Location: Münster, Germany (Onsite Full-Time)
Rate: €100-120 per hour
Contract Length: 30 Months (3920 hours) with extension option
Working Model: No remote working possible
Security Requirement: Security clearance/screening required for this assignment
Mapping cybersecurity risks and threats from a technical perspective and translating them into products used by 1GNC, by:
- Performing threat analysis from a technical perspective;
- Risk profiling from a technical perspective;
- Ensure the development and evaluation of technical use cases;
- Assessing and identifying use cases from a technical perspective;
- Developing technical use cases and evaluating and proposing improvements;
- Ensure the development and evaluation of threat and vulnerability mitigation measures - Assessing and identifying threat books from a technical perspective;
- Preparation of highly complex threat books.
- Assessment of non-standard change proposals with architecture impact on cybersecurity aspects, including participation in multidisciplinary IM/IT projects;
- Proactively analyzing and interpreting sources to detect IT phenomena that pose a new threat to the provision of services and documenting the findings;
- Ensure (real-time) analysis and interpretation of correlated log data and other sources based on known threats;
- (real-time) Reactive analysis and interpretation of correlated log data and other sources in case of escalation by other analysts.
- Determining the impact of identified threats and vulnerabilities and deciding on mitigation measures to be taken
- Commissioning of mitigating measures;
- Monitoring of mitigation orders issued;
- Deciding on escalation of vulnerabilities and threats outside the 1GNC; - Escalating vulnerabilities and threats to NATO/DEU and NLD within the security domain;
- Acting as security disaster manager during working hours
- Identifying business impact indicators.
- Ensuring the operation and quality of the connection of external system content to 1GNC equipment;
- Ensuring the management of the source data used within 1GNC including asset model and network model;
- Ensuring the management of the use case database;
- Ensuring that the relevant processes, procedures and work instructions are kept up to date.
- Establishment of technical maintenance and equipment frameworks within 1GNC;
Additional : Participating in working groups and meetings according to the battle rhythm of 1GNC, acting as information advisor to Chief Information Assurance and as Cyber advisor in the HQ in all aspects of C2 support, CIS, HQ organization as well as information security.
The work location for this position will be at the HQ 1 GNC (Headquarter), Schlossplatz 15, 48143 Muenster. Candidate must be willing to work in Münster full time. Strong preference for candidates already living in Germany , or candidates with a German background.
M ANDATORY Requirements:
- Proven working experience in a multi-national environment.
- Proven experience in working in a SOC (Security Operation Center).
- Proven experience in Security Information and Event Management.
- Proven experience in Cyber Incident Management.
- Experience/training/education with SIEM -LOGPoint, Elastic, Splunk.
- Experience with Incident handling processes - Security of critical infrastructures.
- Experience with Cyber Threat intel - MISP - Security Analytics.
- Proficient in English at level 3332.
- Knowledge of communications and/or information networks.
- Certified in Risk and Information Systems Control is preferred.
- University Master of Science Cybersecurity and Digital Forensics is preferred.
- Certified in ITIL is preferred.
- Cyber Threat intel Course is preferred.
- Cisco Certified Network Associate Course. Open-Source Intel Course is preferred.
- Proficiency in German language is preferred.
- Knowledge of Incident handling process for an area with inceased security requirements is preferred.
- Start date is subject to approval of screening (VGB Level A). The candidate is preferably available within 8-12 weeks or has a one-month notice period.
- Scale 12 Defence CLA
- Working from home is NOT possible


