Active Directory Security Analyst
Spektrum have a wide range of exciting opportunities in several global locations.
We are always looking to add great new talent to our team and look forward to hearing from you.
Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.
Who we are supporting
The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.
The NCIA provides a wide range of services, including:
- Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.
- Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.
- Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
- Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.
- Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers.
Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities.
The program
Assistance and Advisory Service (AAS)
The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.
To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.
Role Background
The Office of the CIO (OCIO) Enterprise Cyber Security Posture Improvement project focuses on acquisition and implementation of state-of-art tools to enhance Enterprise-wide cybersecurity capabilities considering the key cybersecurity functions.
NCIA initiated a project and procured Active Directory Security Assessment Tool(TenableIdentity Exposure) providing identity unification and risk scoring, real‑time attack detection andcontinually assessing directory services security in real‑time, eliminate attack paths that lead to domain domination, and investigate and inform. To support NCSC for the execution of tasks identified in the subject work package of the project, the NCIA is looking for subject matter expertise in the delivery of complex, foundational and novel Cybersecurity capability. This contract is to provide consistent support on a deliverable-based (completion-type) contract, to NCSC contributing to its POW based on the deliverables that are described in the scope of work below.
Role Duties and Responsibilities
Ensuring data accuracy and up-to-date data for Active Directory (AD) Security issues:
- Ensure accurate and up-to-date AD data is collected from the different Domains in scope,
- Security baselines are configured based on industry best practice and NATO policies,
- Review existing policies, fine tune and improve them at the same time,
- Report to the Tool Managers any technical issues, such as connectivity problems between Tenable Identity Exposure and other integrated systems or errors in scans or reports,
- Follow up the new releasing of the security solutions to consider the implementation of new features or capabilities
Monitoring, analysing the collected data, prioritizing based on risk assessment for Active Directory (AD) Security issues:
- Monitor the solution daily
- Identify the potential security issues
- Ensure that the collected data is analysed
- Prioritize the remediation actions based on the previous point
Reporting Active Directory (AD) Security issues:
- Critical vulnerabilities will be reported within 4 hours since identified
- High vulnerabilities will be reported within 8 hours since identified
- Deliver a comprehensive vulnerability report to each stakeholder under you area of responsibility taking into account all vulnerabilities posing a security risk, remediation actions recommended to the system/application owners and the status of the recommended actions. The weekly report is expected to be delivered each Wednesday/Thursday before Close of Business.
- Ensure that the reported information is also available via PowerBI dashboard (or similar)
- Report to the corresponding AD management teams the prioritized remediation actions based on the analysis done on point 2.c/2.d)
- Record the defined KPIs to follow up the trend of AD Security issues
Remediation actions for Active Directory (AD) Security issues:
- Follow up and verify that the reported security issues have been remediated.
- Follow the escalation process in case the reported security issues have not been fixed.
Documentation:
- Document configuration and changes: Keep up-to-date documentation of all configurations, baselines, troubleshooting procedures,
- Keep a lessons learnt document
User access Management:
- Review the list of users with access to the security solution,
- Verify that only the required users have access to the solution,
- Coordinate with the Tool Managers any issue with the User access management
Automation and Scripting
- Improve processes efficiency: Identify areas where automation could reduce manual intervention and improve operational efficiency.
Essential Skills and Experience
- 3+ years of experience in IT security, with a focus on Active Directory security, System Administration, and hands-on on Security Assessment Tools in large organisations.
- Experience with Active Directory Management.
- Strong understanding of security best practices and experience with Tenable products especially with Tenable Identity Exposure.
- Comprehensive experience and hands-on on administering Microsoft Windows Domain based networks
- Systems administration, ideally both with Windows and Linux.
- Good engineering skills including programming and/or scripting knowledge (python, shell scripting, PowerShell).
- Demonstrable experience of analysing, prioritizing and reporting in the field of vulnerabilities assessment.
- Strong analytical and problem-solving skills.
- Excellent communication abilities, both written and verbal, with the ability to clearly and successfully articulate complex issues to a variety of audiences and teams.
- Database management skills, preferably MS SQL.
Desirable Skills and Experience
- Experience in working with NATO.
- Experience of working with NATO Communications and Information Agency.
- Experience of working with national Defence or Government entities.
Education
- Bachelor's degree in Computer Science, Information Technology, or related field Or equivalent experience.
Working Location
- Mons, Belgium
Working Policy
- On-Site
Travel
- Some travel to other NATO sites may be required
Security Clearance
- Valid National or NATO Secret personal security clearance
We never know what new opportunities might be just over the horizon. If this opportunity isn't for you please feel free to send us your resume anyway and be the first to know if something suitable for your skills and experience comes up.
Apply for this job
*
indicates a required field