Would you like to join the leading international intergovernmental organization
The NCIA NATO Cyber Security Centre (NCSC) is responsible for planning and executing all lifecycle management activities for executing this responsibility NCSC provides specialist cyber security-related services covering the spectrum of scientific technical acquisition operations maintenance and sustainment support throughout the lifecycle of NATO Information Communications and Technology (ICT). Within the NCSC the Penetration Testing Section plays a critical offensive security role. They conduct tailored vulnerability assessments penetration testing and red teaming activities against NATO networks throughout their entire lifecycle.
Responsibilities:
- Providing Web infrastructure and application level penetration testing including but not limited to COTS software and NOTS/GOTS software (NATO/Government off the Shelf) following clearly defined methodologies.
- Participating in kick-off meetings with stakeholders and technical points of contact in order to identify requirements for testing.
- Following the documented procedures and workflows outlined by the technical leads.
- Attending team meetings if required.
- Writing technical reports in fluent English following defined templates and Reporting Tools.
- Briefing at both executive and technical levels on security reports and testing outcome including at flag officer level.
- In case of new vulnerabilities detected for COTS software following the Responsible Disclosure Process and following-up with vendors and stakeholders.
- Providing security design reviews to ensure compliance with NATO policies and directives.
- In co-ordination with the Technical Lead of the Penetration testing team ensuring proactive collaboration and coordination with internal and external stakeholders.
- Staying abreast of technological developments relevant to the area of work.
- Performing any other duties as may be required.
We are happy to hear from you if you have:
- Bachelor of Science (BSc) degree at a nationally recognised/certified university in a technical subject with substantial Information Technology (IT) content and 3 years post-related experience.
- Extensive knowledge and experience (at least 3 years) in the following areas:
- Web application penetration testing
- IT infrastructure penetration testing
- Network security architecture design
- Assessing security vulnerabilities within OS software protocols & networks
- Researching and evaluating security products & technologies
- Knowledge in system and network administration of UNIX and Windows systems
- Use of penetration testing tools techniques and recognized testing methodologies
- Scripting skills in at least one of the following: Python Go PowerShell shell (bash ksh csh)
- Technical knowledge in system and network security authentication and security protocols cryptography application security as well as malware infection techniques and protection technologies.
- Ability to evaluate risks and formulate mitigation plans.
- Proven ability to brief at executive level on security findings reports and testing outcome.
- Proven ability to write clear and structured technical reports including executive summary technical findings and remediation plan for several different audiences.
- Fluent English skills (verbal and written).
- Desirable Experience and Education:
- Professional qualifications: OSCP OSCE OSWE GPEN CREST Certified Web Application Tester GXPN GWAPT or equivalent
- Familiarity with risk analysis methodologies.
- Prior experience of working in an international environment comprising both military and civilian elements.
- Knowledge of NATO organization internal structure and resultant relationships.
If youve read the description and feel this role is a great match wed love to hear from you! Click Apply for this job to be directed to a brief questionnaire. It should only take a few moments to complete and well be in touch promptly if your experience aligns with our needs.
Would you like to join the leading international intergovernmental organizationThe NCIA NATO Cyber Security Centre (NCSC) is responsible for planning and executing all lifecycle management activities for executing this responsibility NCSC provides specialist cyber security-related services covering...
Would you like to join the leading international intergovernmental organization
The NCIA NATO Cyber Security Centre (NCSC) is responsible for planning and executing all lifecycle management activities for executing this responsibility NCSC provides specialist cyber security-related services covering the spectrum of scientific technical acquisition operations maintenance and sustainment support throughout the lifecycle of NATO Information Communications and Technology (ICT). Within the NCSC the Penetration Testing Section plays a critical offensive security role. They conduct tailored vulnerability assessments penetration testing and red teaming activities against NATO networks throughout their entire lifecycle.
Responsibilities:
- Providing Web infrastructure and application level penetration testing including but not limited to COTS software and NOTS/GOTS software (NATO/Government off the Shelf) following clearly defined methodologies.
- Participating in kick-off meetings with stakeholders and technical points of contact in order to identify requirements for testing.
- Following the documented procedures and workflows outlined by the technical leads.
- Attending team meetings if required.
- Writing technical reports in fluent English following defined templates and Reporting Tools.
- Briefing at both executive and technical levels on security reports and testing outcome including at flag officer level.
- In case of new vulnerabilities detected for COTS software following the Responsible Disclosure Process and following-up with vendors and stakeholders.
- Providing security design reviews to ensure compliance with NATO policies and directives.
- In co-ordination with the Technical Lead of the Penetration testing team ensuring proactive collaboration and coordination with internal and external stakeholders.
- Staying abreast of technological developments relevant to the area of work.
- Performing any other duties as may be required.
We are happy to hear from you if you have:
- Bachelor of Science (BSc) degree at a nationally recognised/certified university in a technical subject with substantial Information Technology (IT) content and 3 years post-related experience.
- Extensive knowledge and experience (at least 3 years) in the following areas:
- Web application penetration testing
- IT infrastructure penetration testing
- Network security architecture design
- Assessing security vulnerabilities within OS software protocols & networks
- Researching and evaluating security products & technologies
- Knowledge in system and network administration of UNIX and Windows systems
- Use of penetration testing tools techniques and recognized testing methodologies
- Scripting skills in at least one of the following: Python Go PowerShell shell (bash ksh csh)
- Technical knowledge in system and network security authentication and security protocols cryptography application security as well as malware infection techniques and protection technologies.
- Ability to evaluate risks and formulate mitigation plans.
- Proven ability to brief at executive level on security findings reports and testing outcome.
- Proven ability to write clear and structured technical reports including executive summary technical findings and remediation plan for several different audiences.
- Fluent English skills (verbal and written).
- Desirable Experience and Education:
- Professional qualifications: OSCP OSCE OSWE GPEN CREST Certified Web Application Tester GXPN GWAPT or equivalent
- Familiarity with risk analysis methodologies.
- Prior experience of working in an international environment comprising both military and civilian elements.
- Knowledge of NATO organization internal structure and resultant relationships.
If youve read the description and feel this role is a great match wed love to hear from you! Click Apply for this job to be directed to a brief questionnaire. It should only take a few moments to complete and well be in touch promptly if your experience aligns with our needs.
View more
View less