About the job
Almaviva De Belgique is hiring a CIS Security Engineer with NATO clearance for its office in Oeiras, Lisboa, Portugal. This position centers on safeguarding Communications and Information Systems (CIS) throughout their lifecycle, from initial design to day-to-day operation. The role demands careful attention to accreditation standards and security compliance at every step.
Main responsibilities
- Define, design, procure, and implement secure CIS solutions that meet rigorous security requirements.
- Ensure all CIS projects adhere to security accreditation policies and maintain appropriate risk levels.
- Conduct detailed security risk assessments and verify that systems fulfill policy requirements for accreditation.
- Collaborate with the CTO’s CIS Planning and Implementation Authority (CISPIA) to align CIS solutions with organizational objectives.
- Integrate cybersecurity measures across the system lifecycle, from design through deployment and operation.
- Represent CIS security interests in governance forums and communicate effectively with stakeholders.
- Prepare and manage security accreditation documentation, including:
- CIS Description
- Security Accreditation Plan (SAP)
- Security Risk Assessment (SRA)
- Security Requirement Statements (SRSt)
- Security Operating Procedures (SecOPs)
- Security Test & Verification Plan (STVP)
- Security Test & Verification Report (STVR)
Requirements
- Bachelor's degree in a relevant field and at least 4 years of experience, or a minimum of 8 years of relevant experience without a degree.
- Strong understanding of cybersecurity domains, including:
- Boundary protection
- Encryption
- Identity and access management
- Monitoring and detection
- Incident response
- Vulnerability assessment
- Risk management
- Comprehensive knowledge of:
- CIS security principles
- Networking
- Vulnerabilities in modern operating systems and applications
- At least 4 years of experience with:
- Cybersecurity principles, technologies, and best practices
- CIS security controls in both traditional and cloud environments
- Designing, implementing, testing, and validating security components
- Conducting security risk assessments and supporting accreditation processes
- Identifying threats, vulnerabilities, and residual risks, and recommending mitigations
- Supporting security accreditation in large-scale CIS projects
- Using risk assessment methodologies and tools
