Loading ...
Loading ...
2025-0035 AD Security Assessment Data Analysis and Reporting (NS) - THU 3 Apr
View: 100
Update day: 16-11-2025
Category: IT - Software
Industry: IT Services IT Consulting
Position: Entry level
Job type: Contract
Loading ...
Job content
Deadline Date: Thursday 3 April 2025Requirement: Active Directory Security Assessment Data Analysis and Reporting
Location: Mons, BE
Full Time On-Site:Yes
Time On-Site:100%
Period of Performance: 2025 BASE: As soon as possible but not later than 12 May 2025 until 31 December 2025.
2026 OPTION: 1 January 2026 until 31 December 2026
Required Security Clearance: NATO SECRET
- PURPOSE
The purpose of the work package is to provide support to NATO Cyber Security Centre (NCSC) to fulfil identified Active Directory Security Assessment Tool data analysis and reporting activities more effectively.
- BACKGROUND
NCIA initiated a project and procured Active Directory Security Assessment Tool (Tenable Identity Exposure) providing identity unification and risk scoring, real‑time attack detection and continually assessing directory services security in real‑time, eliminate attack paths that lead to domain domination, and investigate and inform.
To support NCSC for the execution of tasks identified in the subject work package of the project, the NCIA is looking for subject matter expertise in the delivery of complex, foundational and novel Cybersecurity capability.
This contract is to provide consistent support on a deliverable-based (completion-type) contract, to NCSC contributing to its POW based on the deliverables that are described in the scope of work below.
- SCOPE OF WORK
This task includes data analysis and reporting of data reported by the Active Directory Security Assessment Tool. For the provision of consistent support and the execution of the task, NCIA will get subject matter expertise from the industry with a service (deliverable based/completion type) based AAS framework contract in the delivery of requested capability.
Active Directory data analysis and reporting give visibility and insight on the networks into Active Directory environment, which in turn is critical to effective Active Directory management, strong security and compliance, and efficient migrations and consolidations. Effective Active Directory data analysis and reporting will also ensure NATO to monitor Active Directory users and groups including permission levels, inactive users/accounts and group policy settings, user entitlements, user activities, event trends, suspicious patterns, etc.
More broadly, NATO needs to be able to monitor the configuration of its domain controllers in order to prevent exploitation by malicious threat actors.
Under the direction / guidance of the NCSC Point of Contact, a contractor will be the part of the NCSC Team supporting the following activities:
- Ensuring data accuracy and up-to-date data for Active Directory (AD) Security issues:
- Ensure accurate and up-to-date AD data is collected from the different Domains in scope,
- Security baselines are configured based on industry best practice and NATO policies,
- Review existing policies, fine tune and improve them at the same time,
- Report to the Tool Managers any technical issues, such as connectivity problems between Tenable Identity Exposure and other integrated systems or errors in scans or reports,
- Follow up the new releasing of the security solutions to consider the implementation of new features or capabilities
- Monitoring, analysing the collected data, prioritizing based on risk assessment for Active Directory (AD) Security issues:
- Monitor the solution daily
- Identify the potential security issues
- Ensure that the collected data is analysed
- Prioritize the remediation actions based on the previous point
- Reporting Active Directory (AD) Security issues:
- Critical vulnerabilities will be reported within 4 hours since identified
- High vulnerabilities will be reported within 8 hours since identified
- Deliver a comprehensive vulnerability report to each stakeholder under you area of responsibility taking into account all vulnerabilities posing a security risk, remediation actions recommended to the system/application owners and the status of the recommended actions. The weekly report is expected to be delivered each Wednesday/Thursday before Close of Business
- Ensure that the reported information is also available via PowerBI dashboard (or similar)
- Report to the corresponding AD management teams the prioritized remediation actions based on the analysis done on point 2.c/2.d)
- Record the defined KPIs to follow up the trend of AD Security issues
- Remediation actions for Active Directory (AD) Security issues:
- Follow up and verify that the reported security issues have been remediated
- Follow the escalation process in case the reported security issues have not been fixed
- Documentation:
- Document configuration and changes: Keep up-to-date documentation of all configurations, baselines, troubleshooting procedures,
- Keep a lessons learnt document
- User access Management:
- Review the list of users with access to the security solution,
- Verify that only the required users have access to the solution,
- Coordinate with the Tool Managers any issue with the User access management
- Automation and Scripting
- Improve processes efficiency: Identify areas where automation could reduce manual intervention and improve operational efficiency
- DELIVERABLES AND PAYMENT MILESTONES
Deliverable: 30 sprints to support Active Directory Security Assessment Data Analysis and Reporting as per described in Para 3
Payment Milestones: Upon completion of each fourth sprint and at the end of the service. Completion of each milestone shall be accompanied documented in Delivery Acceptance Sheet (DAS) - (Annex B), signed for acceptance by the Purchaser’s authorized point of contact and the Contractor
Number of sprints is calculated considering a starting date 12 May 2025. This will be adjusted based on actual starting date.
The Purchaser (NCIA) reserves the right to exercise a number of options of one or more sprints based on the same deliverables, at a later time, depending on the project priorities and requirements, at the same cost.
The payment shall be dependent upon successful acceptance of the Delivery Acceptance Sheet (DAS) - (Annex B).
Invoices shall be accompanied with a Delivery Acceptance Sheet (Annex B) signed by the Contractor and the project authority.
