C003259 First Line Security Event Analyst
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Deadline Date: Friday 2 October 2026
Requirement: First Line Security Event Analyst (FLSEA)
Location: Mons, BE
Full time on-site: Yes
Time On-Site: 100%
Total Scope of the request (hours): 350
Required Start Date: 2 November 2026
End Contract Date: 31 December 2026
Required Security Clearance: NATO SECRET
Duties and Role:
As a First Line Security Event Analyst (FLSEA), the incumbent will perform initial analysis of logs and network traffic, determine alert severity and escalate when required. The analyst will collate information and present findings in a clear, structured format, providing remediation recommendations and first line response where applicable.
Main responsibilities:
Conduct research and assessments of security events within NATO Cyber Security Centre (NCSC)teamProvide analysis of firewall, IDS, anti-virus and other network sensor produced events and present findingsAppropriately leverage the comprehensive extended toolset ( Log Collection, Intrusion Detection, Packet Capture, VA, Network Devices etc.) for enhancing investigationsSupport the end-to-end Incident Handling processPropose optimisations and enhancements which help to both maintain and improve NATO's Cyber Security postureRequirements
Skill, Knowledge & Experience:
The candidate must have a currently active NATO SECRET security clearance. A university degree in a technical subject with a focus on Information Technology (IT), obtained from a nationally recognised/certified institution in addition to a minimum of 1 year experience in the field of cyber security analysis. The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis. Similarly, candidate's lacking experience can compensate by demonstrating a high level of knowledge in the field of cybersecurity.Comprehensive knowledge of the principles of computer and communications security including knowledge of TCP/IP networking, Windows and Linux operating systems Broad understanding of common network security threats and mitigation techniquesExperience in Security Information and Event Management products (SIEM) – ArcSight, SplunkExperience in Analysis of Network Based Intrusion Detection Systems (NIDS) events– SourceFire, Palo Alto Network Threat PreventionExperience in Log analysis from a variety of sources ( Firewalls, Proxies, Routers, DNS and other security appliances)Experience in Network traffic capture analysis using WiresharkLogical approach to analysis and ability to perform structured security investigations using large, complex data setsGood written and spoken communication skillsAbility to work independently and as part of a teamDesirable
Holding industry leading certification in the area of cyber security such as GCIA, GNFA, GCIHComputer Incident Response Centre (CIRT), Computer Emergency Response Team (CERT)Proficiency in Intrusion/Incident Detection and HandlingExperience in Full Packet Capture systems – Niksun, RSA/NetWitness Host Based Intrusion Detection Systems (HIDS) Experience in Computer security tools (Vulnerability Assessment, Anti-virus, Protocol Analysis, Anti-Virus, Protocol Analysis, Anti-Spyware, etc.)Experience in Computer forensics tools (stand alone, online and network)Experience in Military communication systems and networks