Staff Officer (Cyber Security/Incident Response Manager)

NATO

• $100K — $120K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • University Degree in computer security, IT, computer science, or related field with 2 years of relevant experience, or Higher Secondary education with advanced vocational training and 4 years of related experience.
  • Minimum of five years practical experience in Cyber Security and risk management in a large organization.
  • Two years' experience managing contracted staff.
  • Experience in managing IT and Cyber projects and associated risks.
  • Good working knowledge of organizational change management and stakeholder management.

Responsibilities

  • Contribute to the implementation of the CISOA's role within HQ SACT and subordinate commands.
  • Perform real-time cyber defense incident handling tasks, including forensic collections and threat analysis.
  • Actively monitor networks and systems for cyber incidents and threats.
  • Conduct risk analysis and security reviews of system logs to identify cyber threats.
  • Develop and prepare cyber defense incident analysis and reporting.
  • Create a program development plan including security assessments and training manuals.
  • Liaise with HQ SACT Capability Development Directorate for emerging technologies.

Benefits

  • Opportunity to work in a dynamic and international environment.
  • Engagement in cutting-edge cybersecurity initiatives.
  • Access to professional development and training resources.
  • Collaboration with NATO and other military organizations.
  • Potential for career advancement within NATO structures.
Full Job Description
Post Context

ACT contributes to preserving the peace, security and territorial integrity of Alliance member states by leading, at Strategic Command level, Warfare Development required to enhance NATO's posture, military structures, forces, capabilities and doctrines.

The Resources and Management (RM) Directorate acts on behalf of SACT on all internal management and resource-related issues. It monitors the coherency of ACT plans to ensure that ACT remains an effective and efficient organization and improves continuously.

The ACT CIS, Data & Information (ACT CDI) Branch brings Information and Communications Technology (ICT) coherence across HQ SACT. It is in charge to implement at HQ SACT level all NATO policies and Directives in is area of responsibility. The ACT CDI is co-responsible with AOS (ACT Office of Security) of the HQ Cybersecurity, Cyber awareness and Cyber Hygiene. It is also critical enabler within the command and control of all HQ SACT staff tasking. This essential enabling support function provides coherency to the Command's IKM requirements delivers enhanced decision-making process opportunities and provides a central management function that guarantees the through-life cycle of all information and knowledge management within ACT.

Principal Duties:
  • Contribute to the implementation of the CISOA's role and responsibilities within HQ SACT and the subordinate commands (JWC, JFTC, JALLC, JATEC);
  • Perform real-time cyber defense incident handling tasks (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation)Conduct security triage to identify and analyze cyber incidents and threats;
  • Actively monitor networks and systems for cyber incidents and threats;
  • Conduct risk analysis and security reviews of system logs to identify possible cyber threats;
  • Conduct analysis and review, and/or apply network scanners, vulnerability assessment tools, network protocols, internet security protocols, intrusion detection systems, firewalls, content checkers and endpoint software;
  • Collect and analyze data to identify cyber security flaws and vulnerabilities and make recommendations that enable prompt remediation;
  • Develop and prepare cyber defence incident analysis and reporting;
  • Define and maintain tool sets and procedures;
  • Develop, implement, and evaluate prevention and incident response plans and activities, and adapt to contain, mitigate or eradicate effects of cyber security incident;
  • Provide incident analysis support on response plans and activities;
  • Conduct research and development on cyber security incidents and mitigations;
  • Create a program development plan that includes security gap assessments, policies, procedures, playbooks, and training manuals;
  • Review, develop and deliver relevant training material;
  • Contribute to the execution of the Security Accreditation Process in collaboration with ACT Office of Security;
  • Design, deploy and maintain the HQ SACT Cyber protection program which is to be complimentary to the capability output of HQ SACT. This must be considered a constantly changing environment, in particular enabling the communities of interest approach for staff work;
  • Ensure information/knowledge resources are protected whilst remaining readily accessible and easily retrieved;
  • Provide guidance on Cyber evolution across HQ SACT;
  • Increase staff awareness and the best practises for Cyber hygiene;
  • Contribute with NATO HQ and ACO to develop and maintain the NATO Cyber Security policies;
  • Ensure the HQ SACT Cyber Defence Posture Level is maintained in coordination with OCIO and allows the functions of the HQ to continue;
  • Develop and maintain external and internal relationships to enable the CDI Branch to achieve its aims;
  • Contribute to the Cyber Incident Management for ACT;
  • Liaise, when required with HQ SACT Capability Development Directorate (CAPDEV) for the development of current and emerging technologies to enable the development of cutting-edge tools, business management processes whilst protecting critical HQ information;
  • Assist with all aspects of CDI Branch as required by the Section Head.

Essential Qualifications / Experience:
  • University Degree in computer security, information technology, computer science or related discipline and 2 years function related experience, or Higher Secondary education and completed advanced vocational training in that discipline leading to a professional qualification or professional accreditation with 4 years post related experience.
  • A minimum of five years practical experience in Cyber Security and risk management, in a large military or civilian organization.
  • Two years' experience in managing contracted staff.
  • Experience in managing IT and Cyber related projects and the management of associated risks.
  • Good working knowledge of organizational change management processes and stakeholder management.

Language:

English - SLP 3333 - (Listening, Speaking, Reading and Writing)

Desirable Qualifications / Experience:
  • An understanding of a National or NATO Capability Management Process.
  • An understanding of DATA Analysis, Architecture and System Engineering.
  • P3 Course.
  • Managing Successful Programmes.
  • Prince 2 (Agile).
  • CNAFS (Purchase Requests).

Attributes/Competencies:

Personal Attributes:
  • The post requires a details oriented, rigorous person with strong interpersonal skills, able to understand how the practical execution of processes happens and is felt by others, and to translate this understanding in structured technical representations. At the same time, the post requires the ability to translate back from these technical representations in a way that is understandable and compelling to the people that will be affected by change. This requires precision, tact, adaptability, negotiation, and personal resilience. The ability to recognize, respect and deal with cognitive diversity is key.

Managerial Responsibilities:
  • No direct line management responsibility, but may oversee the work of contractor staff and be involved in leading ad hoc teams. May be involved in the direction, planning, coordination and review of the work of others.

Professional Contacts:
  • Have professional contacts with others inside and outside the organization/ provide advice and may negotiate. Could commit the organization to a COA.

Contribution To Objectives:
  • Involve analysis or research of a complete task with recommendations affecting plans of the Branch.

Security Clearance

The successful applicant will be required to apply for and receive a NATO SECRET Security Clearance prior to final confirmation of contract and commencement of employment.

Contract

This position is linked to a specific NATO project and is for a limited duration of 2 (two) years only.

Serving NATO International Civilian staff will be offered a contract in accordance with the NATO Civilian Personnel Regulations. Newly recruited staff will be offered a three year definite duration contract.

Notes for Candidates

The HQ SACT web site gives full details on the eligibility criteria and application processes to be adopted by all candidates. However, candidates should particularly note:

Please answer each of the pre-screening questions completely in English. Expressions such as: "please see attached CV, please see annex, please see enclosed document, etc" are not acceptable; this is a cause of immediate rejection of the application.

Particular attention should be given to Education and Experience section of your application form, which should be populated with details of your career to date and educational achievements and certifications as they relate to your application.

The candidature of NATO redundant staff at grade G15 will be considered with priority.

This vacancy will close on 26 October 2026 @ 18:59hrs (EDT)/11:59hrs (CET).

Similar Jobs

More Jobs at NATO

More Aerospace & Defense Jobs

Find similar Staff Officer (Cyber Security/Incident Response Manager) jobs: