Question
Full-time
2-5

Cyber Security Defender (Malware Analysis & Digital Forensics)

5/1/2026

The role involves providing expert support for 24/7 cyber security incident response and conducting malware analysis through static and dynamic code examination. Additionally, the defender will develop automation tools and maintain forensic environments to support NATO's digital operations.

Working Hours

40 hours/week

Company Size

1,001-5,000 employees

Language

English

Visa Sponsorship

No

About The Company
We are NATO's technology and cyber hub. We are a team of 3,000 civilian and military staff members, located in 29 sites throughout Europe and North America. We help NATO and its member countries communicate and work together to fulfil their mission – preserve peace and security for nearly one billion citizens. The Agency is on the frontlines against cyber threats, protecting NATO’s networks 24 hours a day, seven days a week, to prevent debilitating attacks. Our experts provide capabilities and services that are critical to NATO’s ability to fulfil its core tasks of consultation, collective defence and crisis management. We achieve this by working in partnership with industry, academia and not-for-profit organizations. Our work helps NATO keeps its technological edge.
About the Role

 

Who we are:

For more than 70 years, NATO’s mission has been to preserve peace and security in the Alliance for nearly one billion citizens. The NATO Communications and Information Agency (NCIA) and its predecessors have worked tirelessly in providing the means that enable the connectedness and togetherness that keep our Alliance strong. We are the NCIA, a team of 3000 civilian and military staff in 29 locations throughout Europe, North America and Asia.

Our technology and cyber experts allow NATO to conduct critical operations, protect NATO’s airspace, make data-driven decisions, defend against cyber-attacks, secure NATO networks and maintain superiority in space. This is all possible because of our greatest force, our people. In order to keep this edge we aim to hire, train and retain the very best staff.

Our staff members represent both the diversity and unity of our Alliance. When you join the NCIA, you will be part of an organization where you can contribute authentically to the mission and purpose of NATO and help us keep our technological edge.

 

 

About the job:

Based in Mons, Belgium, you will join the Agency as we embark on a journey to transform our IT services to support NATO’s Digital Endeavour. You will join NATO Cyber Security Centre (NCSC), which is responsible for planning and executing all lifecycle management activities for cyber security. In executing this responsibility, NCSC provides specialist cyber security-related services covering the spectrum of scientific, technical, acquisition, operations, maintenance, and sustainment support, throughout the lifecycle of NATO Communications and Information Systems (CIS).

We are looking for a driven and enthusiastic Cyber Security Defender who will take on the following roles and responsibilities:

  • Provide technical and expert support for to the 24/7 Cyber Security Incident Response Team’s processes, during normal working hours and on-call duties, including weekends and holidays;

  • Support Cyber Security Incident Response/Threat Hunting Team covering one or multiple physical locations, including NATO Alliance Operations and Missions;

  • Perform both static and dynamic code analysis in order to understand malware samples capabilities and capture the results in a report which covers the technical aspects as well as the “so what?” for the decision makers and executives;

  • Develop tools, scripting, automation and integrations to automate activities as much as possible, mostly using Python and PowerShell;

  • Maintain forensic and malware analysis tools and environments on premises or in the cloud.

     

For a full list of duties, please review the job description on the NCI Agency career site.

 

 

 

About you:

The valuable knowledge and experience that you bring to this role are:

  • A Bachelor’s degree at a nationally recognised/certified University in a related discipline and 2 years post-related experience. Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate’s particular abilities or experience that is/are of interest to NCI Agency, that is, at least 6 years extensive and progressive expertise in duties related to the function of the post;

  • Extensive knowledge of malware analysis techniques and technologies;

  • Excellent ability to recognise when an IT network/system has been attacked, be able to take immediate action to limit damage and to escalate the event to higher authority;

  • Practical experience with cyber security in cloud-based environments such as Azure and AWS;

  • Proficiency in assessing security vulnerabilities of operation systems and software;

  • Practical experience and knowledge of malware analysis and malware detection;

  • Practical experience in the analysis of digital forensic artefacts in the context of cyber security;

  • Good knowledge of the principles of computer and communications security, networking, and vulnerabilities of modern operating systems and applications;

  • Good understanding of the MITRE ATT&CK framework and its applicability in Cyber;

  • Good practical experience in Windows, Linux and VMware system administration;

  • Good knowledge of cyber security incident handling;

  • Practical experience in scripting (Python, PowerShell);

  • Fluency in English, both written and spoken.

 

 

 

What we offer:

  • Genuinely meaningful work as part of the most successful alliance in history;

  • 5 year contract with competitive tax-free salary and household and children’s allowances;

  • Privileges for expatriate staff including expatriation and education allowances (where appropriate) and additional home leave;

  • Excellent private health insurance scheme;

  • Generous annual leave of 30 days plus official holidays;

  • NATO Pension Scheme;

  • Development programs such as professional training, wellbeing, and more.

 

 

To learn more about NCIA and our work, please visit our website. 

 

The NCIA prides itself on being an equal opportunity employer. We are committed to fostering an inclusive environment of mutual respect and value uniqueness and differences in gender, gender identity, race, ethnic or cultural origin, age, religion, sexual orientation and physical or neurocognitive ability. 

 

Additional details on the conditions of application can be found via the NCIA career site.

 

Key Skills
Malware analysisDigital forensicsCyber security incident responseThreat huntingPythonPowerShellStatic code analysisDynamic code analysisCloud securityAzureAWSVulnerability assessmentMITRE ATT&CK frameworkWindows administrationLinux administrationVMware
Categories
TechnologySecurity & SafetyGovernment & Public SectorSoftwareData & Analytics
Benefits
Tax-free salaryHousehold allowanceChildren's allowanceExpatriation allowanceEducation allowancePrivate health insurance30 days annual leaveNATO Pension SchemeProfessional training
Apply Now

Please let NATO know you found this job on InterviewPal. This helps us grow!

Apply Now
Prepare for Your Interview

We scan and aggregate real interview questions reported by candidates across thousands of companies. This role already has a tailored question set waiting for you.

Elevate your application

Generate a resume, cover letter, or prepare with our AI mock interviewer tailored to this job's requirements.