SC2024-003533 Senior Online Vulnerability Assessment Analyst (CTS) - THU 9 May

Mons, Wallonia, Belgium

Deadline Date: Thursday 9 May 2024

Requirement: Senior Online Vulnerability Assessment (OVA) Analyst

Location: Mons, BE

Full Time On-Site: Yes

Time On-Site: 100%

Total Scope of the request (hours): 980

Required Start Date: 25 June 2024

End Contract Date: 31 December 2024

Required Security Clearance: NATO COSMIC TOP SECRET

Duties and Role:

Under the direction of the NCSC Security Compliance (OVA) Cell Head/Service Delivery Manager, the incumbent shall execute following tasks:

  • Configure and maintain the following modules part of the OVA solution in order to collect and provide accurate information to the stakeholders: Credentials and authentication methods; Scan Policies; Scan Jobs/Tasks; Audit Files; Assets groups; Report templates
  • Troubleshoot any issues in regards of the OVA scans.
  • Escalate to the OVA Tool Manager any issues that cannot be fixed by the Senior OVA Analyst
  • Daily Analyst and Prioritization of the found vulnerabilities.
  • Weekly / Monthly report the found vulnerabilities, remediation actions taken and status.
  • Support, maintain and improve the OVA data processing procedures
  • Maintain and improve scripted modules part of the OVA data processing procedures
  • Maintain and improve the SQL storage procedures part of the OVA data processing
  • Create, maintain and improve Power BI reports
  • Collaborate with other members of the NATO Security Teams to ensure the protection of enterprise assets.
  • Stay current with emerging security threats and technologies.
  • Keep weekly communication with the CIS personnel of each site under your area of responsibility.

Deliverables and Expected Outcomes:

Under the direction of the NCSC Security Compliance (OVA) Cell Head/Service Delivery Manager, the incumbent shall deliver the following:

  • Daily: verify that the OVA scans are configured correctly and that the information collected is accurate.
  • Weekly: after analysing the data, deliver a comprehensive vulnerability reports to each stakeholder / CIS personnel under you area of responsibility taking into account all vulnerabilities posing a security risk, remediation actions recommended to the system/application owners and the status of the recommended actions. The weekly report is expected to be delivered each Wednesday/Thursday before Close of Business. No weekly report is due if that week does not include any working day (for instance: long official holidays such as Christmas break).
  • Monthly: deliver vulnerability report to the stakeholders / CIS personnel, with an overview of the critical/high vulnerabilities identified, the status of the recommended actions to show in a graphic way the trend of the security posture of CIS assets. The monthly report is expected to be delivered in the week of Microsoft patch Tuesday (second Tuesday of the month).

Performance Standards

  • Timely delivery of the reports as specified on the deliverables and expected outcomes Section.
  • Quality of the content of the reports will be assessed regularly by the SDM / SAO.
  • The reports shall contain key elements of the vulnerabilities identified, systems affected, time of discovery of the vulnerability, time of communicating the vulnerability to the system/application owners, status of the actions recommended to mitigate/remediate the identified vulnerability together with any other relevant information that will provide an additional value to the report.

Requirements

Skill, Knowledge & Experience:

  • The candidate must have a currently active NATO COSMIC TOP SECRET security clearance
  • Bachelor's degree in Computer Science, Information Technology, or related field Or equivalent experience
  • 3+ years of experience in IT security, with a focus on Security Audit and / or Security Assessment of large organisation
  • Strong understanding of security best practices and experience with Tenable products specially with Tenable Security Center
  • Strong knowledge and hands-on in SQL database scripting and Power BI
  • Strong knowledge of python (pyTenable) and PowerShell.
  • Experience working with Tenable.SC and Nessus Manager APIs
  • Strong analytical and problem-solving skills
  • Excellent communication and collaboration skills
  • The incumbent shall be able to understand and interpret the outcomes of security audit reports
  • Experience with threat intelligence, incident response and remediation a plus
  • Knowledge of NATO organization and its IT infrastructure is a plus
  • Certifications such as CISSP, CISM, or CISA is a plus.

 

Apply now Apply later
  • Share this job via
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: APIs Business Intelligence CISA CISM CISSP Clearance Compliance Computer Science Incident response IT infrastructure NATO Nessus PowerShell Python Scripting Security assessment Security Clearance SQL Threat intelligence Top Secret Vulnerabilities

Region: Europe
Country: Belgium
Job stats:  3  0  0
Category: Analyst Jobs

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.