports, briefings and dashboards, to different communities, including: (Business owners, operational community, IT service management, cyber security)
  • Maintain a network of cyber security peers across and beyond the NATO Enterprise to facilitate communications and coordination of urgent actions when the need arises.
  • Research and identify, document and implement improvements to the Incident Response activities, in order to enhance and optimise current best practice to meet new and developing threats.
  • Produce Standard Operating Procedure and Instructions covering all aspects of Incident Response.
  • Participate in, and act as an Incident Response subject matter expert, in various meetings: within the CSIRT, across the sections in the Defend branch, across the NATO Enterprise, including within the NICC, CMAWG, CRMG and other Enterprise-level meetings, as well as within the context of a Cyber Incident Task force.

Specific Working Conditions: Normal working hours 0830-1730. Occasional on-call duties after working hours, on weekends or holidays are required.

In case of a major Cyber Security Incident, the incumbent may be required to work extended hours and on shifts, including nights and weekends, to provide a 24/7 Cyber Security Incident Response.

Travel required: The contractor may be required to travel to NCIA locations in Belgium for in-person or department meetings. In such cases the contractor will be reimbursed for travel costs according to NATO regulations for traveling on NATO duty. Each travel will be a maximum of 2 days lengths and happening no more than once per 2 months. Contractors traveling for work purposes shall initiate travel requests from their designated duty station only.

Requirements

Skills, Knowledge & Experience:

  • The candidate must have a currently active NATO SECRET security clearance
  • A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience;
  • Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work.
  • At least 4 years practical experience in cyber security incident response, or a directly connected field such as network analysis, digital forensics, malware analysis or threat hunting. It is noted that Industry often separates responsibilities in such a way that personnel in these roles may also be performing incident response;
  • Comprehensive understanding of the principles of Computer and Communication Security, networking, and the vulnerabilities of modern operating systems and applications acquired through a blend of academic or professional training coupled with practical professional experience;
  • Recent practical, hands-on experience of Intrusion Detection and Incident Response (TRIAGE, Contain, Eradicate, Recover) in an enterprise-level Computer Emergency Response Team, ideally making use of the MITRE ATT&CK framework;
  • At least 3 years experience in Information and Knowledge Management, ideally in the field of Cyber Security
  • Experience in interfacing with IT Service Management.
  • Very good communication and analytical skills.
  • Language proficiency in English: meet or exceed the NATO STANAG 6001 Level 3 "Professional Proficiency".
  • Knowledge of vulnerability assessment and scoring (CVSS, SSVC, CVD)
  • Relevant certifications in cyber security, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or GIAC Security.

Desirable Experience and Education:

  • Hold a University degree in Cyber Security or IT Security-related discipline or Information Management.
  • Practical experience working with, and/or formal research, of the use of AI/LLM within Cyber Security Defense (not from a red team / penetration testing perspective)
  • Practical experience in the management of vulnerabilities, from ingestion, scoring, assessing prioritization of, and potential impact to CIS
  • Hold relevant certifications such as Certified Information Systems Security Professional (CISSP), GCIH or GIAC/GCIM Security (this list is not exhaustive)
  • Hold a professional certification on IT Service Management.
  • In-depth knowledge of potential security event sources and their interpretation and analysis in support of the incident detection and handling processes
  • Practical hands-on experience in System and Network administration to include Network (TCP/IP) Engineering
  • Experience in working for or supporting a military or governmental organization.
  • Recent experience in a large organisational CERT, especially within the Incident Response Team.
  • Experience in actively contributing to industry recognized communities for incident response, such as FIRST.org.
EMW

About EMW

EMW was founded in 1995 by engineers and managers who formerly held senior positions in well known telecommunications and information technology companies to pursue their vision for this new company.

Our core business is providing information and communication technology services in the areas of planning, engineering and implementation; project and program management; systems integration; operations and maintenance; and training. Our competencies range over all aspects of inside and outside plant; feeder, access and inter-office networks; switching, transmission, multiplexing and data communications equipment; network management, operations support, and asset management systems; information assurance; web enabling; applications software; and beyond. While staying abreast of today’s technologies, we keep a watchful eye on technology trends, and are very serious about future-proofing our solutions.

We play in the global marketplace, and are proud to serve a wide spectrum of distinguished clients from defense and government agencies, as well as commercial enterprise. Our watchwords are competency, innovation, integrity, and—above all—respect and care for the customer.

Industry
IT & Software
Company Size
201-500 employees
Headquarters
Herndon, VA
Year Founded
1991
Website
emw.com
Social Media