Web Application Security Specialist

The Hague, Netherlands

⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️

Apply now Apply later

Spektrum have a wide range of exciting opportunities in several global locations.

We are always looking to add great new talent to our team and look forward to hearing from you.

Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.

Who we are supporting 

The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.

The NCIA provides a wide range of services, including:

  • Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.
  • Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.
  • Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
  • Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.
  • Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers.

Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities.

The program

Assistance and Advisory Service (AAS)

The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.

To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.

Role ID – 2025-0234

 

Role Background

 

The NCIA provides advanced technological solutions and support to NATO and its member nations. Its mission is to ensure effective and secure communication and information systems for the alliance, enabling operations and decision-making. The agency plays a critical role in maintaining NATO's technological edge and operational readiness through innovation, collaboration, and the implementation of cutting-edge technologies. Internet Website Publishing and Protection service provides a suite of capabilities for web assets focused on security performance and reliability. These include a Web Application Firewall (WAF), Web Application and API Protection (WAAP), Content Delivery Network (CDN), Distributed Denial of Service (DDoS) protection, bot management, and SSL/TLS.

 

Role Duties and Responsibilities

 

  • Operations

 

  • Configure and maintain Cloudflare WAF rules and policies, in line with NATO Security Policy, to protect against OWASP Top 10 and other emerging threats.
  • Implement and manage WAAP features for securing APIs and applications, including schema validation, threat intelligence, and behavioural analysis.
  • Implement Rate Limiting Policies to protect APIs and web applications from abuse, brute force attacks, and scraping attempts. Design intelligent thresholds based on traffic patterns and application sensitivity.
  • Monitor and mitigate DDoS attacks, leveraging Cloudflare’s L3/L4/L7 protection capabilities.
  • Optimize CDN configurations to ensure high availability, low latency, and efficient caching strategies.
  • Deploy and fine-tune Bot Management policies to differentiate between good bots and malicious traffic.
  • Leverage Cloudflare Workers to deploy server less functions at the edge for custom logic, header rewriting, request inspection, or response manipulation.
  • Monitor and enforce Page Rules for URL-specific behaviours such as redirects, cache settings, and security controls.
  • Analyse traffic patterns, security logs, and incident data to proactively identify and remediate vulnerabilities.
  • Work closely with DevOps, Application Security, and Networking teams to enforce secure deployment practices.
  • Respond to security incidents and support troubleshooting efforts related to Cloudflare services.
  • Keep documentation up to date for security policies, procedures, and architecture diagrams.
  • Stay current with Cloudflare’s roadmap, industry trends, and evolving threat landscapes.

 

  • Inventory

 

  • Maintain updates to the CMDB with the Configuration Items used by the services/systems listed in Annex C;
  • Perform all operation, support and maintenance activities on the platforms described in Annex C.

 

  • Incident Logging, Tracking, Dispatching

 

  • Log and track incidents, work orders and change requests using the incident ticketing system (ITSM);
  • Investigate and resolve Application Security Service (WAF, WAAP, CDN, etc), Performance and Availability (CDN) and Threat Mitigation and Resilience (DDoS, Rate Limiting) related issues, directly assigned by end-users/requesters, or escalated from Level 2 support, within the staff competences and administrator permissions;
  • Maintain communication with end-users when needed;
  • Ensure all tickets are updated with accurate and detailed information and resolved (or assigned to appropriate stakeholders) within the agreed service levels;

 

  • Escalation

 

  • Escalate complex issues to Level 4 support (vendor) or appropriate teams when necessary.
  • Follow up on escalated issues to ensure timely resolution and user satisfaction.

 

  • Knowledge Base Management

 

  • Contribute to the creation/maintenance of a knowledge base, documenting common issues and solutions.
  • Share knowledge and best practices with team members to improve overall service quality.

 

  • Performance Monitoring

 

  • Monitor support metrics and KPIs to ensure high-quality service delivery.
  • Participate in regular reviews to identify areas for improvement and implement corrective actions.

