EMW

C005319 Type 3 Security Audit Remediation Support Engineer (NS) - MON 14 Sep

EMW  •  Mons, BE (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Deadline Date: Monday 14 September 2026

Requirement: Type 3 Security Audit Remediation Support Engineer

Location: Mons, BE

Full Time On-Site: Yes

Time On-Site: 100%

Total Scope of the request (hours): 395

Required Start Date: 19 October 2026

End Contract Date: 31 December 2026

Required Security Clearance: NATO SECRET

Duties & Role:

Under the direction of the Section Head, the contractor shall:

1. Perform vulnerability assessment and technical analysis, including but not limited to:

  • Analyse the results of the vulnerability assessments when a new assessment is available.
  • Prepare, for every assessment report, a remediation action plan and provide it to the appropriate technical point of contact not later than two working days after release of the assessment report;
  • Interpret complex technical findings and provide remediation support to system administrators;
  • Assess the technical impact of the vulnerabilities in order to prioritise remediation, for all remediation plans being tracked;
  • Support vulnerability monitoring activities: review newly and publicly disclosed vulnerabilities and support the team in the preparation of NATO Security Bulletins.

2. Perform remediation tracking and site coordination, including but not limited to:

  • Act as the technical point of contact for remediation towards site administrators and system owners;
  • Monitor and maintain the tracking of remediation activities for all open findings;
  • Produce weekly and monthly progress reports for the various stakeholders;
  • Chair technical coordination meetings with site administrators in order to resolve remediation roadblocks.

3. Report on remediation status and support governance activities, including but not limited to:

  • Brief the monthly Enterprise Vulnerability Assessment Plan (EVAP) meeting, presenting the progress of the remediation activities;
  • Participate in status update meetings, activity planning meetings and other meetings as instructed, on site or via conference call capabilities;
  • Provide, at the end of the period of performance, a closure report summarising at high level the activities carried out.

4. Execute coordination and information gathering activities within NCSC, NCIA and with stakeholders at the supported NATO sites, in support of the above activities.

Specific Working Conditions: Given the on-site and coordination nature of the duties, the work is not suitable for regular remote execution. Any occasional telework shall be subject to the NCIA teleworking policy and to prior approval by the Line Manager.

The service shall be provided during the Purchaser's business hours – Monday to Thursday from 08h30 until 17h30 and Friday from 08h30 until 15h30 – on all days except weekends and the Purchaser's site-specific official holidays

All deliverables shall be produced using NCIA templates, or in a format agreed with the point of contact, shall be peer reviewed within the delivery cycle and shall be stored under configuration management in the NCIA-provided tools.

It is crucial for the performance of the services to understand the rules, regulations and methods of work in NATO and in particular in NCSC; therefore frequent replacement of the contractor is not advised and the services shall be performed by one and the same individual for the entire period of performance.

Travel required: The contractor may be required to travel to other NCIA locations for in-person or department meetings. In such cases the contractor will be reimbursed for travel costs according to NATO regulations for traveling on NATO duty. Each travel will be a maximum of 2 days lengths and happening no more than twice per month. Contractors traveling for work purposes shall initiate travel requests from their designated duty station only.

Requirements

Skills, Knowledge & Experience:

  • The candidate must have a currently active NATO SECRET security clearance
  • A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience;
  • Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work.
  • At least 5 years of practical experience in vulnerability management, with proven experience within the last 6 months;
  • At least 3 years of experience in testing and validating that contracted deliveries meet the security requirements and fulfil the intended use cases;
  • General knowledge of cyber security principles, best practices, concepts and technology;
  • Knowledge of cyber security architectures, including boundary protection, encryption, identity and access management, monitoring and detection, incident response, vulnerability assessments and risk management;
  • Practical experience with vulnerability scanners and their output formats, such as Tenable Nessus, Qualys or OpenVAS;
  • Demonstrated experience in producing remediation action plans and coordinating their implementation with system administrators across multiple sites.
  • Ability to interpret complex technical findings and to translate them into actionable remediation guidance for system administrators;
  • Scripting proficiency in Python (Pandas/NumPy) or PowerShell for parsing scan results and automating data handling;
  • Ability to take ownership of tasks and strong motivation to accomplish them to the end, working both independently and within a team;
  • Very good communication, analytical and writing skills;
  • Language proficiency in English: meet or exceed the NATO STANAG 6001 Level 3 "Professional Proficiency".
  • Relevant certifications in cyber security, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or GIAC Security certifications.

Desirable Experience:

  • Familiarity with NATO security policy and supporting directives;
  • Experience in working for or supporting a military or governmental organization.
EMW

About EMW

EMW was founded in 1995 by engineers and managers who formerly held senior positions in well known telecommunications and information technology companies to pursue their vision for this new company.

Our core business is providing information and communication technology services in the areas of planning, engineering and implementation; project and program management; systems integration; operations and maintenance; and training. Our competencies range over all aspects of inside and outside plant; feeder, access and inter-office networks; switching, transmission, multiplexing and data communications equipment; network management, operations support, and asset management systems; information assurance; web enabling; applications software; and beyond. While staying abreast of today’s technologies, we keep a watchful eye on technology trends, and are very serious about future-proofing our solutions.

We play in the global marketplace, and are proud to serve a wide spectrum of distinguished clients from defense and government agencies, as well as commercial enterprise. Our watchwords are competency, innovation, integrity, and—above all—respect and care for the customer.

Industry
IT & Software
Company Size
201-500 employees
Headquarters
Herndon, VA
Year Founded
1991
Website
emw.com
Social Media