> Markdown version of [/jobs/ext/2662869-incident-response-specialist-threat-hunting-and-malware-analysis-for-nato-with-security-clearance](https://www.wearedevelopers.com/jobs/ext/2662869-incident-response-specialist-threat-hunting-and-malware-analysis-for-nato-with-security-clearance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Specialist (Threat Hunting and Malware Analysis) for NATO with security clearance - **Company:** WLG - **Location:** Bergen, Belgium - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Network Analysis, Cyber Security, Digital Forensics, Information Management, Intrusion Detection and Prevention, Knowledge Management, Language Modeling, Network Administration, TCP/IP, Software Vulnerability Management, Mitre Att&ck, Malware, Cybercrime, Vulnerability Analysis - **Published:** September 2, 2026 - **Apply:** https://www.adzuna.be/details/5865415412 ## About the Role * At least four years of hands-on incident response, or a directly adjacent field - digital forensics, threat hunting, or malware and network analysis * A thorough grasp of computer and communications security, networking, and where modern operating systems and applications actually break * Recent hands-on intrusion detection and response inside an enterprise-scale response team, ideally against the MITRE ATT&CK framework * At least three years in information and knowledge management, preferably in security * Working alongside IT service management * Very good communication and analysis, and professional English * Vulnerability assessment and scoring - CVSS, SSVC, coordinated disclosure * A relevant certification such as CISM, CISSP or a GIAC security qualification * A bachelor's degree in a related discipline with three years of related experience - or, exceptionally, ten years of progressive expertise in this kind of work Nice to have * A degree in cyber or IT security, or information management * Practical work or research on using AI and language models in defensive security * Vulnerability management end to end: ingestion, scoring, prioritisation, impact * An IT service management certification, and depth on security event sources and how to read them * Hands-on system and network administration, including TCP/IP engineering * Time in a large organisational response team, and contribution to recognised communities such as FIRST ## Description You would join the incident response team of a multinational defence organisation in Mons, Belgium, under the section head - responding to security incidents around the clock, and helping the wider alliance and its partners do the same. What you would be doing * Running incident response - triage, containment, eradication, recovery - in normal hours and on occasional call-out * Giving technical coordination and support to operating authorities across member and partner nations, non-governmental organisations and industry partners * Leading or supporting response teams sent out to extend that coverage to one or several physical locations, including on operations and missions * Building and maintaining the taxonomy behind the branch's information, and the content of the portals that sit on it * Designing and distributing the reports, briefings and dashboards that business owners, the operational community, service management and security people each need * Keeping a live network of security peers, so an urgent action can be coordinated when it is needed rather than when it is convenient * Finding and implementing improvements to the response process as the threats move * Writing the standard operating procedures and instructions that cover it all * Acting as the response expert in meetings across the organisation and in an incident task force ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)