OCIO-0014 Enterprise Risk Mgmt Supporting Officer (NS) - THU 27 Jul RELAUNCH
EMW, Inc.About the role
Previously submitted candidates were found not compliant due to the following reasons:
- The experience of the candidate remains to a pretty much technical level and is not considered qualified for an Enterprise-level support to CISOA and related risk management activities;
Deadline Date: Thursday 27 July 2023
Requirement: Enterprise Risk Management Supporting Officer
Location: Brussels, BE
Full time on-site: Yes
Time On-Site: 100%
NATO Grade: A3/G17/88
Total Scope of the request (hours): 700
Required Start Date: 28 August 2023
End Contract Date: 30 December 2023
Required Security Clearance: NATO SECRET
Note: For all Level-of-Effort and Completion-Type requests processed outside of the IWC Value Stream, and for which the contractor will not be reimbursed directly by OCIO for travel expenses, additional travel funding shall be allocated on a Not-to-exceed basis when the yearly Option is exercised.
Annex A – Special Terms and Conditions
The contractor will be responsible for complying with the respective national requirements for working permits, visas, taxes, social security etc. whilst working on site at NATO HQ Brussels, Belgium.
No special status is either conferred or implied by the host organisation, NATO HQ Brussels, Belgium to the contractor whilst working on-site.
The contractor will be responsible for complying with all the respective National Health COVID-19 regulations in Belgium before taking up the position.
1. INTRODUCTION
NATO is undergoing a major adaptation of its overall approach to cybersecurity. As part of its mandate, the NATO Chief Information Officer (CIO) is overseeing the coherence of the NATO Enterprise ICT (Information Communication Technology) capabilities and services and is the single point of authority (SPA) for cybersecurity. The NATO CIO is responsible for developing and implementing a cybersecurity strategy through a comprehensive cyber adaptation programme. This includes significant interaction with executive stakeholders, both military and civilian, required to oversee the NATO Enterprise coherence and cybersecurity efforts.
As part of its mandate, the Office of the NATO CIO (OCIO) needs to execute and enforce the role of SPA for cybersecurity, which includes the assessment of the Enterprise Surface of Attack and the management of eventual cybersecurity risks stemming from NATO CIS and assets.
Within this framework, the OCIO has developed a series of projects to support the Enterprise ICT coherence and cybersecurity, developing and refining the Enterprise Risk Management processes and tools.
The aim is to use a deeper integration of existing cyber-related processes (e.g. Accreditation, Threat Assessment, Capability Development etc.) into the Risk Management Process and Framework to improve the baseline level of support to existing Cyber Risk Management enabling tools (e.g. Registries, assessment tools, up-to-date maps).
In this context, the support to the Board of CISOA portal and to the risk management process of the various NATO CIS Operational Authorities Enterprise-wide is essential. The OCIO aims at better integrating the functionalities of the Enterprise Risk Management tool prototype (portal) and further improving coherence, information sharing and Situational Awareness in the area of risk management in support of the OCIO’s role of main NATO Enterprise Risk Owner.
TASKS
The contractor will effectively and efficiently provide, with minimal supervision, the following services, with a special focus on cybersecurity risk management:
2.1 Expand the functionalities of the Enterprise Risk Management tool prototype (portal) supporting the Cyber Risk Management enabling tools (e.g. Registries, assessment tools, up-to-date maps). The portal is used as a baseline to include additional features in support of the accreditation process, coordinated with all recognised Security Accreditation Process Stakeholders (SAAs, CISOAs, CISPs and CISPIAs) by the OCIO itself.
o Measurement: To the NATO CIO satisfaction with the degree of support provided in managing and supporting the Cyber Risk Management enabling tools (e.g. Registries, assessment tools, up-to-date maps) ;
2.2 Support the integration of existing cyber-related processes (e.g. Accreditation, Threat Assessment, Capability Development etc.) into the Risk Management Process and Framework, by integrating and feeding the necessary inputs.
o Measurement: The degree and quality of support in the deve
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s