Enter a job title or keyword

CSIRT Analyst (Intrusion Detection and Digital Forensics) for NATO with security clearance

WLG


Job Location:

Mons - Belgium

Monthly Salary: Not provided by the employer
Posted: 16 September 2026 (8 hours ago)
Application Deadline: 14 December 2026
Vacancies: 1 Vacancy

Job Summary

When something gets in somebody has to be the one who stays calm and worksthe problem. That is this job.

You would join the incident response team of a multinational defence organisation in MonsBelgium under the section head responding to security incidents around the clock and helpingthe wider alliance and its partners do the same.

What you would be doing

  • Running incident response triage containment eradication recovery in normal hours andon occasional call-out
  • Giving technical coordination and support to operating authorities across member and partnernations non-governmental organisations and industry partners
  • Leading or supporting response teams sent out to extend that coverage to one or severalphysical locations including on operations and missions
  • Building and maintaining the taxonomy behind the branchs information and the content of theportals that sit on it
  • Designing and distributing the reports briefings and dashboards that business owners theoperational community service management and security people each need
  • Keeping a live network of security peers so an urgent action can be coordinated when it isneeded rather than when it is convenient
  • Finding and implementing improvements to the response process as the threats move
  • Writing the standard operating procedures and instructions that cover it all
  • Acting as the response expert in meetings across the organisation and in an incident taskforce

What you would bring

  • At least four years of hands-on incident response or a directly adjacent field digitalforensics threat hunting or malware and network analysis
  • A thorough grasp of computer and communications security networking and where modernoperating systems and applications actually break
  • Recent hands-on intrusion detection and response inside an enterprise-scale response teamideally against the MITRE ATT&CK framework
  • At least three years in information and knowledge management preferably in security
  • Working alongside IT service management
  • Very good communication and analysis and professional English
  • Vulnerability assessment and scoring CVSS SSVC coordinated disclosure
  • A relevant certification such as CISM CISSP or a GIAC security qualification
  • A bachelors degree in a related discipline with three years of related experience orexceptionally ten years of progressive expertise in this kind of work

Nice to have

  • A degree in cyber or IT security or information management
  • Practical work or research on using AI and language models in defensive security
  • Vulnerability management end to end: ingestion scoring prioritisation impact
  • An IT service management certification and depth on security event sources and how to readthem
  • Hands-on system and network administration including TCP/IP engineering
  • Time in a large organisational response team and contribution to recognised communities suchas FIRST

Why this one is worth a look

Very few response teams operate at this scale or with this reach and the work is genuinelyoperational rather than advisory.


About Company

Company Logo

Work Life Group Sp. z o.o., agencja zatrudnienia (employment agency) KRAZ no. 19578. NIP 7010247728. ul. Nowogrodzka 50/54 lok. 515, 00-695 Warszawa, Poland.

View Profile View Profile