RoleCall

ICT Security Accreditation Expert

Spektrum· Brussels, Belgium·

cloudcyber-security

Spektrum have a wide range of exciting opportunities in several global locations.  We are always looking to add great new talent to our team and look forward to hearing from you.

Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.


Who we are supporting 

The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.

The NCIA provides a wide range of services, including:

  • Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.
  • Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.
  • Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
  • Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.
  • Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers.

Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities.

The program

Assistance and Advisory Service (AAS)

The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.

To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.


Role ID – NATOIS-0042

Role Profile

The Information and Communication Technology Management (ICTM) Directorate has a portfolio of ICT-related projects with a diverse nature, some rather infrastructure related and others related to software acquisition and development. ICTM has a requirement for an expert in ICT security accreditation/approval for these projects. Their efforts will focus on supporting the work of the Security Accreditation Authority being the JISD/NOS, by overseeing the security approval/accreditation process for ICT-related projects and contribute to CIS Security Risk Management activities: reviewing security-related documents, security risk assessments, security audit reports and remediation plans, and attending security-related meetings when required.

Role Background

Division: International Staff (IS) - ICTM

Mission: The ICTM Directorate provides support and services to the North Atlantic Council (NAC), its Committees, IS staff, and, when required, to Member and Partner Nation Delegations based in the HQ. The Directorate comprises of two pillars: Information Communication Technology (ICT) and Digital Information Management Services (DIMS).

Vision: ICTM is a recognised and trusted Directorate for the implementation of ICT-related projects for the IS. PRINCE2 has been adopted as methodology. In order to guarantee the (cyber-) security of systems that are being implemented, ICTM follows a security approval process, agreed by the Security Accreditation Authority being the JISD/NOS. As part of this process, security-related documentation needs to be submitted to a variety of stakeholders for review and approval.

They will be embedded in the Security Accreditation Authority, being the Joint Intelligence and Security Division/NATO Office of Security (JISD/NOS), in order to enable the Security Approval/Accreditation Process of ICTM-led projects. In the past years ICTM and JISD/NOS have developed templates and examples of the documentation set that needs to be submitted as part of a Security Approval/Accreditation Process, as well as specific procedures applicable within the NHQ CIS Governance. These templates and procedures will be made available to the expert.

Role Duties and Responsibilities

  • Security Accreditation/Approval and CIS Security Risk Management:
    • Review and contribute to the security-related documents or Approval/Accreditation Documentation Sets (ADS) from ICT-projects including but not limited to NonFunctional Requirements (NFRs), which is part of the Statement of Work (SoW), the Security Approval/Accreditation Plans, Security Risk Assessments, Security Requirements Statements, Security Test and Verifications, Security Audit Reports, etc.;
    • Draft security recommendations and Security Approval/Accreditation letters
  • Security Architecture:
    • Provide security-related advice and guidance to project managers and other project stakeholders regarding security design matters throughout the entire project lifecycle, including security approval-related activities;
  • Project Team member:
    • As required, to develop security-related documentation such as Security Risk Assessment (SRA), based on project scope
  • Make recommendations as necessary on how to improve the existing processes or templates
  • Represent the team in internal meetings related to cybersecurity and support security-related decision when representing the team in CIS security-related Boards.
  • Development of Security Accreditation/Approval Plan;
  • Review of Accreditation/Approval Documentation Sets;
  • Assess Security Accreditation/Approval requests;
  • Advice and Guidance to Project Managers;
  • Contribute to the continuous improvement of internal processes;
  • Other security-related duties as required by the NATO supervisor.

Essential Skills, Experience and Certifications

  • Minimum 8 years of experience in ICT security-related functions;
  • Proven, strong expertise in ICT security architecture and security accreditation/approval;
  • Experience in participating in ICT systems and applications implementations.
  • Experience in both on-premise and cloud deployments.
  • Ideally, they should also have experience in working:
    • in an international organization or governmental environment.
    • in a classified environment.
    • within complex multi-stakeholder environments.
  • Proven understanding and technical knowledge of the ICT infrastructure & security services (directory services, database, PKI, firewall, etc.), latest software technologies either onpremises or cloud-based;
  • Good understanding of project management methodologies and tools (e.g. PRINCE2);

Desirable Skills, Experience and Certifications

  • Knowledge and practice of NATO CIS security related directives.
  • National certification on cybersecurity risk management or security accreditation processes (e.g. Prestataires d’accompagnement et de conseil en sécurité des systèmes d’information (PACS), IT-Grundschutz, ENS)
  • Artificial Intelligence (AI) security knowledge

Education

  • Technically oriented university degree (information management, electronic engineering, etc.) or equivalent completed advanced vocational training;

Language Proficiency

  • Business English

Working Location

  • Brussels, Belgium

Working Policy

  • On-site

Travel

  • Some travel to other NATO sites may be required

Security Clearance

  • Valid National or NATO Secret personal security clearance

We never know what new opportunities might be just over the horizon. If this opportunity isn't for you, please feel free to send us your resume anyway and be the first to know if something suitable for your skills and experience comes up. 

ICT Security Accreditation Expert at Spektrum · RoleCall