This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Lead and/or participate in Red Team and Blue Team activities during NATO military exercises. Conduct web application, infrastructure, and application-level penetration testing. Perform security design reviews to ensure compliance with NATO policies, directives, and security requirements. Provide security consultancy and expert guidance to projects, programmes, plans, and other stakeholders. Establish and maintain effective communication with key stakeholders, including the NCIA Configuration Control Board, Security Accreditation Boards, NATO Security Accreditation Authorities, and NCI Agency organizational units involved in accreditation processes.
Job Responsibility
Lead and/or participate in Red Team and Blue Team activities during NATO military exercises
conduct web application, infrastructure, and application-level penetration testing
perform security design reviews to ensure compliance with NATO policies, directives, and security requirements
provide security consultancy and expert guidance to projects, programmes, plans, and other stakeholders
establish and maintain effective communication with key stakeholders, including the NCIA Configuration Control Board, Security Accreditation Boards, NATO Security Accreditation Authorities, and NCI Agency organizational units involved in accreditation processes
Requirements
Minimum 3 years hands-on experience in web application penetration testing
IT infrastructure penetration testing
network security architecture and design
identification and assessment of security vulnerabilities across operating systems, software, protocols, and networks
research and evaluation of security technologies and products
system and network administration of UNIX and Windows environments
practical use of penetration testing tools, techniques, and recognized testing methodologies
scripting proficiency in at least one of the following languages: Perl, Python, Ruby, or Shell scripting (Bash, KSH, CSH)
strong technical expertise in system and network security, authentication mechanisms, security protocols, cryptography, application security, malware infection techniques, and protection technologies
ability to assess security risks and develop effective mitigation strategies and remediation plans