# C005302 Cyber Security Incident Responder (NS) - MON 14 Sep

> EMW, Inc. · Mons, Belgium · Contract · Posted 2026-09-01

**Workplace:** on_site

**Department:** AAS

## Description

**Deadline Date:** Monday 14 September 2026

**Requirement:** Cyber Security Incident Responder

**Location:** Mons, BE

**Full Time On-Site:** Yes

**Time On-Site:** 100%

**Total Scope of the request (hours):** 395

**Required Start Date:** 20 October 2026

**End Contract Date:** 31 December 2026

**Required Security Clearance:** NATO SECRET

**Duties & Role:**  

Under the direction of the Section Head of the CSIRT, the contractor shall:

-   Provision 24/7 Cyber Security Incident Response (Triage, Contain, Eradicate, Recover) activities, during normal working hours and occasional on-call duties, including weekends and holidays
-   Deliver technical coordination, support, and assistance in respect of Cyber Security Incident Response to NATO CIS Operating Authorities, including but not limited to: NATO Nations, Partner Nations, non-Governmental Organisations and Industry Partners.
-   Lead, be a member of, or support Cyber Security Response Teams designated to extend the NCSC Incident Response coverage to one or multiple physical locations, including within the NATO Alliance Operations and Missions.
-   Build, manage the lifecycle of, and maintain the taxonomy related to the Branch's information.
-   Manage the content of different information portals within the agreed taxonomy.
-   Design, create and distribute a variety of reports, briefings and dashboards, to different communities, including: (Business owners, operational community, IT service management, cyber security)
-   Maintain a network of cyber security peers across and beyond the NATO Enterprise to facilitate communications and coordination of urgent actions when the need arises.
-   Research and identify, document and implement improvements to the Incident Response activities, in order to enhance and optimise current best practice to meet new and developing threats.
-   Produce Standard Operating Procedure and Instructions covering all aspects of Incident Response.
-   Participate in, and act as an Incident Response subject matter expert, in various meetings: within the CSIRT, across the sections in the Defend branch, across the NATO Enterprise, including within the NICC, CMAWG, CRMG and other Enterprise-level meetings, as well as within the context of a Cyber Incident Task force.

**Specific Working Conditions:** Normal working hours 0830-1730. Occasional on-call duties after working hours, on weekends or holidays are required.

In case of a major Cyber Security Incident, the incumbent may be required to work extended hours and on shifts, including nights and weekends, to provide a 24/7 Cyber Security Incident Response.

**Travel required:** The contractor may be required to travel to NCIA locations in Belgium for in-person or department meetings. In such cases the contractor will be reimbursed for travel costs according to NATO regulations for traveling on NATO duty. Each travel will be a maximum of 2 days lengths and happening no more than once per 2 months. Contractors traveling for work purposes shall initiate travel requests from their designated duty station only.

## Requirements

**Skills, Knowledge & Experience:**

-   The candidate must have a currently active NATO SECRET security clearance
-   A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience;
-   Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work.
-   At least 4 years practical experience in cyber security incident response, or a directly connected field such as network analysis, digital forensics, malware analysis or threat hunting. It is noted that Industry often separates responsibilities in such a way that personnel in these roles may also be performing incident response;
-   Comprehensive understanding of the principles of Computer and Communication Security, networking, and the vulnerabilities of modern operating systems and applications acquired through a blend of academic or professional training coupled with practical professional experience;
-   Recent practical, hands-on experience of Intrusion Detection and Incident Response (TRIAGE, Contain, Eradicate, Recover) in an enterprise-level Computer Emergency Response Team, ideally making use of the MITRE ATT&CK framework;
-   At least 3 years experience in Information and Knowledge Management, ideally in the field of Cyber Security
-   Experience in interfacing with IT Service Management.
-   Very good communication and analytical skills.
-   Language proficiency in English: meet or exceed the NATO STANAG 6001 Level 3 "Professional Proficiency".
-   Knowledge of vulnerability assessment and scoring (CVSS, SSVC, CVD)
-   Relevant certifications in cyber security, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or GIAC Security.

Desirable Experience and Education:

-   Hold a University degree in Cyber Security or IT Security-related discipline or Information Management.
-   Practical experience working with, and/or formal research, of the use of AI/LLM within Cyber Security Defense (not from a red team / penetration testing perspective)
-   Practical experience in the management of vulnerabilities, from ingestion, scoring, assessing prioritization of, and potential impact to CIS
-   Hold relevant certifications such as Certified Information Systems Security Professional (CISSP), GCIH or GIAC/GCIM Security (this list is not exhaustive)
-   Hold a professional certification on IT Service Management.
-   In-depth knowledge of potential security event sources and their interpretation and analysis in support of the incident detection and handling processes
-   Practical hands-on experience in System and Network administration to include Network (TCP/IP) Engineering
-   Experience in working for or supporting a military or governmental organization.
-   Recent experience in a large organisational CERT, especially within the Incident Response Team.
-   Experience in actively contributing to industry recognized communities for incident response, such as FIRST.org.

## Apply

[Apply at EMW, Inc.](https://apply.workable.com/emw/j/D89B0F16AB/apply)

---
Powered by [Workable](https://www.workable.com)