 

  • Automation and Efficiency

 

  • Leverage Infrastructure as Code (IaC) tools (e.g., Terraform or Cloudflare’s native SDK/curl) to establish and maintain a scalable, repeatable, and auditable security posture through the deployment and management of Cloudflare WAF rules, firewall policies, custom configurations, and security settings.
  • Utilize automation to create workflows for repetitive tasks, improve service efficiency and proactively implement solutions.

 

  • Communication and Collaboration

 

  • Communicate effectively with internal user community to understand their issues and provide clear instructions.
  • Collaborate with IT teams to resolve issues and improve service delivery.

 

Essential Skills, Experience and Certifications

 

  • Technical Proficiency

 

  • Cloudflare Security Stack
  • Web Application Firewall (WAF) Configuration
  • DDoS Mitigation & Rate Limiting
  • API Security & Schema Validation (Page Shield)
  • Bot Management
  • SSL/TLS Management
  • DNS & CDN Optimization
  • Security Analytics & Logging
  • Secure Coding & Vulnerability Assessment/Mitigation (WASP top 10)
  • Incident Response & Troubleshooting
  • DevOps & Automation - Use Terraform or APIs to automate Cloudflare configurations.
  • Cloudflare Workers and Zero Trust (Bonus)

 

  • Tasks

 

  • Deploy, Configuration, Management, Security Operations
  • Monitoring, Upgrade, Version Control

 

  • Problem-Solving Skills

 

  • Analytical Thinking – Ability to analyse traffic patterns and identify anomalies or malicious behaviour using data-driven insights.
  • Troubleshooting & Debugging – Skilled at diagnosing and resolving technical issues related to performance, security rules, and system errors.
  • Security Incident Response – Capable of quickly responding to and mitigating active security threats without affecting legitimate traffic.
  • Performance Optimization – Identifies and addresses performance bottlenecks while balancing security and speed.
  • Automation & Configuration Consistency – Uses Infrastructure as Code to ensure consistent, reliable, and error-free deployments.
  • Risk Assessment & Prioritization – Evaluates security risks and prioritizes remediation efforts based on impact and urgency.

 

  • Automation Skills

 

  • Experience with IaaC to automate routine support tasks.
  • Proficiency in automation to create workflows and automate repetitive processes.
  • Ability to identify and implement automation opportunities to enhance efficiency.

 

  • Communication and Interpersonal Skills

 

  • Excellent verbal and written communication skills.
  • Full proficiency in English.
  • Ability to communicate technical information to non-technical users in a clear and concise manner.

 

  • Customer Service Orientation

 

  • Strong customer service focus with a commitment to user satisfaction.
  • Patience and empathy when dealing with user issues and concerns.

 

  • Organizational Skills

 

  • Ability to manage multiple support tickets and prioritize tasks effectively.
  • Attention to detail in documenting support activities and maintaining accurate records.

 

  • Team Collaboration

 

  • Ability to work effectively as part of a team and share knowledge and resources.
  • Willingness to collaborate with colleagues to solve complex issues.

 

  • Others

 

  • The candidate has strong customer relationship skills, including negotiating complex and sensitive situations under pressure.
  • Full proficiency in the English language.
  • The candidate must have the nationality of one of the NATO nations.

 Working Location

  • The Hague (NLD)

Working Policy

  • On-site

Travel

  • Some travel to other NATO sites may be required

Security Clearance

  • Valid National or NATO Secret personal security clearance

We never know what new opportunities might be just over the horizon. If this opportunity isn't for you please feel free to send us your resume anyway and be the first to know if something suitable for your skills and experience comes up. 

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  7  1  0
Category: AppSec Jobs

Tags: Analytics APIs Application security Automation C CDN Clearance Cloudflare DDoS DevOps DNS Firewalls Incident response KPIs Monitoring NATO OWASP Risk assessment Security Clearance Terraform Threat intelligence TLS Vulnerabilities Zero Trust

Region: Europe
Country: Netherlands

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.