Deadline Date:
Thursday 6 November 2025
Requirement Title: Support for DevSecOps Engineering
Location of Performance:
100% Off site
Cost Not to Exceed:
2025 BASED SPRINTS NTE € 4,266.00 / week for a total NTE €17,064.00 (4 weeks)
2026 - 2027 - 2028 Options
Period of performance:
BASE period: 8 December 2025
Evaluation Methodology:
Lowest Priced Technically Compliant
Required Security Clearance:
NATO SECRET
- Current National or NATO SECRET clearance
- Nationality of one of the NATO member countries
- Current work visa for the specific location if applying for an in-country position
The NATO Communications and Information Agency (NCI Agency) is dedicated to supporting NATO's strategic objectives, including the ambitious NATO 2030 agenda. As part of this commitment, we are spearheading the modernization and digital transformation of NATO's IT services. Our focus is on leveraging public cloud technologies like Microsoft Azure, incorporating a security-by-design approach, and ensuring a seamless transition to a modern, collaborative workplace environment.
To achieve these goals, we are building a Cloud Operations Center team under the Cloud Portfolio, operating under the NATO Enterprise Cloud Operating Model (NECOM) and under the guidance of the Cloud Center of Excellence (CCoE). The NECOM framework provides a standardized approach for cloud service management, ensuring interoperability, scalability, and security across NATO's IT infrastructure. The Cloud Center of Excellence will serve as a hub for best practices, innovation, and expertise, driving the adoption and optimization of cloud technologies within NATO. This team will play a crucial role in our journey towards providing managed, protected, and reliable End User Services.
Embracing the latest technological advancements, this initiative will foster innovation and ensure NATO remains at the cutting edge of IT capabilities. By continuously evolving and integrating new technologies, we aim to enhance operational efficiency and readiness for future challenges. This remote position offers an exciting opportunity to be at the forefront of NATO's technological evolution and contribute to the security and efficiency of our operations.
NCI Agency - Cloud Centre of Excellence (CCoE)
The Cloud Centre of Excellence (CCoE) within the NCI Agency is focused on driving successful cloud adoption and maximizing the potential of cloud technologies across the organization. It serves as a central governing body, promoting best practices, enabling knowledge sharing, and ensuring alignment between business objectives and cloud initiatives. The CCoE supports various cloud-based solutions, ensuring their effective and efficient implementation and management. By fostering a culture of continuous improvement and innovation, the CCoE helps the NCI Agency leverage cloud technologies to enhance operational efficiency, scalability, and agility.
The ideal service will offer expertise in managing resources in Microsoft Azure Cloud by leveraging DevSecOps practices. Strong analytical, problem-solving, and organizational skills are required, along with the ability to document processes on Microsoft Azure services and DevSecOps tools and practices.
This service is critical for maintaining a secure and efficient cloud environment, supporting internal users and external collaborators.
- The NCI Agency is embracing cloud services by transitioning to Microsoft Azure with a security-centric design. This shift aims to enhance operational efficiency, collaboration, and security across the organization.
- The objective of this statement of work is to establish a support and operating model for End User Services operating in the Public Cloud.
The contractor will be part of a team providing Technical Level 2 and 3 support, ensuring the secure, available, managed and compliant delivery of Public Cloud Services to NATO and its Strategic Commands.
Under the direction / guidance of the IaaS/PaaS Team technical lead or the Cloud Operations Center Manager, the contractor will perform the following activities:
Operation of cloud infrastructure in Microsoft Azure by leveraging DevSecOps practices:
- Deploy and manage landing zones by utilizing DevSecOps practices to ensure a secure, scalable foundation for cloud workloads;
- Deploy and manage cloud workloads on top of the landing zones in an automated fashion;
- Utilize Infrastructure as Code and CI/CD pipelines through Azure Devops;
- Build, deploy and maintain containerized workloads using Azure Kubernetes Services (AKS);
- Deploy and monitor Azure Virtual Machines (VMs), including sizing, patching, backup, performance tuning and cost optimization;
- Build and maintain automated disaster recovery and backup solutions using services like Azure Backup, Site Recovery and storage replication;
- Monitor the performance and effectiveness of landing zones and cloud workloads;
- Identify opportunities for improvement and implement optimizations to enhance security and efficiency.
- Manage secure and reliable access to applications for end-users includingconfiguration of Azure Application Gateways, Azure load-balancers and customdomains;
- Monitor Application availability, performance and security using services such asAzure Monitor, Log Analytics, Application insights and configure automatedalerts;
- Provide support for Microsoft Azure Services - related issues, includingtroubleshooting access, networking and cloud resource specific issues;
- Maintain comprehensive documentation for Microsoft Azure Services processes, configurations, and workflows;
- Implement and manage governance controls such as Azure policies to ensure compliance with organizational standards;
- Ensure all deployed workloads and services adhere to Zero trust security principles, including proper network segmentation, identity-base access control and logging;
- Conduct regular audits and reviews of access controls and permissions.
