Network Security Tool Manager for NATO with security clearance

WLG
Bergen, Belgium
3 days ago
Apply on www.adzuna.be
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Cyber Security System Configuration Data Centers Linux Monitoring of Systems Intrusion Detection and Prevention Network Security Network Troubleshooting Packet Analyzer Security Information and Event Management Data Streaming Systems Integration
+5 more
Cybercrime Performance Monitor Firepower ArcSight Event Correlation Cisco

Job description

A NATO cyber security operations centre in Mons can only detect what it can see. The platforms that give it that visibility - security monitoring, traffic aggregation and full packet capture across many networks, sites and data centres - need one person who owns them properly. That is this role. What you would be doing

  • Delivering and maintaining the network visibility and security monitoring capability the operations centre works from.
  • Acting as the subject matter expert for the operation, configuration and lifecycle of security monitoring and packet capture technology.
  • Managing that lifecycle end to end: deployment, configuration, maintenance, upgrades, obsolescence and decommissioning.
  • Configuring and tuning monitoring, traffic aggregation and packet capture so the data collection is reliable and the analysis is worth doing.
  • Watching platform health, availability, data quality, retention, storage use and performance.
  • Finding and closing the visibility gaps that would otherwise blunt threat detection.
  • Troubleshooting Linux, network, connectivity, performance and data collection problems across the monitoring environment.
  • Keeping the documentation real - architecture diagrams, inventories, operating procedures, support information.
  • Supporting the design of new monitoring solutions, and their integration with the wider analytics and incident management tooling.
  • Working with the security analysts and the detection engineers so monitoring coverage keeps up with what they need to detect.
  • Capacity planning and scalability assessment, and the compliance, audit and assurance work that comes with cyber defence technology.
  • Supporting cabling, deployment planning and site surveys for monitoring and visibility infrastructure, and taking part in cyber defence exercises when they run.

Requirements

  • Expert knowledge of network security monitoring and cyber defence operations in an enterprise monitoring environment.
  • Extensive hands on experience supporting large scale, distributed security monitoring across multiple networks, sites, segments or data centres.
  • Enterprise experience with security monitoring and packet capture platforms such as Cisco Firepower, Corelight and NetWitness.
  • Strong hands on work with network visibility, traffic aggregation, packet brokers and packet capture.
  • Proven platform health and performance monitoring, capacity management, troubleshooting and operational governance.
  • An advanced understanding of enterprise networking - concepts, protocols, architectures and data flows.
  • Linux and network troubleshooting: connectivity, packet flow, interfaces, performance and system level diagnostics.
  • Practical experience of cabling, site surveys and the physical side of deploying monitoring infrastructure.
  • Strong knowledge of security telemetry collection, event correlation, threat detection and threat hunting.
  • English at NATO STANAG 6001 level 3, professional proficiency.
  • A relevant cyber security certification - CISM, CISSP or GIAC Security.
  • A bachelor’s degree in a related discipline with two years of relevant experience; exceptionally, six years or more of progressive experience in the same work instead.

Also valued

  • Designing large scale security monitoring and network visibility architectures.
  • Integrating monitoring tools with SIEM and SOAR platforms.
  • Automation, scripting or orchestration.
  • Major platform upgrades, migrations, refreshes and service transition.
  • Previous work in an international environment with both military and civilian elements, and a working knowledge of how NATO is organised., Practical detail

Benefits & conditions

  • Fully on site in Mons, Belgium, in a normal office environment. Equipment is provided for restricted information.
  • 5 October to 30 December 2026, 400 hours in total.
  • Occasional travel to other locations in support of operational duties, reimbursed under NATO travel rules. Travel inside the duty country counts as commuting.
  • You must hold a valid clearance and be a citizen of a NATO member country.

If you have kept a sensor estate honest at scale - and you know the difference between a dashboard that is green and a capture that is actually complete - this one is for you.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.be
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all