Deadline Date:
Thursday 11 September 2025
Requirement:
Support for DevSecOps Engineering
Location:
Off-Site
Not to Exceed:
2025 BASE SPRINTS NTE € 4,700 / week for a total NTE € 50,760 (12 weeks)
2026 - 2027 - 2028 Options
Period of Performance:
BASE period: 13 October 2025
Required Security Clearance:
NATO SECRET
Please do NOT
apply for any NATO contract positions unless you meet ALL the following criteria:
- Current National or NATO SECRET clearance
- Nationality of one of the NATO member countries
- Current work visa for the specific location if applying for an in-country position
Introduction:
Supporting NATO throughout all its geographical locations, the NCI Agency is looking for Support for DevSecOps Engineering, joining the journey of NATO's modernization of IT services, through leveraging the public cloud (Microsoft Azure), delivering managed, protected, security-centric and reliable IT Services.
NCI Agency - Cloud Operations Team:
The NATO Communications and Information Agency (NCI Agency) is dedicated to supporting NATO's strategic objectives, including the ambitious NATO 2030 agenda. As part of this commitment, we are spearheading the modernization and digital transformation of NATO's IT services. Our focus is on leveraging public cloud technologies like Microsoft Azure, incorporating a security-by-design approach, and ensuring a seamless transition to a modern, collaborative workplace environment.
To achieve these goals, we are building a Cloud Operations Center team under the Cloud Portfolio, operating under the NATO Enterprise Cloud Operating Model (NECOM) and under the guidance of the Cloud Center of Excellence (CCoE). The NECOM framework provides a standardized approach for cloud service management, ensuring interoperability, scalability, and security across NATO's IT infrastructure. The Cloud Center of Excellence will serve as a hub for best practices, innovation, and expertise, driving the adoption and optimization of cloud technologies within NATO. This team will play a crucial role in our journey towards providing managed, protected, and reliable End User Services.
Embracing the latest technological advancements, this initiative will foster innovation and ensure NATO remains at the cutting edge of IT capabilities. By continuously evolving and integrating new technologies, we aim to enhance operational efficiency and readiness for future challenges. This remote position offers an exciting opportunity to be at the forefront of NATO's technological evolution and contribute to the security and efficiency of our operations.
NCI Agency - Cloud Centre of Excellence (CCoE):
The Cloud Centre of Excellence (CCoE) within the NCI Agency is focused on driving successful cloud adoption and maximizing the potential of cloud technologies across the organization. It serves as a central governing body, promoting best practices, enabling knowledge sharing, and ensuring alignment between business objectives and cloud initiatives. The CCoE supports various cloud-based solutions, ensuring their effective and efficient implementation and management. By fostering a culture of continuous improvement and innovation, the CCoE helps the NCI Agency leverage cloud technologies to enhance operational efficiency, scalability, and agility.
The ideal service will offer expertise in managing resources in Microsoft Azure Cloud by leveraging DevSecOps practices. Strong analytical, problem-solving, and organizational skills are required, along with the ability to document processes on Microsoft Azure services and DevSecOps tools and practices.
This service is critical for maintaining a secure and efficient cloud environment, supporting internal users and external collaborators.
Objectives:
- The NCI Agency is embracing cloud services by transitioning to Microsoft Azure with a security-centric design. This shift aims to enhance operational efficiency, collaboration, and security across the organization.
- The objective of this statement of work is to establish a support and operating model for End User Services operating in the Public Cloud.
The contractor will be part of a team providing Technical Level 2 and 3 support, ensuring the secure, available, managed and compliant delivery of Public Cloud Services to NATO and its Strategic Commands.
Under the direction / guidance of the IaaS/PaaS Team technical lead or the Cloud Operations Center Manager, the contractor will perform the following activities:
Operation of cloud infrastructure in Microsoft Azure by leveraging DevSecOps practices:
- Deploy and manage landing zones by utilizing DevSecOps practices to ensure a secure, scalable foundation for cloud workloads;
- Deploy and manage cloud workloads on top of the landing zones in an automated fashion;
- Utilize Infrastructure as Code and CI/CD pipelines through Azure Devops;
- Build, deploy and maintain containerized workloads using Azure Kubernetes Services (AKS);
- Deploy and monitor Azure Virtual Machines (VMs), including sizing, patching, backup, performance tuning and cost optimization;
- Build and maintain automated disaster recovery and backup solutions using services like Azure Backup, Site Recovery and storage replication;
- Monitor the performance and effectiveness of landing zones and cloud workloads;
- Identify opportunities for improvement and implement optimizations to enhance security and efficiency.
