Cyber Security Accreditation Support
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
Responsibilities
- Provide security accreditation advice and guidance to NCI Agency Project and System Managers across the full lifecycle of NATO CIS.
- Act as the focal point between NCI Agency and NATO Security Accreditation Authorities (SAAs).
- Build and sustain effective communications with Security Accreditation Boards, NATO SAAs, and NCI Agency organisational units supporting the accreditation process.
- Conduct Security Risk Assessments (SRA) in support of NATO CIS projects, including identification of threat levels and vulnerabilities for all assets comprising NATO CIS, derivation of residual risks, and provision of risk management recommendations.
- Identify, plan, request, and manage the development of all required accreditation documentation, including but not limited to the CIS Description, Security Accreditation Plan (SAP), Security Risk Assessment Report (SRAR), Security Requirement Statements (SRS), Security Operating Procedures (SecOPs), and Security Test and Verification Plan (STVP).
- Stay abreast of technological developments relevant to cybersecurity, network security, and cloud security.
- Provide subject‑matter related briefings and presentations to NCI Agency stakeholders and management.
- Coordinate and cooperate with activities across other Business Areas within NCI Agency.
- Perform any other related duties as directed by the section head.
Requirements
- The candidate must hold a university degree in Information Security, Telecommunications, Electronics, or Avionics.
- Alternatively, in the absence of such a degree, the candidate must have compensating relevant professional experience and hold at least one of the following certifications: CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), or CISM (Certified Information Security Manager).
- The candidate must have at least 2 years of experience in Security Accreditation of major Communication and Information Systems (CIS) within acquisition and/or development programmes for a large organisation.
- The candidate must have at least 2 years of experience applying security risk assessment methodologies and tools.
- The candidate must have at least 2 years of experience in the planning, design, and implementation of security components for major CIS.
- The candidate must have a proven ability to communicate effectively both orally and in writing.
- The candidate must have demonstrated briefing and presentation skills to senior stakeholders.
- Demonstrated interest and expertise in Cyber Security, Network Security, and Cloud Security is desirable and will be positively weighted during technical evaluation.
- Familiarity with international security standards, in particular ISO/IEC 27001, is desirable and will be positively weighted during technical evaluation.
- Experience working in or with NATO or other international defence organisations is desirable and will be positively weighted during technical evaluation.
- Any resource proposed for this Statement of Work requires a valid NATO SECRET security clearance prior to the start of the engagement.
Core Competencies
Demonstrates expertise in Security Accreditation processes and methodologies, with a strong focus on Cyber Security, Network Security, and Cloud Security. Proven ability to communicate effectively and deliver presentations to senior stakeholders while managing accreditation documentation and conducting Security Risk Assessments.