Requirement: Technical Lead Architect Support Services for the ITM Recovery Project
Location: The Hague, NETHERLANDS
Cost Not to Exceed: Base 2026: 16,425 EUR /Month
Period of Performance: As soon as possible: 13 October (Tentative) 2026 until 31 December 2026.
Required Security Clearance: NATO SECRET
Please do NOT apply for any NATO contract positions unless you meet ALL the following criteria:
- Current National or NATO SECRET clearance
- Nationality of one of the NATO member countries
- Current work visa for the specific location if applying for an in-country position
Introduction
The ITM Recovery Increment 1 (ITM RC1) project will replace the legacy Automated Information Systems (AIS) NS classification network with a modernized ITM Operational Network (ON) at NS in a private cloud across the NATO Command Structure (NCS). The project structure includes 14 Work Packages, organized in 4 pillar teams with about 30 people interacting daily with each other and externally too. This task falls under WP07 System Integration scope.
Scope of Work
Architecture Validation & Guidance
- Review and validate the design documents for the private air-gapped cloud (vCF 9, NSX-T, Cisco ACI), identifying gaps, risks, and non-conformances against best practices, dependencies and overarching NATO architecture and directives documents.
- Provide design guidance to infrastructure and platform teams throughout the implementation lifecycle.
- Define and maintain architecture decision records (ADRs) and ensure traceability from requirements to design.
- Define and specify Interface Control Documents (ICDs) between the private cloud infrastructure and all producer/consumer services.
- Ensure interfaces are designed with security, observability, and automation in mind.
- Maintain an interface register and track ICD sign-off across workstream owners.
- Coordinate design and implementation efforts between the cyber security team and the infrastructure team, specifically covering: Privileged Access Management (PAM) implementation via CyberArk; PKI design and certificate lifecycle management; and Cyber Security Monitoring capability integration with the private cloud.
- Chair or co-chair joint design sessions and resolve cross-team technical dependencies.
- Validate and guide implementation of infrastructure automation using Ansible / AAP, Terraform, Jenkins, and vCF Automation.
- Define the automation and IaC target operating model for the cloud platform team.
- Advise on and document the transition from traditional infrastructure support to an automation-first operating model.
- Support upskilling of cloud operating teams in automation principles and tooling.
Platform & Infrastructure:
- Hands-on experience with VMware vCF 5; working knowledge of vCF 9 (direct vCF 9 experience strongly preferred).
- Experience designing or validating NSX-T software-defined networking at enterprise scale.
- Familiarity with Cisco ACI in a multi-site or data centre context.
- Experience with Backup and Recovery solution and implementation.
- Demonstrable experience applying Security by Design principles (e.g. Zero Trust Approaches) to private cloud or data centre environments.
- Direct experience with CyberArk PAM implementation and integration.
- Understanding of PKI design and certificate management in enterprise environments.
- Hands-on experience with two or more of: Ansible / AAP, Terraform, Jenkins, vCF Automation.
- Experience leading or supporting the adoption of IaC practices within an infrastructure or cloud operating team.
- Ability to produce and maintain ADRs, ICDs, and architecture review reports to a professional standard.
- Experience coordinating across security, infrastructure, and application teams in a complex enterprise programme.


