Cyber Security Engineer — Security Accreditation and RiskAssessment for NATO with security clearance
Il y a 1 jour
Brussels, Brussels, Belgique
WLG
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
Before a classified system goes live, somebody has to
be able to say what the risks are, what controls answer them, and
what is left over. A multinational defence organisation is looking
for the engineer who does that work: the assessment, the paperwork
that carries it and the conversations with the authorities who sign
it off. What you would be doing Contributing to solution
architecture in your areas by identifying which security directives
actually apply. Advising on how physical, procedural and technical
security controls are applied and operated, and explaining plainly
what each one is for. Running security risk assessments for
communication and information systems: the threats, the
vulnerabilities across every asset, the residual risk and what to
do about it. Spotting the risks a candidate technical architecture
creates, and proposing alternatives or countermeasures rather than
only objections. Scoping, defining and prioritising the
requirements that accreditation depends on, to agreed standards and
with the evidence written down. Working with stakeholders to
prioritise those requirements and to resolve the conflicts between
them. Advising project and system managers across the whole life of
a system, including input to project proposals and invitations to
bid. Planning, requesting and managing the documents accreditation
needs — system description, accreditation plan, risk assessment
report, security requirement statements, operating procedures and
the test and verification plan. Witnessing security testing and
agreeing the remediation plan with the accrediting authority.
Building durable working relationships with accreditation boards,
national authorities, system operating authorities and the internal
teams that support the process, and representing the organisation
on accreditation matters. What you would bring A bachelor's degree
from a recognised university in a related discipline with two years
of relevant experience behind it. Exceptionally, around six years
of progressive expertise in this kind of work can stand in place of
the degree. At least two years across each of the areas the post
turns on: accreditation of major system acquisition or development
projects in a large organisation; risk assessment methods and
tooling; and the planning, design and implementation of security
components. Working knowledge of the organisation's security policy
framework and its supporting directives. Time spent in an
international environment with both military and civilian
colleagues, and a working picture of how the alliance's commands
are organised. Relevant certification such as CISA or CISSP.
English you can defend a risk position in, in writing and in front
of a board. Extensions are offered where the work goes well.
Applications are reviewed as they arrive.