2025-0203 Pen. Testing Service - NPCL Support (NS) - THU 14 Aug RELAUNCH
EMW, Inc.About the role
Deadline Date: Thursday 14 August 2025
Previously proposed candidates were not compliant for the following reasons:
- Does not reach the required three year threshold of verifiable penetration testing practice supported by public evidence and/or recognized relevant certifications
- Did not demonstrate the required technical depth during assessment and therefore cannot be endorsed for this position
Requirement: Penetration Testing Service - NPCL Support
Location: Mons, BE
Full Time On-Site: Yes
Time On-Site: 100%
Period of Performance: As soon as possible but not later than 22 September 2025 until 31 December 2025 with possibility to exercise the following options:
2026 Option: 1st January until 31st December 2026
2027 Option: 1st January until 31st December 2027
2028 Option: 1st January until 31st December 2028
Required Security Clearance: NATO SECRET
1. PURPOSE
The objective of this statement of work (SoW) is to outline the scope of work and deliverables for the penetration testing service to be conducted by the selected company.
The purpose of the work package is to provide support to NATO Cyber Security Centre (NCSC) to fulfil identified penetration testing activities more effectively.
2. BACKGROUND
To support the NCSC with the execution of tasks identified in the subject work package of the service, the NCI Agency is looking for experienced penetration testing professionals to augment the existing teams in order to respond to the increasing demand for high quality security assessments and expertise.
This contract is to provide consistent support on a deliverable-based (completion-type) contract, to NCSC contributing to its POW based on the deliverables that are described in the scope of work below.
3. SCOPE OF WORK
The “Senior Penetration Tester” is a position within the NATO Communications and Information Agency (NCIA), an organization of the North Atlantic Treaty Organization (NATO).
The NCIA has been established with a view to meeting to the best advantage the collective requirements of some or all NATO nations in the fields of capability delivery and service provision related to Consultation, Command & Control as well as Communications, Information and Cyber Defence functions, thereby also facilitating the integration of Intelligence, Surveillance, Reconnaissance, Target Acquisition functions and their associated information exchange.
The NCI Agency NATO Cyber Security Centre (NCSC) is responsible for planning and executing all lifecycle management activities for cyber security. In executing this responsibility, NCSC provides specialist cyber security-related services covering the spectrum of scientific, technical, acquisition, operations, maintenance, and sustainment support, throughout the lifecycle of NATO Information Communications and Technology (ICT).
Within the NCSC, the Assess Branch performs comprehensive vulnerability assessments, penetration testing, security compliance audits and red teaming activities against NATO CIS components throughout their lifecycle and across the NATO CIS footprint, improving its cyber hygiene while contributing to the CIS accreditation, IT change management and cyber incident response and recovery processes. It reports on security shortfalls and provides expertise in support of the mitigation and remediation assistance process. The Section also supports exercises, software development assurance and purple teaming activities.
The Penetration Testing Section manages and conducts tailored penetration testing activities against NATO networks and systems, with the objective to assess the impact of current cyber threats, as well as, their likelihood and difficulty of exploitation, on NATO CIS, a NATO Mission or NATO’s cyber defences by emulating an intermediate or advanced cyber adversary. These unique activities are performed in support of accreditation, IT change management and software development assurance throughout the lifecycle of NATO CIS, during NATO exercises and in support of incident handling and recovery.
Being part of the Penetration Testing Section and under the direction of the Team Lead, the Senior Penetration Tester will perform the following activities:
• Provide Web, infrastructure and application level penetration testing, including but not limited to COTS software and NOTS/GOTS software (NATO/Government off the Shelf), following clearly defined methodologies.
• Participate in kick-off meetings with stakeholders and technical points of contact in order to identify requirements for testing.
• Follow the documented procedures and workflows outlined by the technical leads
• Attend tea
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s