Senior Online Vulnerability Assessment (OVA) Analyst

at  Spektrum

Mons, Wallonie, Belgium -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate29 Jul, 2024Not Specified30 Apr, 20243 year(s) or aboveIt Infrastructure,Incident Response,Cisa,Threat Intelligence,It Security,Computer Science,Remediation,Power Bi,Sc,Database Scripting,Tenable,Powershell,Information Technology,Cissp,PythonNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

Spektrum have a wide range of exciting opportunities in several global locations.
We are always looking to add great new talent to our team and look forward to hearing from you.
Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.

WHO WE ARE SUPPORTING

The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO’s member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.

The NCIA provides a wide range of services, including:

  • Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO’s communication networks and information systems against cyber threats.
  • Command and Control Systems: The NCIA develops and maintains the systems used by NATO’s military commanders to plan and execute operations.
  • Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
  • Electronic Warfare: The NCIA provides electronic warfare services to support NATO’s mission to detect, deny, and defeat threats to its communication networks.
  • Information Management: The NCIA manages NATO’s information technology infrastructure, including its databases, applications, and servers.

Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO’s communication and information technology capabilities.

ESSENTIAL SKILLS AND EXPERIENCE

  • 3+ years of experience in IT security, with a focus on Security Audit and / or Security Assessment of large organisation
  • Strong understanding of security best practices and experience with Tenable products specially with Tenable Security Center
  • Strong knowledge and hands-on in SQL database scripting and Power BI
  • Strong knowledge of python (pyTenable) and PowerShell. Experience working with Tenable.SC and Nessus Manager APIs
  • Strong analytical and problem-solving skills
  • Excellent communication and collaboration skills
  • The incumbent shall be able to understand and interpret the outcomes of security audit reports

DESIRABLE SKILLS AND EXPERIENCE

  • Experience with threat intelligence, incident response and remediation a plus
  • Knowledge of NATO organization and its IT infrastructure is a plus
  • Certifications such as CISSP, CISM, or CISA is a plus.

EDUCATION

  • Bachelor’s degree in Computer Science, Information Technology, or related field Or equivalent experience

Responsibilities:

Under the direction of the NCSC Security Compliance (OVA) Cell Head/Service Delivery Manager, the incumbent shall execute following tasks:

  • Configure and maintain the following modules part of the OVA solution in order to collect and provide accurate information to the stakeholders:
  • Credentials and authentication methods
  • Scan Policies
  • Scan Jobs/Tasks
  • Audit Files
  • Assets groups
  • Report templates
  • Troubleshoot any issues in regards of the OVA scans.
  • Escalate to the OVA Tool Manager any issues that cannot be fixed by the Senior OVA Analyst
  • Daily Analyst and Prioritization of the found vulnerabilities.
  • Weekly / Monthly report the found vulnerabilities, remediation actions taken and status.
  • Support, maintain and improve the OVA data processing procedures
  • Maintain and improve scripted modules part of the OVA data processing procedures
  • Maintain and improve the SQL storage procedures part of the OVA data processing
  • Create, maintain and improve Power BI reports
  • Collaborate with other members of the NATO Security Teams to ensure the protection of enterprise assets.
  • Stay current with emerging security threats and technologies.
  • Keep weekly communication with the CIS personnel of each site under your area of responsibility.

Deliverables and Expected Outcomes:

Under the direction of the NCSC Security Compliance (OVA) Cell Head/Service Delivery Manager, the incumbent shall deliver the following:

  • Daily: verify that the OVA scans are configured correctly and that the information collected is accurate.
  • Weekly: after analysing the data, deliver a comprehensive vulnerability reports to each stakeholder / CIS personnel under you area of responsibility taking into account all vulnerabilities posing a security risk, remediation actions recommended to the system/application owners and the status of the recommended actions. The weekly report is expected to be delivered each Wednesday/Thursday before Close of Business. No weekly report is due if that week does not include any working day (for instance: long official holidays such as Christmas break).
  • Monthly: deliver vulnerability report to the stakeholders / CIS personnel, with an overview of the critical/high vulnerabilities identified, the status of the recommended actions to show in a graphic way the trend of the security posture of CIS assets. The monthly report is expected to be delivered in the week of Microsoft patch Tuesday (second Tuesday of the month).

Performance Standards

  • Timely delivery of the reports as specified on the deliverables and expected outcomes Section.
  • Quality of the content of the reports will be assessed regularly by the SDM / SAO.
  • The reports shall contain key elements of the vulnerabilities identified, systems affected, time of discovery of the vulnerability, time of communicating the vulnerability to the system/application owners, status of the actions recommended to mitigate/remediate the identified vulnerability together with any other relevant information that will provide an additional value to the report.


REQUIREMENT SUMMARY

Min:3.0Max:8.0 year(s)

Information Technology/IT

IT Software - Network Administration / Security

Other

Graduate

Computer science information technology or related field or equivalent experience

Proficient

1

Mons, Belgium