- Manage secure and reliable access to applications for end-users including configuration of Azure Application Gateways, Azure load-balancers and custom domains;
- Monitor Application availability, performance and security using services such as Azure Monitor, Log Analytics, Application insights and configure automated alerts;
- Provide support for Microsoft Azure Services - related issues, including troubleshooting access, networking and cloud resource specific issues;
- Maintain comprehensive documentation for Microsoft Azure Services processes, configurations, and workflows;
- Implement and manage governance controls such as Azure policies to ensure compliance with organizational standards;
- Ensure all deployed workloads and services adhere to Zero trust security principles, including proper network segmentation, identity-base access control and logging;
- Conduct regular audits and reviews of access controls and permissions.
- Collaborate with IT security, compliance, and other relevant teams to ensure cohesive cloud resources management strategies.
- Contribute to the lifecycle of cloud secure products in collaboration with the CTO CCOE to ensure reusable, secure and automated infrastructure modules
- Communicate effectively with stakeholders to understand IaaS and Paas requirements and address concerns.
- Identify opportunities to enhance efficiency through automation and proactively implement solutions.
- Champion continuous improvement by evaluating new Azure capabilities, DevOps tools and security practices and integrate them into operations.
- Lead operational readiness for new cloud solutions, by establishing runbooks, knowledge base transfer sessions and handover to support teams
The content and scope of each sprint will be agreed during the sprint‐planning meetings as covered in the section 4.
Coordination and Reporting:
- The contractor shall participate in daily status update meetings, activity planning and other meetings as instructed, via electronic means using Conference Call capabilities, according to the Cloud Operation Center Manager / Team Leaders instructions.
- This contractor hired for this position will be part of the NCIA Cloud Operations Center Team.
- Place of Performance: The contractor will be required to provide the service 100% off site NCI Agency.
- The contractor will be required to provide the service within a NATO country, following the rules and regulations applicable for the operations of NATO CIS.
- NCIA Recognised Business hours/Holidays: NCIA-Braine L'Alleud (BLA) official holiday schedule applies and will be provided to the contractor.
- NCIA Hours of Operations: Monday to Thursday 0830 - 1730 and Friday 0830 - 1530 (CET)
- Contractor Furnished Services: Contractor shall furnish everything required to perform the contract except for the items specified and covered under NCIA Furnished Property and Services below.
- NCIA Furnished Property and Services: End-device (laptop); Access to relevant networks and environments will be provided by NCIA
- Travel: The contractor is required to travel for the on-boarding and off-boarding to NATO offices in NATO HQ or Braine-l'Alleud as part of this role, for periods not exceeding 1 week.
- The contractor might be required to travel to NATO offices in NATO HQ or Braine-l'Alleud every 6 months for periods not exceeding 1 week.
- Travel will be the responsibility of the contractor and the expenses will be reimbursed in accordance with Article 5.5 of AAS Framework Contract and within the limits of the NCIA Travel Directive. The service provider, in accordance with the terms and conditions of the framework agreement, will invoice them separately to the purchaser. These additional travel costs are considered an extra charge to the overall bid price.
- Others: The service depicted in this SOW is expected to be carried by a SINGLE PERSON.
SECURITY
- To deliver services under this SoW a valid NATO SECRET security clearance is required. With this role being of technical nature providing administrative support, a security clearance at the NATO Secret level is required prior to the start of the engagement.
The Support for DevSecOps Engineering requires an experienced DevSecOps Engineer with the following qualifications:
Technical Expertise:
- In-depth knowledge of Microsoft Azure Cloud IaaS/PaaS Services;
- Proficiency in designing, deploying and managing landing zones in Microsoft Azure by leveraging IaC and CI/CD pipelines;
- Expertise in managing governance controls such as Azure Policy;
- Experience in building, deploying and maintaining containerized workloads using Azure Kubernetes Services (AKS);
- Experience in managing deploying and monitoring Azure Virtual Machines (VMs);
- Expertise in enabling secure and reliable access to applications for end- users.
- Strong analytical skills to assess and improve DevSecOps processes and workflows;
- Ability to troubleshoot complex Microsoft Azure Services issues and implement effective solutions.
- Understanding of security best practices and compliance requirements related to Microsoft Azure services and DevSecOps practices;
- Experience conducting audits and ensuring adherence to regulatory standards.
- Excellent communication skills to effectively collaborate with IT teams, stakeholders, and end-users;
- Ability to document processes clearly and provide training on Microsoft Azure Services and DevSecOps practices.
- Strong organizational skills to manage multiple tasks and priorities effectively;
- Attention to detail in managing user accounts, groups, and access controls.
- Ability to work effectively as part of a team and share knowledge and resources;
- Willingness to collaborate with colleagues to solve complex issues.
- The Contractor has strong customer relationship skills, including negotiating complex and sensitive situations under pressure;
- Full proficiency in the English language. French language proficiency is of advantage.