2025-0126 Support to Deployable CIS Cyber Defence Project (NS) - FRI 9 May
Belgium - Remote
Full Time Contract Senior-level / Expert Clearance required EUR 34K - 81K * est.
EMW, Inc.
Deadline Date: Friday 9 May 2025
Requirement: Support to Deployable CIS Cyber Defence Project
Location: Off-Site
Note: Please refer to your Subcontract Agreement, article 6.4.1.a, which states “Off-Site Discount: 5% (this discount is applicable to all requirements, and applies when the assigned personnel are permitted to work Off-Site, such as at- home)". Please be sure to price this discount in your overall price proposal when submitting bids against off-site RFQs
Period of Performance: 2025 BASE: starting as soon as possible but not later than 09 JUN 2025 (tentative) to 20 DEC 2025
Required Security Clearance: NATO Secret
1. Introduction
The NCI Agency has been established with a view to meeting the collective requirements of some or all NATO nations in the fields of capability delivery and service provision related to Consultation, Command & Control as well as Communications, Information and Cyber Defence functions, thereby also facilitating the integration of Intelligence, Surveillance, Reconnaissance, Target Acquisition functions and their associated information exchange.
As per NATO directive “Minimum Level of Communication and Information Systems Capabilities at Land Tactical Level” [MC(2019)0640], the Mission Network Operation Centre (MNOC) contains the Mission Cyber Security Operation Centre (MCSOC), which is the central mission service management and cyber security operations centre. The MCSOC provides mission-wide Cyber Defence (CD)/CIS Security visibility to the mission commander and coordinating/facilitating CD/CIS Security related reporting, incident management, coordination of incident responses, etc., for DCIS operating in exercises or actual operations.
The MCSOC is expected to be supported by staff from the NATO Cyber Security Centre (NCSC) and the NATO CIS Group (NCISG). Deployed systems are connected to static primarily via SATCOM link, so dependency on this needs to be carefully planned and managed. The MNOC also has a controlled interface to existing fixed systems (e.g. NATO Secret – NS).
The MCSOC has further relationships to other NATO programmes, systems, policies, processes, and procedures that need to be integrated or reflected in developing requirements as NATO enterprise strategy evolves (for example, Federated Mission Networking).
2. Scope of Work and Deliverables
The contractor will provide support services comprising the following tasks and activities:
- Review and integration of aspects from previous Mission Cyber Security Operations Centre (MCSOC) documentation (produced in 2022 and 2023);
- Review the Identity and Access management concept developed in 2022.
- Develop a Programme of Work product, delivered as a standard NCI Agency Technical Report. With the aim to:
- Identify DCIS specific requirements and gap analysis to implement NATO’s Cyber Defence Regulations in the deployed environment and explore and propose possible solutions and develop a roadmap for implementation of Cyber Defence requirements in to the DCIS environment.
- Review and further develop the existing MCSOC Concept of Employment (CONEMP) in line with emerging and changing requirements of DCIS and other adjacent programmes of work in NATO.
- Review and further develop the existing concept documentation for federated SOC operation, including uplift of MCSOC documentation to reflect the latest changes to Federated Mission Networking (FMN) Spirals.
- Create and/or update additional MCSOC project documentation as directed by the Technical Lead (TL) and Project Manager (PM).
- Update the existing MCSOC documentation (produced in 2022 and 2023) to reflect the change of focus from the NRF towards the emerging concept of an Allied Reaction Force (ARF);
- Continuation of the previous ACT Programme of Work;
- Update the DCIS CD roadmap from 2024;
- Update MCSOC documentation;
- Update / further develop the Identity and Access management concept developed in 2022.
- Prepare a technical report describing future Cyber Defence requirements for DCIS architecture in the next years. Creating a holistic DCIS Cyber Defence Architecture to shape future DCIS projects.
The deliverables will be required by various dates, as identified in Section 5, throughout the contract execution.
All deliverables are to be peer reviewed within its delivery cycle. Input and guidance will be provided by NCIA in written from or/and during the targeted review meetings.
During the period of performance a Delivery Acceptance Sheet (DAS) shall be provided to
the Purchaser for each scheduled delivery, as identified in Section 3. The Template is provided in the Annex C. The Purchaser will confirm the acceptance by signing the DAS.
The expected classification level of the deliverables is NATO Restricted. However, in some particular circumstances it might be needed that a specific deliverable and the delivery of the service may require the contractor’s personnel to access information, as well as CIS systems, classified up to NATO Secret, therefore the contractor’s personnel shall be in possession of a valid security clearance up to and including NATO Secret information as from contract start.
The contractor’s personnel will carry out tasks and will issue deliverables as described in the table below:
WP1 - 2025 ACT Programme of Work DCIS
The contractor’s personnel will participate in project activities as directed by the NCIA project manager / NCIA Technical Lead. As required, s/he will perform analysis of previous MCSOC documentation (produced in 2022 and 2023); S/He will review the Identity and Access management concept developed in 2022. From these analyses they will contribute to a Programme of Work product, delivered as a standard NCI Agency Technical Report.
The 2025 Programme of Work will:
- Update the DCIS CD roadmap from 2024
- Update MCSOC documentation
- Update / further develop the Identity and Access management concept developed in 2022.