2026 Option: 1 January 2026 to 31 December 2026:
Deliverable: 46 sprints to support Active Directory Security Assessment Data Analysis and Reporting as per described in Para 3
Cost Ceiling: Price will be determined by applying the price adjustment formula as outlined in CO‐115786‐ AAS+ Special Provisions article 6.5.
Payment Milestones: Upon completion of each fourth sprint and at the end of the service. Completion of each milestone shall be accompanied documented in Delivery Acceptance Sheet (DAS) - (Annex B), signed for acceptance by the Purchaser’s authorized point of contact and the Contractor
The Purchaser (NCIA) reserves the right to exercise a number of options of one or more sprints based on the same deliverables, at a later time, depending on the project priorities and requirements, at the same cost.
The payment shall be dependent upon successful acceptance of the Delivery Acceptance Sheet (DAS) - (Annex B).
Invoices shall be accompanied with a Delivery Acceptance Sheet (Annex B) signed by the Contractor and the project authority.
- COORDINATION AND REPORTING
For each sprint to be considered as complete and payable, the contractor must report the outcome of his/her work during the sprint, first verbally during the retrospective meeting and then in written within three (3) days after the sprint’s end date. The format of this report shall be a short email to the NCIA Project Manager mentioning briefly the work held and the development achievements during the sprint.
At the end of the project, the Contractor shall provide a Project Closure Report that is summarizing the activities during the period of performance at high level.
- ACCEPTANCE AND REJECTION CRITERIA
- Acceptance Criteria
- Quality of work reached NATO standards,
- Tasks are completed within the assigned time,
- Performances are as defined by the line manager
- Rejection Criteria
- Quality of work is low,
- Tasks are not completed within the assigned time,
- Performances are not as defined by the line manager
- A replacement will be requested if the contractor cannot fulfil the tasks as explained in rejection criteria
- Payment will not be done if the sprint is not completed
- PENALTY AND REJECTION PROCESS
If any of the above mentioned issues persist, the outsourcing partner will be asked to provide a replacement.
- SCHEDULE
The period of performance is as soon as possible but not later than 12 May 2025 and will end no later than 31 December 2025.
If the 2026 option is exercised, the period of performance is 01 January 2026 to 31 December 2026.
- CONSTRAINTS
All documentation etc. will be stored under configuration management and/or in the provided NCIA tools.
- SECURITY AND NON-DISCLOSURE AGREEMENT
The signature of a Non-Disclosure Agreement between the contractor contributing to this task and NCIA will be required prior to execution.
- PRACTICAL ARRANGEMENTS
The contractor will be required to work following the rules and regulations applicable for the operations of NATO CIS.
The contractor will not be required to travel to other NATO locations as part of his role.
This work must be accomplished by one contractor.
The Purchaser will provide the contractor with the following Purchaser-Furnished Equipment (PFE):
- Access to NATO sites, as required, for the purpose of executing this SOW
- Workspace (needed business IT for both on- and off-site work, hot-desk at NCSC facility)
- NCIA "REACH" laptop to be used by the contractor for the execution of the contract
- REQUIRED PROFILE
- DESIRABLE PROFILE
Requirements
- SECURITY AND NON-DISCLOSURE AGREEMENT
- It is mandatory to have the candidate be in possession of a NATO SECRET security clearance to facilitate follow-on engagements and coordination at NATO venues
- REQUIRED PROFILE
- Activities performed by a contractor include the lifecycle management of the Tenable Identity Exposure software (including all tasks related to A2SL inclusion), its configuration to ensure coverage of all in-scope Active Directory servers, and the regular monitoring of the availability of the capability
- Bachelor’s degree in Computer Science, Information Technology, or related field Or equivalent experience
- 3+ years of experience in IT security, with a focus on Active Directory security, System Administration, and hands-on on Security Assessment Tools in large organisations
- Experience with Active Directory Management
- Strong understanding of security best practices and experience with Tenable products especially with Tenable Identity Exposure
- Comprehensive experience and hands-on on administering Microsoft Windows Domainbased networks
- Systems administration, ideally both with Windows and Linux
- Good engineering skills including programming and/or scripting knowledge (python, shell scripting, PowerShell)
- Demonstrable experience of analysing, prioritizing and reporting in the field of vulnerabilities assessment
- Strong analytical and problem-solving skills
- Excellent communication abilities, both written and verbal, with the ability to clearly and successfully articulate complex issues to a variety of audiences and teams
- Database management skills, preferably MS SQL
- DESIRABLE PROFILE
- Experience in working with NATO
- Experience of working with NATO Communications and Information Agency
- Experience of working with national Defence or Government entities
Loading ...
Loading ...
Deadline: 31-12-2025
Click to apply for free candidate
Report job
Loading ...
SIMILAR JOBS
-
⏰ 25-12-2025🌏 Saint-Ghislain, Hainaut
-
⏰ 17-12-2025🌏 Mons, Hainaut
-
⏰ 17-12-2025🌏 Binche, Hainaut
-
⏰ 19-12-2025🌏 Mons, Hainaut
Loading ...
-
⏰ 25-12-2025🌏 Mouscron, Hainaut
-
⏰ 22-12-2025🌏 Ath, Hainaut
-
⏰ 17-12-2025🌏 Mons, Hainaut
-
⏰ 18-12-2025🌏 Chièvres, Hainaut
Loading ...
-
⏰ 18-12-2025🌏 Mons, Hainaut
-
⏰ 17-12-2025🌏 Mons, Hainaut