Requirement: Type 3 Security Audit Remediation Support Engineer
Location: Mons, BELGIUM
Full Time On-Site: Yes
Time On-Site: 100%
Not to Exceed Rate: 71 EUR
Total Scope of the request (hours): 395
Required Start Date: 19 October 2026
End Contract Date: 31 December 2026
Required Security Clearance: NATO SECRET
Please do NOT apply for any NATO contract positions unless you meet ALL the following criteria:
- Current National or NATO SECRET clearance
- Nationality of one of the NATO member countries
- Current work visa for the specific location if applying for an in-country position
Duties & Role:
Under the direction of the Section Head, the contractor shall:
Perform vulnerability assessment and technical analysis, including but not limited to:
- Analyse the results of the vulnerability assessments when a new assessment is available.
- Prepare, for every assessment report, a remediation action plan and provide it to the appropriate technical point of contact not later than two working days after release of the assessment report;
- Interpret complex technical findings and provide remediation support to system administrators;
- Assess the technical impact of the vulnerabilities in order to prioritise remediation, for all remediation plans being tracked;
- Support vulnerability monitoring activities: review newly and publicly disclosed vulnerabilities and support the team in the preparation of NATO Security Bulletins.Perform remediation tracking and site coordination, including but not limited to:
- Act as the technical point of contact for remediation towards site administrators and system owners;
- Monitor and maintain the tracking of remediation activities for all open findings;
- Produce weekly and monthly progress reports for the various stakeholders;
- Chair technical coordination meetings with site administrators in order to resolve remediation roadblocks.
- Brief the monthly Enterprise Vulnerability Assessment Plan (EVAP) meeting, presenting the progress of the remediation activities;
- Participate in status update meetings, activity planning meetings and other meetings as instructed, on site or via conference call capabilities;
- Provide, at the end of the period of performance, a closure report summarising at high level the activities carried out.
Requirements
Skills, Knowledge & Experience:
- The candidate must have a currently active NATO SECRET security clearance
- A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience;
- Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work.
- At least 5 years of practical experience in vulnerability management, with proven experience within the last 6 months;
- At least 3 years of experience in testing and validating that contracted deliveries meet the security requirements and fulfil the intended use cases;
- General knowledge of cyber security principles, best practices, concepts and technology;
- Knowledge of cyber security architectures, including boundary protection, encryption, identity and access management, monitoring and detection, incident response, vulnerability assessments and risk management;
- Practical experience with vulnerability scanners and their output formats, such as Tenable Nessus, Qualys or OpenVAS;
- Demonstrated experience in producing remediation action plans and coordinating their implementation with system administrators across multiple sites.
- Ability to interpret complex technical findings and to translate them into actionable remediation guidance for system administrators;
- Scripting proficiency in Python (Pandas/NumPy) or PowerShell for parsing scan results and automating data handling;
- Ability to take ownership of tasks and strong motivation to accomplish them to the end, working both independently and within a team;
- Very good communication, analytical and writing skills;
- Language proficiency in English: meet or exceed the NATO STANAG 6001 Level 3 "Professional Proficiency".
- Relevant certifications in cyber security, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or GIAC Security certifications.


