> Markdown version of [/jobs/ext/2033675-cyber-security-section-head-trellix-epo-windows-hardening-cissp-for-nato-with-security-clearance](https://www.wearedevelopers.com/jobs/ext/2033675-cyber-security-section-head-trellix-epo-windows-hardening-cissp-for-nato-with-security-clearance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Section Head (Trellix ePO, Windows Hardening, CISSP) for NATO with security clearance - **Company:** WLG - **Location:** Ramstein-Miesenbach, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Wireless LAN, Antivirus Softwares, Cloud Computing, CompTIA Security+, Cyber Security, Information Systems, Information Leak Prevention, Disaster Recovery, VMware ESX Servers, IBM Service Management Framework, IPv4, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Network Security, Windows Servers, Public Key Infrastructure, Comptia Pentest+ CE, Information Technology Security Auditing, Storage Virtualization, VMware VSphere, Software Vulnerability Management, Forensic Toolkit, Computer Network Technologies, Tablet Computers, Mttr, Firewalls (Computer Science), Nessus, CIS Benchmarks, Vulnerability Analysis - **Published:** August 12, 2026 - **Apply:** https://www.adzuna.de/details/5837263598 ## About the Role * Five years or more of Windows Server security hardening - security baselines, policy enforcement, vulnerability mitigation and system compliance. * Three years or more with Trellix ePolicy Orchestrator and Trellix Endpoint Security, including Data Loss Prevention and Application Control, or an equivalent security suite. * Two years of system security, security architecture, network security engineering, security governance and risk management. * Detailed working knowledge of security and networking technology: IPv4, software firewalls, VPNs, intrusion detection and forensic tools. * Practical experience of wireless LAN technology and endpoint security across laptops, tablets and phones. * Security incident handling, reading the results of a security audit, and conducting risk assessments. * Supporting large NATO enterprise CIS estates, with a working understanding of the NATO command structure and of NATO security policy and its supporting directives. * CISM or CISSP certification. Also valued: CGRC/CAP or CASP+ (or Cloud+, PenTest+, Security+, GSEC or equivalent), ITIL v3 or v4 Foundation, and the NATO COMPUSEC Practitioner and CIS Security Officer courses. * Palo Alto enterprise firewalls, Public Key Infrastructure, and centralised endpoint security - antivirus, DLP, application control, drive encryption - plus vulnerability scanning with Nessus. * Windows Server 2022, 2019 and 2016, and Windows 10 and 11. * Server, network and storage virtualisation: VMware vSphere, ESX, NSX and vSAN. A grounding in cloud technology. * Familiarity with ITIL or another service management framework - incident, request fulfilment, problem, change and capacity management - and the basics of disaster recovery and business continuity (RPO, RTO, MTTR, MTBF, active-active and active-passive). * A bachelor's degree in a related discipline with two years of relevant experience. Exceptionally, six years or more of progressive experience in the same work can stand in place of the degree. * English to NATO STANAG 6001 level 3 (3333), or B2 to C1. * Previous work in an international environment with both military and civilian elements., Practical detail ## Description A NATO communications and information systems unit at Ramstein needs someone to own cyber security for the site. Not a monitoring seat: you would be the section head, with three or four cyber security and COMSEC people reporting to you, responsible for every part of the security picture from the boundary in. What you would be doing * Leading a team of three to four cyber security and COMSEC staff through day to day operations. * Owning the administration of all cyber security activity for the site, coordinated with the central NATO cyber security organisation - boundary protection management, data loss prevention and enterprise antimalware among them. * Applying and maintaining the specific security controls that policy and local risk assessments call for. * Running risk assessments for smaller information systems, identifying the risks that come with a proposed technical architecture, and suggesting the countermeasures that reduce them. * Defining secure system configurations that match the intended architecture. * Supporting the investigation of suspected attacks and security breaches. * Scheduling, coordinating and facilitating security audits and inspections, then managing the post inspection actions. * Supervising the monitoring, testing and evaluation of computer security systems, and the security side of CIS accreditation. * Planning and where necessary implementing cyber security services for the other parts of the organisation. * Explaining security risk to business managers in language they can act on. ## Related Videos - [IP Authentication: A Tale of Performance Pitfalls and Challenges in Prod](https://www.wearedevelopers.com/videos/1413-ip-authentication-a-tale-of-performance-pitfalls-and-challenges-in-prod) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)