Cyber Security Officer

Spektrum· Ramstein, Germany· greenhouse· veröffentlicht 17.07.2026
Muss:CloudMobileSecuritySeniorLeadPrincipalRemote
Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects. Who we are supporting The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium. The NCIA provides a wide range of services, including: Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats. Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations. Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces. Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks. Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers. Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities. The program Assistance and Advisory Service (AAS) The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V. To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce. Role ID – C004920 Role Background The Cyber Security Officer is responsible for designing, implementing, and maintaining cyber security solutions that protect the organization's information systems and infrastructure. The role supports secure system development, risk management, security operations, compliance activities, and incident response while leading a small Cyber Security and COMSEC team. The position works closely with stakeholders and the NATO Cyber Security Centre (NCSC) to ensure systems comply with NATO security policies and operational requirements. Role Duties and Responsibilities  Design, develop, implement, test, and maintain secure information systems throughout the system development lifecycle.  Develop cyber security solutions that meet operational and business requirements.  Work with stakeholders to translate business and functional requirements into secure technical solutions.  Apply and maintain security controls in accordance with organizational policies and local risk assessments.  Perform risk assessments for information systems and identify security risks.  Recommend security improvements and mitigation strategies for identified risks.  Define and maintain secure system configurations that comply with approved architectures.  Support the investigation of cyber security incidents, suspected attacks, and security breaches.  Lead and supervise a team of 3–4 Cyber Security and COMSEC personnel.  Manage Cyber Security operations as the Cyber Security Section Head.  Coordinate cyber security activities with the NATO Cyber Security Centre (NCSC).  Oversee boundary protection, data loss prevention, endpoint protection, and enterprise anti-malware solutions.  Plan, schedule, coordinate, and facilitate cyber security audits and inspections.  Manage corrective actions resulting from security audits and inspections.  Supervise security monitoring, testing, evaluation, and accreditation activities for information systems.  Plan and implement cyber security services to support Agency business units.  Deputize for senior staff when required.  Perform additional duties as assigned.  Support physical tasks, including lifting equipment up to 25 lbs when required. Essential Skills, Experience and Certifications  Strong knowledge of cyber security principles, system security, and security architecture.  Windows Server security hardening and compliance management.  Network security, firewall technologies, VPNs, intrusion detection, and forensic tools.  Security governance, risk management, and vulnerability management.  Security incident response and investigation.  Data Loss Prevention (DLP) and endpoint security management.  Security audit coordination and compliance management.  Server, network, and storage virtualization technologies.  Public Key Infrastructure (PKI).  Cloud technology fundamentals.  Strong analytical and problem-solving skills.  Ability to work independently and manage multiple priorities.  Excellent written and verbal communication skills.  Positive customer-focused attitude with strong interpersonal skills.  Ability to perform effectively in high-pressure environments.  Familiarity with ITIL service management processes.  Basic understanding of Disaster Recovery (DR) and Business Continuity (BC). Experience  Minimum 5 years' experience in Windows Server security hardening.  Minimum 3 years' experience with Trellix ePolicy Orchestrator and Trellix Endpoint Security (or equivalent endpoint security platform).  Minimum 2 years' experience in: o System security o Security architecture o Network security engineering o Security governance o Risk management  Experience with: o Windows Server 2016, 2019 and 2022 o Windows 10 and Windows 11 o Palo Alto Enterprise Firewalls o Trellix/McAfee Endpoint Security solutions o Vulnerability scanning tools such as Nessus o VMware vSphere, ESX, NSX and vSAN o Wireless LAN security o Mobile endpoint security o Supporting NATO Enterprise CIS environments  Previous experience working in an international military and civilian environment is desirable. Education  Bachelor's degree in Cyber Security, Information Technology, Computer Science, or a related discipline. OR  At least 6 years of extensive and progressive experience in a closely related cyber security role. Certifications Mandatory  CISM or CISSP Preferred  CGRC/CAP, CASP+, Cloud+, PenTest+, Security+, GSEC, CISA, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISSP-ISSEP, GSLC, GSNA, CEH, GIAC certifications  ITIL Foundation (v3 or v4)  NATO COMPUSEC Practitioner Level 1 (0731)  NATO COMPUSEC Practitioner Level 2 (0732)  NATO CIS Security Officer (0280) Language  English Lev el B2–C1 (NATO STANAG 6001 Level 3333). Working Location  Location: Ramstein, Germany  Work Arrangement: Full-time, primarily on-site  Remote work may be permitted only with prior Agency approval and project requirements.  Some physical duties may be required, including lifting up to 25 lbs. Working Policy  Employment Type: Full-time Contract  Contract Duration: 30 August 2026 – 30 December 2026  Weekly Working Hours: 38 hours per week  Working Days: Monday to Friday  Daily unpaid lunch break in accordance with local regulations.  Contractor must maintain valid personal liability and comprehensive insurance.  Must be available during agreed working hours.  Must comply with all Agency security, information assurance, and data protection policies.  Reliable communication and secure access to Agency systems are required throughout the assignment. Travel  Some travel to other NATO sites may be required Security Clearance  Valid NATO Cosmic Top Secret (CTS-A / COSMIC TOP SECRET ATOMAL) security clearance at the time of submission and throughout the contract. We never know what new opportunities might be just over the horizon. If this opportunity isn't for you, please feel free to send us your resume anyway and be the first to know if something suitable for your skills and experience comes up.