Jobs and Careers
EM

2025-0203 Pen. Testing Service - NPCL Support (NS) - THU 14 Aug RELAUNCH

EMW, Inc.
Belgiumfull_timeVerifiedPosted 2 Aug 2025

About the role

Deadline Date: Thursday 14 August 2025

Previously proposed candidates were not compliant for the following reasons:

  • Does not reach the required three year threshold of verifiable penetration testing practice supported by public evidence and/or recognized relevant certifications
  • Did not demonstrate the required technical depth during assessment and therefore cannot be endorsed for this position

Requirement: Penetration Testing Service - NPCL Support

Location: Mons, BE

Full Time On-Site: Yes

Time On-Site: 100%

Period of Performance: As soon as possible but not later than 22 September 2025 until 31 December 2025 with possibility to exercise the following options:

2026 Option: 1st January until 31st December 2026

2027 Option: 1st January until 31st December 2027

2028 Option: 1st January until 31st December 2028

Required Security Clearance: NATO SECRET

 

1. PURPOSE

The objective of this statement of work (SoW) is to outline the scope of work and deliverables for the penetration testing service to be conducted by the selected company.

The purpose of the work package is to provide support to NATO Cyber Security Centre (NCSC) to fulfil identified penetration testing activities more effectively.

2. BACKGROUND

To support the NCSC with the execution of tasks identified in the subject work package of the service, the NCI Agency is looking for experienced penetration testing professionals to augment the existing teams in order to respond to the increasing demand for high quality security assessments and expertise.

This contract is to provide consistent support on a deliverable-based (completion-type) contract, to NCSC contributing to its POW based on the deliverables that are described in the scope of work below.

3. SCOPE OF WORK

The “Senior Penetration Tester” is a position within the NATO Communications and Information Agency (NCIA), an organization of the North Atlantic Treaty Organization (NATO).

The NCIA has been established with a view to meeting to the best advantage the collective requirements of some or all NATO nations in the fields of capability delivery and service provision related to Consultation, Command & Control as well as Communications, Information and Cyber Defence functions, thereby also facilitating the integration of Intelligence, Surveillance, Reconnaissance, Target Acquisition functions and their associated information exchange.

The NCI Agency NATO Cyber Security Centre (NCSC) is responsible for planning and executing all lifecycle management activities for cyber security. In executing this responsibility, NCSC provides specialist cyber security-related services covering the spectrum of scientific, technical, acquisition, operations, maintenance, and sustainment support, throughout the lifecycle of NATO Information Communications and Technology (ICT).

Within the NCSC, the Assess Branch performs comprehensive vulnerability assessments, penetration testing, security compliance audits and red teaming activities against NATO CIS components throughout their lifecycle and across the NATO CIS footprint, improving its cyber hygiene while contributing to the CIS accreditation, IT change management and cyber incident response and recovery processes. It reports on security shortfalls and provides expertise in support of the mitigation and remediation assistance process. The Section also supports exercises, software development assurance and purple teaming activities.

The Penetration Testing Section manages and conducts tailored penetration testing activities against NATO networks and systems, with the objective to assess the impact of current cyber threats, as well as, their likelihood and difficulty of exploitation, on NATO CIS, a NATO Mission or NATO’s cyber defences by emulating an intermediate or advanced cyber adversary. These unique activities are performed in support of accreditation, IT change management and software development assurance throughout the lifecycle of NATO CIS, during NATO exercises and in support of incident handling and recovery.

Being part of the Penetration Testing Section and under the direction of the Team Lead, the Senior Penetration Tester will perform the following activities:

• Provide Web, infrastructure and application level penetration testing, including but not limited to COTS software and NOTS/GOTS software (NATO/Government off the Shelf), following clearly defined methodologies.

• Participate in kick-off meetings with stakeholders and technical points of contact in order to identify requirements for testing.

• Follow the documented procedures and workflows outlined by the technical leads

• Attend tea

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

EMW, Inc.

View company profile →