Would you like to join the leading international intergovernmental organization
The Penetration Testing Section of the NCSC conducts tailored penetration testing against NATO networks and systems. The team assesses the impact likelihood and difficulty of exploitation by advanced cyber adversaries supporting accreditation IT change management software development assurance exercises and incident response. Reporting to the Team Lead the Senior Penetration Tester will be responsible for executing comprehensive penetration testing and vulnerability assessments to improve NATOs cyber hygiene and support its cyber defence posture.
Responsibilities:
Provide Web infrastructure and application-level penetration testing including but not limited to COTS software and NOTS/GOTS software (NATO/Government off the Shelf) following clearly defined methodologies.
Participate in kick-off meetings with stakeholders and technical points of contact in order to identify requirements for testing.
Follow the documented procedures and workflows outlined by the technical leads
Attend team meetings if required
Write technical reports in fluent English following defined templates and Reporting Tools.
Brief at both executive and technical levels on security reports and testing outcome including at flag officer level.
In case of new vulnerabilities detected for COTS software follow the Responsible Disclosure Process and follow-up with vendors and stakeholders.
In co-ordination with the Technical Lead of the Penetration testing team ensure proactive collaboration and coordination with internal and external stakeholders.
Stay abreast of technological developments relevant to the area of work.
Perform any other duties as may be required.
Essential Qualifications & Experience:
The service contractor will be required to have a Bachelor of Science (BSc) degree at a nationally recognised/certified university in a technical subject with substantial Information Technology (IT) content and 3 years post-related experience. As an exception the lack of a university degree may be compensated by the demonstration of a candidates particular abilities or experience that are of interest to the NCI Agency; namely at least 10 years of extensive and progressive experience in the duties related to the functions of this post.
Extensive knowledge and experience (at least 3 years) in the following areas:
Web application penetration testing
IT infrastructure penetration testing
Network security architecture design
Assessing security vulnerabilities within OS software protocols & networks
Researching and evaluating security products & technologies
Knowledge in system and network administration of UNIX and Windows systems
Use of penetration testing tools techniques and recognized testing methodologies
Scripting skills in at least one of the following: Python Go PowerShell shell (bash ksh csh)
Technical knowledge in system and network security authentication and security protocols cryptography application security as well as malware infection techniques and protection technologies.
Ability to evaluate risks and formulate mitigation plans.
Proven ability to brief at executive level on security findings reports and testing outcome.
Proven ability to write clear and structured technical reports including executive summary technical findings and remediation plan for several different audiences.
Desirable Experience and Education:
Professional qualifications: OSCP OSCE OSWE GPEN CREST Certified Web Application Tester GXPN GWAPT or equivalent
Familiarity with risk analysis methodologies.
Prior experience of working in an international environment comprising both military and civilian elements.
Knowledge of NATO organization internal structure and resultant relationships.
Language Proficiency:
A thorough knowledge of one of the two NATO languages both written and spoken is essential and some knowledge of the other is desirable.
NOTE: Most of the work of the NCI Agency is conducted in the English language.
If youve read the description and feel this role is a great match wed love to hear from you! Click Apply for this job to be directed to a brief questionnaire. It should only take a few moments to complete and well be in touch promptly if your experience aligns with our needs.
Would you like to join the leading international intergovernmental organizationThe Penetration Testing Section of the NCSC conducts tailored penetration testing against NATO networks and systems. The team assesses the impact likelihood and difficulty of exploitation by advanced cyber adversaries sup...
Would you like to join the leading international intergovernmental organization
The Penetration Testing Section of the NCSC conducts tailored penetration testing against NATO networks and systems. The team assesses the impact likelihood and difficulty of exploitation by advanced cyber adversaries supporting accreditation IT change management software development assurance exercises and incident response. Reporting to the Team Lead the Senior Penetration Tester will be responsible for executing comprehensive penetration testing and vulnerability assessments to improve NATOs cyber hygiene and support its cyber defence posture.
Responsibilities:
Provide Web infrastructure and application-level penetration testing including but not limited to COTS software and NOTS/GOTS software (NATO/Government off the Shelf) following clearly defined methodologies.
Participate in kick-off meetings with stakeholders and technical points of contact in order to identify requirements for testing.
Follow the documented procedures and workflows outlined by the technical leads
Attend team meetings if required
Write technical reports in fluent English following defined templates and Reporting Tools.
Brief at both executive and technical levels on security reports and testing outcome including at flag officer level.
In case of new vulnerabilities detected for COTS software follow the Responsible Disclosure Process and follow-up with vendors and stakeholders.
In co-ordination with the Technical Lead of the Penetration testing team ensure proactive collaboration and coordination with internal and external stakeholders.
Stay abreast of technological developments relevant to the area of work.
Perform any other duties as may be required.
Essential Qualifications & Experience:
The service contractor will be required to have a Bachelor of Science (BSc) degree at a nationally recognised/certified university in a technical subject with substantial Information Technology (IT) content and 3 years post-related experience. As an exception the lack of a university degree may be compensated by the demonstration of a candidates particular abilities or experience that are of interest to the NCI Agency; namely at least 10 years of extensive and progressive experience in the duties related to the functions of this post.
Extensive knowledge and experience (at least 3 years) in the following areas:
Web application penetration testing
IT infrastructure penetration testing
Network security architecture design
Assessing security vulnerabilities within OS software protocols & networks
Researching and evaluating security products & technologies
Knowledge in system and network administration of UNIX and Windows systems
Use of penetration testing tools techniques and recognized testing methodologies
Scripting skills in at least one of the following: Python Go PowerShell shell (bash ksh csh)
Technical knowledge in system and network security authentication and security protocols cryptography application security as well as malware infection techniques and protection technologies.
Ability to evaluate risks and formulate mitigation plans.
Proven ability to brief at executive level on security findings reports and testing outcome.
Proven ability to write clear and structured technical reports including executive summary technical findings and remediation plan for several different audiences.
Desirable Experience and Education:
Professional qualifications: OSCP OSCE OSWE GPEN CREST Certified Web Application Tester GXPN GWAPT or equivalent
Familiarity with risk analysis methodologies.
Prior experience of working in an international environment comprising both military and civilian elements.
Knowledge of NATO organization internal structure and resultant relationships.
Language Proficiency:
A thorough knowledge of one of the two NATO languages both written and spoken is essential and some knowledge of the other is desirable.
NOTE: Most of the work of the NCI Agency is conducted in the English language.
If youve read the description and feel this role is a great match wed love to hear from you! Click Apply for this job to be directed to a brief questionnaire. It should only take a few moments to complete and well be in touch promptly if your experience aligns with our needs.
View more
View less