Security Engineer / Architect
About Candidate
- Extensive experience in Cyber and Information Security, focusing on security accreditation, risk management, and compliance.
- Expertise in developing, reviewing, and recommending security accreditation documentation for complex Communication and Information Systems (CIS).
- Proven ability to manage security risk assessments, including vulnerability assessments, threat modeling, and business impact analysis.
- Strong knowledge of security standards such as NIST, ISO 27005, and EU/EC directives, with hands-on experience in implementing these frameworks.
- Proficient in SIEM tools, particularly Splunk, for incident response, vulnerability scanning, and threat hunting.
- Extensive background in cyber risk management and threat intelligence, including the design of security solutions for classified environments.
- Experience in liaising with various stakeholders, including NATO, EU institutions, and national security bodies, to ensure compliance with security policies and directives.
- Led the implementation of security measures for critical infrastructure projects, including NATO’s cloud environments and satellite systems.
- In-depth knowledge of security requirements for classified systems and development of cyber hygiene procedures.
- Skilled in incident analysis, including network attack vectors, protocol analysis, and firewall log analysis.
- Led cybersecurity business transformation initiatives and developed proposals to improve risk management processes.
- Managed large-scale security projects, including procurement processes and contract management, with a strong focus on budget and operational effectiveness.
- Strong leadership experience, managing teams of up to 10 staff or external consultants, ensuring security policies and guidelines are followed.
- Hands-on experience in the integration and accreditation of security solutions in complex, multi-national environments.
- Involved in the establishment and operation of cybersecurity programs, such as the NATO Cyber Incident Response Center.
- Knowledgeable in the design and implementation of command and control systems, and security governance for critical national infrastructure.