🌎
This job posting isn't available in all website languages

Team Lead Detection and Analysis

📁
Security
📅
251073 Requisition #

 

Who we are:

For more than 70 years, NATO’s mission has been to preserve peace and security in the Alliance for nearly one billion citizens. The NATO Communications and Information Agency (NCIA) and its predecessors have worked tirelessly in providing the means that enable the connectedness and togetherness that keep our Alliance strong. We are the NCIA, a team of 3000 civilian and military staff in 29 locations throughout Europe, North America and Asia.

Our technology and cyber experts allow NATO to conduct critical operations, protect NATO’s airspace, make data-driven decisions, defend against cyber-attacks, secure NATO networks and maintain superiority in space. This is all possible because of our greatest force, our people. In order to keep this edge we aim to hire, train and retain the very best staff.

Our staff members represent both the diversity and unity of our Alliance. When you join the NCIA, you will be part of an organization where you can contribute authentically to the mission and purpose of NATO and help us keep our technological edge.

 

 

About the job:

Based in Mons, Belgium you will join the Agency as we embark on a journey to transform our IT services to support NATO’s Digital Endeavour. You will join NATO Cyber Security Centre (NCSC), which is responsible for planning and executing all lifecycle management activities for cyber security. In executing this responsibility, NCSC provides specialist cyber security-related services covering the spectrum of scientific, technical, acquisition, operations, maintenance, and sustainment support, throughout the lifecycle of NATO Communications and Information Systems (CIS).

We are looking for a driven and enthusiastic Team Lead Detection and Analysis who will take on the following roles and responsibilities:

  • Lead a team composed of analysts and security tool managers, providing guidance, mentorship, and technical expertise to enhance threat detection and response capabilities;
  • Lead on the strategy for security detection content development in CSOC;
  • Develop and maintain detection content for tools, including Security Information Event Management (SIEM), Endpoint Detection and Response (EDR), and Network Detection and Response (NDR);
  • Develop and monitor detection content KPIs;
  • Conduct in-depth analysis of security alerts using on premise and cloud-based tools including SIEM, SOAR, EDR, NDR tools, and Full Packet Capture (FPC) systems;
  • Provide investigative support and guidance to escalated incidents, correlating logs, and determining the root cause of suspicious activities.

 

 

For a full list of duties, please review the job description on the NCI Agency career site.

 

 

 

About you:

The valuable knowledge and experience that you bring to this role are:

  • Bachelor’s degree at a nationally recognized/certified University in a related discipline and 3 years post-related experience. Or, exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate’s particular abilities or experience that is/are of interest to NCI Agency, that is, at least 10 years extensive and progressive expertise in duties related to the function of the post;
  • Previous experience of mentoring team members and resource management. Including delegating tasks, managing workloads, and reviewing performance;
  • Expert knowledge of writing security detection rules in formats such as Sigma, Snort, Suricata, Yara, and query languages such as KQL and SPL;
  • Expert knowledge of potential security event sources and their interpretation and analysis in support of the incident detection and handling processes;
  • Expert understanding of threat intelligence frameworks (MITRE ATT&CK, Cyber Kill Chain);
  • Excellent communications skills and reporting experience with capacity to communicate to different types of audience (senior executive, middle management, technical and non-technical);
  • Comprehensive understanding of the principles of Computer and Communication Security, networking, and the vulnerabilities of modern operating systems and applications acquired through a blend of academic or professional training, coupled with practical professional experience;
  • Recent practical, hands-on experience working within a SOC environment, in the field of Intrusion Detection and Monitoring & Analysis;
  • Extensive experience in the implementation and integration of Cyber Security protective measures;
  • Proficiency in managing detection content using Git or similar version control systems to track changes and collaborate;
  • Fluency in English, both written and spoken.

 

Note that the work is conducted mainly on site in Mons, Belgium.

 

 

What we offer:

  • Genuinely meaningful work as part of the most successful alliance in history;
  • 3 year contract with competitive tax-free salary and household and children’s allowances;
  • Privileges for expatriate staff including expatriation and education allowances (where appropriate) and additional home leave;
  • Excellent private health insurance scheme;
  • Generous annual leave of 30 days plus official holidays;
  • NATO Pension Scheme;
  • Development programs such as professional training, wellbeing, and more.

 

 

To learn more about NCI Agency and our work, please visit our website. 

 

The NCI Agency prides itself on being an equal opportunity employer. We are committed to fostering an inclusive environment of mutual respect and value uniqueness and differences in gender, gender identity, race, ethnic or cultural origin, age, religion, sexual orientation and physical or neurocognitive ability. 

 

Additional details on the conditions of application can be found via the NCI Agency career site.

 

Previous Job Searches

Similar Listings

Belgium

📁 Security

Requisition #: 250949

Belgium

📁 Security

Requisition #: 251040