Cyber Security Engineer (Security Accreditation) - BRU
Brussels · NCIA · NCIM Groep
Omschrijving
Duties
- Contributes to the development of solution architectures in specific business, infrastructure or functional areas by identification of applicable NATO security directives.
- Provides guidance on the application and operation of elementary physical, procedural and technical security controls.
- Explains the purpose of security controls and performs security risk assessments for communication and information systems.
- Identifies risks that arise from potential technical solution architectures.
- Suggests alternate solutions or countermeasures, which can mitigate identified risks.
- Defines and manages scoping, requirements definition and prioritisation activities related to security accreditation.
- Follows agreed standards and applies appropriate techniques to elicit and document detailed requirements related to security accreditation.
- Works with stakeholders to prioritise requirements and resolve conflicts.
- Provide security accreditation advice and guidance to NCI Agency Project, System Managers during whole life cycle of NATO CIS, including providing inputs to Project Proposals and Invitations for Bid.
- Conduct Security Risk Assessment in support of security accreditation of NATO CIS, in particular; identify level of threats and vulnerabilities for all assets comprising NATO CIS, derive residual risks and provide risk management recommendations.
- Identify, plan, request and manage development of required documents for accreditation (CIS Description, Security Accreditation Plan, Security Risk Assessment Report, Security Requirement Statements, Security Operating Procedures, and Security Test and Verification Plan).
- Witness security testing (in accordance with STVP) and coordinate remediation plan with the relevant SAA.
- Represent the Agency on security accreditation matters.
- Stay abreast of technological developments relevant to the area of work.
- Perform any other duties as may be required.
Requirement
- A minimum requirement of a Bachelor's degree at a nationally recognized / certified University in a related discipline and 2 years post-related experience.
- Exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 6 years extensive and progressive expertise in duties related to the function of the post.
- Relevant certifications, such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP).
- Good knowledge and experience (at least 2 years) in the following areas: Security Accreditation of major CIS acquisition and/or development projects for a large organization.
- Good knowledge and experience (at least 2 years) in the following areas: Security risk assessment methodologies and tools.
- Good knowledge and experience (at least 2 years) in the following areas: Planning, design and implementation of security components of major CIS.
- Good knowledge and experience (at least 2 years) in the following areas: Knowledge of NATO Security Policy and supporting directives.
- Prior experience of working in an international environment comprising both military and civilian elements.
- Knowledge of NATO responsibilities and organization, including Allied Command Operations (ACO) and Allied Command Transformation (ACT).
Je wordt doorgestuurd naar de website van NCIM Groep. ZZPdock is geen tussenpartij.