Information Security Engineer (Endpoint Security, Firewalls, Risk Assessment) for NATO with security clearance

WLG

Ramstein-Miesenbach

Vor Ort

EUR 90.000 - 140.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Mach aus dieser Rolle ein Vorstellungsgespräch — ein Lebenslauf und ein Anschreiben, die darauf ausgerichtet sind, was dieser Arbeitgeber sucht.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

NATO unit at Ramstein is seeking a senior cyber security lead to head a small team responsible for the site’s security from boundary to data. You will coordinate with the central NATO cyber security organization and own all security activities for the site.

Responsibilities include risk assessments, secure configurations, incident handling, and supporting audits. Requires senior Windows security expertise, TOC/COMSEC knowledge, and NATO policy familiarity. On-site role in Ramstein, 38 hours/week.

Qualifikationen

  • Bachelor's degree in related discipline; two years of relevant experience (six years can substitute).
  • Five+ years Windows Server security hardening, baselines and policy enforcement.
  • Three+ years Trellix ePolicy Orchestrator and Trellix Endpoint Security.
  • Two+ years security engineering, governance, risk, and architecture.

Aufgaben

  • Lead a team of 3–4 cyber security and COMSEC staff in daily operations.
  • Own administration of all cyber security activities for the site in coordination with NATO central security org.
  • Define secure configurations and run risk assessments for information systems.
  • Support security audits, inspections and post-inspection actions.

Kenntnisse

Windows Server Security
Trellix EPO/Endpoint
Security Architecture
Risk Assessment
Incident Handling
NATO Security Standards
CISM/CISSP
Nessus/NIDS

Ausbildung

Bachelor's degree in related discipline

Tools

Palo Alto Firewalls
PKI
Nessus
VMware vSphere

Jobbeschreibung

A NATO communications and information systems unit at Ramstein needs someone to own cyber security for the site. Not a monitoring seat: you would be the section head, with three or four cyber security and COMSEC people reporting to you, responsible for every part of the security picture from the boundary in.

What You Would Be Doing
  • Leading a team of three to four cyber security and COMSEC staff through day to day operations.
  • Owning the administration of all cyber security activity for the site, coordinated with the central NATO cyber security organisation - boundary protection management, data loss prevention and enterprise antimalware among them.
  • Applying and maintaining the specific security controls that policy and local risk assessments call for.
  • Running risk assessments for smaller information systems, identifying the risks that come with a proposed technical architecture, and suggesting the countermeasures that reduce them.
  • Defining secure system configurations that match the intended architecture.
  • Supporting the investigation of suspected attacks and security breaches.
  • Scheduling, coordinating and facilitating security audits and inspections, then managing the post inspection actions.
  • Supervising the monitoring, testing and evaluation of computer security systems, and the security side of CIS accreditation.
  • Planning and where necessary implementing cyber security services for the other parts of the organisation.
  • Explaining security risk to business managers in language they can act on.
What They Are Looking For
  • Five years or more of Windows Server security hardening - security baselines, policy enforcement, vulnerability mitigation and system compliance.
  • Three years or more with Trellix ePolicy Orchestrator and Trellix Endpoint Security, including Data Loss Prevention and Application Control, or an equivalent security suite.
  • Two years across system and network security engineering, security architecture, governance and risk.
  • Detailed working knowledge of security and networking technology: IPv4, software firewalls, VPNs, intrusion detection and forensic tools.
  • Practical experience of wireless LAN technology and endpoint security across laptops, tablets and phones.
  • Security incident handling, reading the results of a security audit, and conducting risk assessments.
  • Supporting large NATO enterprise CIS estates, with a working understanding of the NATO command structure and of NATO security policy and its supporting directives.
  • CISM or CISSP certification. Also valued: CGRC/CAP or CASP+ (or Cloud+, PenTest+, Security+, GSEC or equivalent), ITIL v3 or v4 Foundation, and the NATO COMPUSEC Practitioner and CIS Security Officer courses.
  • Palo Alto enterprise firewalls, Public Key Infrastructure, and centralised endpoint security - antivirus, DLP, application control, drive encryption - plus vulnerability scanning with Nessus.
  • Windows Server 2022, 2019 and 2016, and Windows 10 and 11.
  • Server, network and storage virtualisation: VMware vSphere, ESX, NSX and vSAN. A grounding in cloud technology.
  • Familiarity with ITIL or another service management framework - incident, request fulfilment, problem, change and capacity management - and the basics of disaster recovery and business continuity (RPO, RTO, MTTR, MTBF, active‑active and active‑passive).
  • A bachelor's degree in a related discipline with two years of relevant experience. Exceptionally, six years or more of progressive experience in the same work can stand in place of the degree.
  • Fluent professional English, or B2 to C1.
  • Previous work in an international environment with both military and civilian elements.
Practical detail
  • Fully on site in Ramstein, Germany.
  • 38 hours a week, Monday to Friday, with an unpaid lunch break per local practice.
  • 1 October to 30 December 2026, 420 hours in total.
  • You must hold a valid clearance and be a citizen of a NATO member country.

If you have run a security section rather than sat in one, and you can hold your nerve in an inspection week, this is the shape of role that suits you.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cybersecurity Engineer
Cybersecurity Engineer

Leonardo • Darmstadt

Hybrid
EUR 50.000 - 70.000
Network Security Engineer
Network Security Engineer

Leonardo SpA • Deutschland

Hybrid
EUR 70.000 - 90.000
Security Manager
Security Manager

Twentyfour Industries • Deutschland

Hybrid
EUR 70.000 - 100.000
Flexible hours
Remote options
Relocation support
+1
Cyber Threat Analyst - Assessment / Active TS/SCI
Cyber Threat Analyst - Assessment / Active TS/SCI

Peraton • Deutschland

Vor Ort
EUR 69.000 - 110.000
Senior Security Analyst
Senior Security Analyst

Base Cyber Security • Münster

Hybrid
EUR 70.000 - 110.000
Staff Assistant (Disaster, Emergency, Fire Prev.) (m/w/d)
Staff Assistant (Disaster, Emergency, Fire Prev.) (m/w/d)

Allied Joint Support and Enabling Command (JSEC) Ulm NATO • Ulm

Vor Ort
Employee canteen on site
Company pension scheme
38.5-hour week
Cyber Threat Analyst - Assessment / Active TS/SCI
Cyber Threat Analyst - Assessment / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 68.000 - 110.000
Medical insurance
401(k)
Paid time off (PTO)
Senior Cyber Threat Analyst - Assessment / Active TS/SCI
Senior Cyber Threat Analyst - Assessment / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 88.000 - 142.000
Medical, dental, and vision insurance
401(k) plan
Paid time off
Staff Officer (Lines of Communication)
Staff Officer (Lines of Communication)

NATO • Deutschland

Vor Ort
EUR 60.000 - 80.000
Tax-free salary
Health insurance
Generous annual leave
Network Security Engineer
Network Security Engineer

Fortinet, Inc. • Frankfurt

Vor Ort
EUR 80.000 - 100.000