All jobs
Spektrum logo
Spektrum

194 open roles · NATO

Senior Cyber Security Engineer (Pen Tester)

Senior
Posted 2 years ago
Apply on company siteYou’ll apply directly with the employer on Greenhouse.
Added to ZestAmigo
Last seen on employer site

Where you can work

Unspecified

Locations named in the listing

  • Capellen, Luxembourg
  • Leeds, England, United Kingdom
View location wording from the posting
  • Capellen, Luxembourg
  • Leeds, England, United Kingdom

Employer description

Introduction

NSPA are looking for engineers to support their Cyber Security infrastructure to covering day to day and project activities, in addition providing Cyber Security services to NSPA customers or partners from across the NATO nations.

Day to Day Activities

  • Planning and carrying out the replacement of products or technologies within the infrastructure. This will involve developing time schedules, collaborating with the helpdesk, communicating with the customers, configuring the new equipment and performing the actual migration work. Following this, documentation and diagrams will have to be updated.
  • Operating and maintaining a wide variety of different cyber security solutions on a day-to-day basis, including but not limited to: Network firewall, web proxy, mail proxy and anti-spam, antivirus for servers, DMZ segregation, web application firewall, intrusion prevention, SIEM log correlation and reporting, managed file transfer, certificates, strong authentication etc.
  • Providing support on various cyber security tasks and operations, such as incident response, troubleshooting, change management, write and implement security procedures for operating security solutions, lifecycle management, security and risk assessments, etc.

Project Activities

  • Assessment of new cyber security products or technologies. This will involve researching the product, liaising with the manufacturer, arranging for a lab trial, conducting a test phase and then writing a report and making recommendations to NSPA.
  • Design and implementation of new secure solutions for various projects and to ensure that NSPA Cyber Security posture remains adequate and aligned with best practices.
  • Operating effectiveness testing and improvement of existing cyber security controls involving various cyber security technologies (including but not limited to network firewalls, Web Application firewalls, SIEM, Network IPS, e-mail protection, web browsing protection, Public Key Infrastructure, Medium and Strong authentication, etc.).
  • Cyber Security advisory and support provided for various customer projects.
  • Cyber Security penetration testing project.

Working Location

  • Main working location: Capellen, Luxembourg (NSPA HQ)
  • Some projects may require business travel to other sites
  • Some remote/hybrid work may be required

Working Hours

  • Monday to Thursday:
  • Arrival 06:00 to 09:00
  • Lunch break Minimum 30 minutes 11:45 – 13:45
  • Departure 16:15 to 20:00
  • Friday
  • Arrival 6:00 to 9:00
  • Departure 12:15 to 17:00
  • Public Holiday of Luxenberg will be applicable
  • Some on-call duties and weekend work will be required on a rotation basis

Project Duration

  • 3 years + 2 Years

Mandatory Requirements

  1. Professional Experience
  2. Proven experience of at least 5 years in IT Cyber Security.
  3. Proven experience of at least 1 year in a NATO environment.
  4. Proven experience and skills (Minimum 8 of the below)
  5. Next Generation Firewalls (including Intrusion Detection/Prevention System),
  6. Web Application Firewalls and Reverse Proxies,
  7. Web Proxies
  8. E-mail gateways
  9. Vulnerability Management
  10. Anti-malware, sandboxing and endpoint protection technologies
  11. Public Key Infrastructures (PKIs), smartcards and user authentication technologies
  12. Mobile Device Management (MDM)
  13. Apple infrastructure and iOS management
  14. Security Incident Event Management (SIEM)
  15. Multi-Factor authentication
  16. Privileged Access Management
  17. Good Knowledge - Ability to troubleshoot and solve issues involving the aforementioned technologies
  18. Skills
  19. Good Knowledge - Web application penetration testing
  20. Good Knowledge - Mobile application penetration testing
  21. Good Knowledge - Source code vulnerability analysis
  22. Good Knowledge - Ability to identify and exploit web vulnerabilities (XSS, CSRF, SQLi, SSRF, arbitrary file upload, etc.)
  23. Good Knowledge - Ability to identify and exploit mobile vulnerabilities (API issues, insecure storage, memory corruption, deep links, etc.)
  24. Good Knowledge - Network penetration testing experience
  25. Good Knowledge - Protocol analysis
  26. Good Knowledge - CTF experience
  27. Good Knowledge - Secure coding practices
  28. Good Knowledge - Cryptography
  29. Good Knowledge - Red and Blue team experience
  30. Proven knowledge of
  31. Good Knowledge - Cloud Architecture and Security
  32. Good Knowledge - Operating System (Windows and Linux) security and of Active Directory security
  33. Good Knowledge - Networking protocols
  34. Good Knowledge - Application Security
  35. Experience allowing to write scripts efficiently - Programming Skills in Bash or Python or Perl
  36. Good Knowledge - Offensive security tactics, techniques, tools and procedures
  37. Triage, following, procedures pro-active pivoting and hunting - Handling security alerts (ex: antivirus alert, suspicious email report)
  38. Good Knowledge - Handling security incident/intrusion
  39. Language
  40. Proficiency in English, written and oral, equivalent to CEFR B2 or higher
  41. Ability to write clear and concise reports and technical documentation with proper justification
  42. Ability to explain issues at different levels of the hierarchy and in particular to management
  43. Security Clearance
  44. Hold a valid NATO SECRET (or higher) security clearance
Track this application

Keep your own notes. Only you can mark an application as sent.

Report a problem with this listing

Sign in to report this listing.

More at Spektrum

Unspecified

Stavanger, Rogaland, Norway +1 more

Employment type unspecified

Salary unavailable

Posted 17 hours ago

Source: Greenhouse

Unspecified

Stavanger, Rogaland, Norway +1 more

Employment type unspecified

Salary unavailable

Posted 18 hours ago

Source: Greenhouse

Similar roles elsewhere