Incident Response Specialist (Threat Hunting and Malware Analysis) for NATO with security clearance

WLG
Bergen, Belgium
3 days ago
Apply on www.adzuna.be
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Network Analysis Cyber Security Digital Forensics Information Management Intrusion Detection and Prevention Knowledge Management Language Modeling Network Administration TCP/IP Software Vulnerability Management Mitre Att&ck
+3 more
Malware Cybercrime Vulnerability Analysis

Job description

You would join the incident response team of a multinational defence organisation in Mons, Belgium, under the section head - responding to security incidents around the clock, and helping the wider alliance and its partners do the same.

What you would be doing

  • Running incident response - triage, containment, eradication, recovery - in normal hours and on occasional call-out
  • Giving technical coordination and support to operating authorities across member and partner nations, non-governmental organisations and industry partners
  • Leading or supporting response teams sent out to extend that coverage to one or several physical locations, including on operations and missions
  • Building and maintaining the taxonomy behind the branch’s information, and the content of the portals that sit on it
  • Designing and distributing the reports, briefings and dashboards that business owners, the operational community, service management and security people each need
  • Keeping a live network of security peers, so an urgent action can be coordinated when it is needed rather than when it is convenient
  • Finding and implementing improvements to the response process as the threats move
  • Writing the standard operating procedures and instructions that cover it all
  • Acting as the response expert in meetings across the organisation and in an incident task force

Requirements

  • At least four years of hands-on incident response, or a directly adjacent field - digital forensics, threat hunting, or malware and network analysis
  • A thorough grasp of computer and communications security, networking, and where modern operating systems and applications actually break
  • Recent hands-on intrusion detection and response inside an enterprise-scale response team, ideally against the MITRE ATT&CK framework
  • At least three years in information and knowledge management, preferably in security
  • Working alongside IT service management
  • Very good communication and analysis, and professional English
  • Vulnerability assessment and scoring - CVSS, SSVC, coordinated disclosure
  • A relevant certification such as CISM, CISSP or a GIAC security qualification
  • A bachelor’s degree in a related discipline with three years of related experience - or, exceptionally, ten years of progressive expertise in this kind of work

Nice to have

  • A degree in cyber or IT security, or information management
  • Practical work or research on using AI and language models in defensive security
  • Vulnerability management end to end: ingestion, scoring, prioritisation, impact
  • An IT service management certification, and depth on security event sources and how to read them
  • Hands-on system and network administration, including TCP/IP engineering
  • Time in a large organisational response team, and contribution to recognised communities such as FIRST

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.be
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner ¡ LIVE

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 ¡ LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa ¡ LIVE

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn ¡ LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters ¡ World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all