NIC Emerging Requirement 2022 Cyber Incident Responder (NATO-NCIA)

Mons, Belgium, Sapienza Consulting [C002171]

Field(s) of expertise
Information Technology
Job type

About this job

Sapienza Consulting, a tpgroup company, is recruiting a NIC Emerging Requirement 2022 Cyber Incident Responder to join NATO – NCIA in Mons, Wallonia, Belgium.


  • Provision of 24/7 Cyber Security Incident Response (TRIAGE, Contain, Eradicate, Recover) activities, during normal working hours and on-call duties, including weekends and holidays
  • Deliver of technical co-ordination, support and assistance in respect of Cyber Security Incident Response to NATO CIS Operating Authorities or other similar bodies as directed, including but not limited to, NATO Nations, Partner Nations, non-Governmental Organisations and Industry partners
  • Lead, be a member of, or support a Cyber Security Response Team designated to provide Cyber Security Incident Reponse happening on one or mutiple physical locations, including NATO Alliance Operations and Missions
  • Cyber Security Incident reporting activities in support of NATO CIS, reporting Security Incidents to the appropriate NATO Stakeholders as required
  • Identification and Sharing of technical Indicators of Compromise with the other NATO stakeholders, the NATO nations and our different partners, in accordance with our sharing agreements
  • Analysis, interpretation and dissemination of Security Advisories and Threat Intelligence Reports from NATO Nations, Partner Nations, non-Governmental Organisations and Industry partners
  • Redact, review and prepare reports, recommendations and presentations to the CDMB, Security Authorities and NATO IA communities on all aspects of Cyber Security Incident Response (TRIAGE, Contain, Eradicate, Recover)
  • Research to identify, document and implement improvements to the Incident Response (TRIAGE, Contain, Eradicate, Recover) activities in order to enhance and optimise current best practice to meet new and developing threats
  • Production of Standard Operating Procedures covering all aspects of Incident Response (TRIAGE, Contain, Eradicate, Recover) activities
  • Performs other duties as may be required


  • The candidate must have a NATO SECRET security clearance
  • A university degree at a nationally recognised/certified University in a technical subject with substantial Information Technology (IT) content and 4 years of specific experience. Exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate’s particular abilities or experience that is/are of interest to NCI Agency; that is, at least 10 years extensive and progressive expertise in the duties related to the function of the post



  • Excellent communications skills and reporting experience with capacity to communicate to different types of audience (senior executive, middle management, technical and non-technical)
  • Comprehensive understanding of the principles of Computer and Communication Security, networking, and the vulnerabilities of modern operating systems and applications acquired through a blend of academic or professional training coupled with practical professional experience
  • Recent practical, hands-on experience of Intrusion Detection and Incident Response (TRIAGE, Contain, Eradicate, Recover) in an enterprise-level Computer Emergency Response Team, ideally making use of the MITRE ATT&CK framework
  • Experience in interpreting the results of CIS Technical Security/Vulnerability Assessments



  • Hold a University degree in Cyber Security or IT Security-related discipline or Information Management
  • Hold relevant certifications such as Certified Information Systems Security Professional (CISSP), GCIH or GIAC/GCIM Security
  • Hold a professional certification on IT Service Management
  • In-depth knowledge of potential security event sources and their interpretation and analysis in support of the incident detection and handling processes
  • Practical hands-on experience in System and Network administration to include Network (TCP/IP) Engineering

For information on how the personal data in your application is processed, please see the Sapienza Consulting Privacy Policy.