- Collaborate with IT security, compliance, and other relevant teams to ensure cohesive cloud resources management strategies.
- Contribute to the lifecycle of cloud secure products in collaboration with the CTOCCOE to ensure reusable, secure and automated infrastructure modules
- Communicate effectively with stakeholders to understand IaaS and Paas requirements and address concerns.
- Identify opportunities to enhance efficiency through automation and proactively implement solutions.
- Champion continuous improvement by evaluating new Azure capabilities, DevOps tools and security practices and integrate them into operations.
- Lead operational readiness for new cloud solutions, by establishing runbooks, knowledge base transfer sessions and handover to support teams
The content and scope of each sprint will be agreed during the sprint‐planning meetings as covered in the section 4.
Coordination and Reporting:
The contractor shall participate in daily status update meetings, activity planning and other meetings as instructed, via electronic means using Conference Call capabilities, according to the Cloud Operation Center Manager / Team Leaders instructions. This contractor hired for this position will be part of the NCIA Cloud Operations Center Team.
Constraints:
All the deliverables provided under this statement of work will be based on NCI Agency templates or agreed with the project point of contact. All code, scripts, documentation, etc. will be stored under configuration management and/or in the provided NCI Agency tools.
Security:
To deliver services under this SoW a valid NATO SECRET security clearance is required. All the deliverables of this project will be considered NATO UNCLASSIFIED, while access to networks exceeding this classification level is required. With this role being of technical nature providing administrative support, a security clearance at the NATO Secret level is required prior to the start of the engagement.
Practical Arrangements:
Place of Performance: The contractor will be required to provide the service 100% off site NCI Agency. The contractor will be required to provide the service within a NATO country, following the rules and regulations applicable for the operations of NATO CIS.
- NCIA Recognised Business hours/Holidays
- NCIA-Braine L'Alleud (BLA) official holiday schedule applies and will be provided to the contractor.
- Monday to Thursday 0830 - 1730 and Friday 0830 - 1530 (CET)
- Contractor shall furnish everything required to perform the contract except for the items specified and covered under NCIA Furnished Property and Services below.
- End-device (laptop)
- Access to relevant networks and environments will be provided by NCIA
- The contractor is required to travel for the on-boarding and off-boarding to NATO offices in NATO HQ or Braine-l'Alleud as part of this role, for periods not exceeding 1 week.
- The contractor might be required to travel to NATO offices in NATO HQor Braine-l'Alleud every 6 months for periods not exceeding 1 week.
- Travel will be the responsibility of the contractor and the expenses will be reimbursed in accordance with Article 5.5 of AAS Framework Contract and within the limits of the NCIA Travel Directive. The service provider, in accordance with the terms and conditions of the framework agreement, will invoice them separately to the purchaser. These additional travel costs are considered an extra charge to the overall bid price.
- The service depicted in this SOW is expected to be carried by a SINGLE PERSON.
Qualification:
The Support for DevSecOps Engineering requires an experienced DevSecOps Engineer with the following qualifications:
Technical Expertise:
- In-depth knowledge of Microsoft Azure Cloud IaaS/PaaS Services;
- Proficiency in designing, deploying and managing landing zones in MicrosoftAzure by leveraging IaC and CI/CD pipelines; .E
- xpertise in managing governance controls such as Azure Policy;
- Experience in building, deploying and maintaining containerized workloadsusing Azure Kubernetes Services (AKS);
- Experience in managing deploying and monitoring Azure Virtual Machines(VMs);
- Expertise in enabling secure and reliable access to applications for end-users.
- Strong analytical skills to assess and improve DevSecOps processes andworkflows;
- Ability to troubleshoot complex Microsoft Azure Services issues andimplement effective solutions.
- Understanding of security best practices and compliance requirementsrelated to Microsoft Azure services and DevSecOps practices;
- Experience conducting audits and ensuring adherence to regulatorystandards.
- Excellent communication skills to effectively collaborate with IT teams,stakeholders, and end-users;
- Ability to document processes clearly and provide training on Microsoft AzureServices and DevSecOps practices.
- Strong organizational skills to manage multiple tasks and priorities effectively;
- Attention to detail in managing user accounts, groups, and access controls.
- Ability to work effectively as part of a team and share knowledge andresources;
- Willingness to collaborate with colleagues to solve complex issues.
- The Contractor has strong customer relationship skills, including negotiating complex and sensitive situations under pressure;
- Full proficiency in the English language. French language proficiency is of advantage.