This will be presented as a technical report describing future Cyber Defence requirements for DCIS architecture in the next years. Creating a holistic DCIS Cyber Defence Architecture to shape future DCIS projects.
Deliverable D1: Review and provide status of current/previous PoW documentation as described in this SOW. Interim report to be provided by 31 JUL 2025.
Deliverable D2: Deliver first/working draft of PoW Technical Report to the reviewed by NCIA Technical Lead. Report to include:
- DCIS specific requirements / gaps analysis.
- CONEMP with emerging and changing requirements of NATO DCIS.
- Updated MCSOC concept, including inputs from NCISG and NCIA.
Interim report to be provided by 30 SEP 2025.
Deliverable D3: Final Report – ACT Programme of Work DCIS 2025 Cyber Defence Study (after coordination with NCISG and NCIA) released to NATO stakeholders.
Report to be provided by 30 NOV 2025.
Acceptance Criteria A1: Interim and final reports are reviewed by the project team and the contractor’s personnel will update it based on NCIA feedback/correction.
For acceptance, the reports have to be approved by the project manager.
Report schedule will be
- D1: 31 July 2025
- D2: 30 September 2025
- D3: 30 November 2025
3. Delivery Schedule and Payment Milestones
This is a completion-type contract which requires contractor personnel with complementary skills to complete the work.
Schedule of payments: Payment will be made after the Purchaser has accepted the respective deliverable and signed its Delivery Acceptance Sheet (DAS) (Annex A).
The contractor shall submit an invoice, with approved DAS attached, to the Purchaser for payment as per the schedule listed in the table below:
2025 – Base
Deliverable Delivery Date Payment Amount Payment Milestones
WP1-D1:
Delivery Date: 31 July 2025
Payment Milestones: After deliverable completion and signed Delivery Acceptance Sheet
WP1-D2:
Delivery Date: 30 Sept 2025
Payment Milestones: After deliverable completion and signed Delivery Acceptance Sheet
WP1-D3:
Delivery Date: 30 Nov 2025
Payment Milestones: After deliverable completion and signed Delivery Acceptance Sheet
4. Coordination and Reporting
The contractor’s personnel shall participate in status update meetings and other meetings, physically in the office, or in person via electronic means using Conference Call capabilities, according to service manager’s instructions.
The contractor’s personnel shall deliver interim drafts and report the status of the deliverables as required by the NCI Agency project team, with monthly team meeting to be held on REACH.
Acceptance of each delivery completion will be documented in Annex A – Delivery Acceptance Sheet.
5. Schedule
This task order will be active immediately after signing of the contract by both parties. The period of performance is to begin a soon as possible but not later than 9 June 2025 and will end no later than 20 December 2025.
6. Constraints
All the deliverables provided under this statement of work will be based on NCI Agency templates or agreed with the Purchaser.
All documentation will be stored under configuration management and/or in the provided NCI Agency tools.
Part of the work may involve handling classified networks, therefore, a security clearance at the right level is expected for the contractor’s personnel undertaking this service.
7. Security
The security classification of the service will be up to NATO SECRET.
The contractor’s personnel providing the services under this SOW is required to hold a valid NATO SECRET security clearance as from the start date of the contract.
8. Practical Arrangements
The contractor’s personnel will be required to provide the service remotely.
NCI Agency will provide one NATO RESTRICTED REACH laptop computer to the contractor during the execution of the Contract. The contractor shall return this laptop computer back to NCI Agency after completion of the Contract.
This service must be accomplished by ONE individual.
9. Travel
The contractor’s personnel may be required to travel to other NCI Agency or NATO locations for completing these tasks. Travel arrangements will be the responsibility of the contractor and the expenses will be reimbursed in accordance with Article 5.5 of the AAS+ Framework Contract and within the limits of the NCIA Travel Directive.
10. Required Qualifications
[See Requirements]
Requirements
7. Security
- The contractor’s personnel providing the services under this SOW is required to hold a valid NATO SECRET security clearance as from the start date of the contract.
10. Required Qualifications
Delivery of the services within this SOW requires a cybersecurity contractor with the following qualifications and experience:
- The contractor’s personnel shall have extensive knowledge and experience (totalling more than 10 years) in Cyber Security and Information Security.
More specifically:
- M.Sc. or PhD in Information Security or in a related field of study;
- Certification on Certified Information Systems Security Professional (CISSP);
Proven experience of at least 2 years in any of the activities below:
- Experience in concept development in the area of cyber security;
- Experience in cyber as a domain operational concepts;
- Experience in working in a Security Operations Centre;
- Experience in setting up processes for a Security Operations Centre;
- Experience in setting up SIEM/Logging, Firewalls and NIDS/NIPS/HIDS concepts;
- Experience in converting requirements into security architectures and technically feasible solutions;
- Experience in system design, architecture, and implementation;
- Experience in NATO organisational structures and relationships with NATO and Partner nations;
- Experience in working within a complex customer environment and multi-national team;
Desirable qualifications and experience:
- Knowledge to evaluate and assess scenarios for cyber security threat / risk ratios;
- Ability to independently produce and edit technical documentation and scientific reports in English;
- Excellent communications skills;
- Good understanding of project management methodologies
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: C CISSP Clearance CSOC Firewalls IAM Incident response NATO PhD Security Clearance SIEM SOC Strategy Surveillance
Perks/benefits: Gear Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.