Cyber Security Engineer — Security Accreditation and Risk Assessment for NATO with security clearance
Job Summary
Before a classified system goes live somebody has to be able to say what the risksare what controls answer them and what is left over. A multinational defence organisation islooking for the engineer who does that work: the assessment the paperwork that carries it andthe conversations with the authorities who sign it off.
What you would be doing
- Contributing to solution architecture in your areas by identifying which security directivesactually apply.
- Advising on how physical procedural and technical security controls are applied andoperated and explaining plainly what each one is for.
- Running security risk assessments for communication and information systems: the threats thevulnerabilities across every asset the residual risk and what to do about it.
- Spotting the risks a candidate technical architecture creates and proposing alternatives orcountermeasures rather than only objections.
- Scoping defining and prioritising the requirements that accreditation depends on to agreedstandards and with the evidence written down.
- Working with stakeholders to prioritise those requirements and to resolve the conflictsbetween them.
- Advising project and system managers across the whole life of a system including input toproject proposals and invitations to bid.
- Planning requesting and managing the documents accreditation needs system descriptionaccreditation plan risk assessment report security requirement statements operating proceduresand the test and verification plan.
- Witnessing security testing and agreeing the remediation plan with the accreditingauthority.
- Building durable working relationships with accreditation boards national authoritiessystem operating authorities and the internal teams that support the process and representingthe organisation on accreditation matters.
What you would bring
- A bachelors degree from a recognised university in a related discipline with two years ofrelevant experience behind it. Exceptionally around six years of progressive expertise in thiskind of work can stand in place of the degree.
- At least two years across each of the areas the post turns on: accreditation of major systemacquisition or development projects in a large organisation; risk assessment methods and tooling;and the planning design and implementation of security components.
- Working knowledge of the organisations security policy framework and its supportingdirectives.
- Time spent in an international environment with both military and civilian colleagues and aworking picture of how the alliances commands are organised.
- Relevant certification such as CISA or CISSP.
- English you can defend a risk position in in writing and in front of a board.
Extensions are offered where the work goes well. Applications are reviewed as theyarrive.
About Company
Work Life Group Sp. z o.o., agencja zatrudnienia (employment agency) KRAZ no. 19578. NIP 7010247728. ul. Nowogrodzka 50/54 lok. 515, 00-695 Warszawa, Poland.