Brussels, Brussels, Belgium•BrusselsBelgiumEurope•April 2, 2025
Deadline Date: Monday 3 October 2022
Requirement: Cyber Threat Intelligence Analyst Services
Location: Brussels, BE
Full time on-site: Yes
NATO Grade: G12/75
Total Scope of the request (hours): 440
Required Start Date: 31 October 2022
End Contract Date: 31 December 2022
Required Security Clearance: NATO SECRET
1. INTRODUCTION
The NATO Office of the Chief Information Officer (OCIO) is responsible for Cyber Defence for the NATO Enterprise. The OCIO has been tasked to increase NATO’s Cyber Defence posture. As part of this initiative, the OCIO plans to enhance the ability of NATO’s Cyber Threat Analysis Branch (CTAB) within the Joint Intelligence & Security Division to provide the quality and quality of cyber intelligence products required by the NATO Enterprise. The contractor will work for the OCIO, however, will be located with CTAB.
The Cyber Threat Analysis Branch is responsible for providing evidence-based assessments of the cyber threat landscape to empower NATO stakeholders to make risk-informed decisions. The multidisciplinary team combines all-source data with cutting edge technologies to support and enhance the Alliance leaderships’ understanding on the nature of cyber competition and conflict. CTAB systematically identifies strategic patterns and trends in cyber space and generates tailored insights to support network defence and mission assurance with predictive analysis, cyber threat intelligence, and threat hunting.
The contractor will support the work of the OCIO and the Cyber Threat Analysis Branch by reviewing and analysing past incidents and getting insights on trends and possible threat actor attack patterns targeting NATO.
2. TASKS
In providing Cyber Threat Intelligence Analyst services, the contractor will be responsible for tracking, reviewing and correlating (historic) events/incidents that are observed by NATO’s internal incident response team. Specific tasks include:
2.1 Support with the development of a process, procedure and methodology to track cluster and link incident tickets together:
Measurement: A document that describes the process, procedure and methodology followed to assess, cluster and link incident response tickets.
2.2 Review, triage, assess, cluster and link historic events/incidents together based on ticket data. Assist in the prioritization of the development of threat hunt playbooks, based on observed and recurring activity. Liaise with NATO’s Incident Handling Officers to understand tickets and request more technical data when needed.
Measurement: Report on incidents that show overlap, links, etc, describing why they are linked, why it matters, lessons that can be learned and how to defend against the type of activity.
2.3 Assess, cluster and link disparate activity into related intrusions & campaigns.
Measurement: Merger or cross-correlation of intrusion sets into operations or campaigns.
2.4 Support Enterprise risk and incident management activities
Measurement: support information exchange with OCIO, based on cyber threat data analysis and trend information.
Exploration of how above correlated information could be ingested and rendered in Enterprise tools used by the OCIO.
4. LOCATION
The services will be provided on site at the NATO HQ offices in Brussels, Belgium.
5. TIMELINES
The services of the contractor are to be provided in the period of 31st October 2022 until 31th December, 2022. An earlier start date is possible, if feasible by the contractor.
Under the current framework contract, a contract extension is possible for the calendar year 2023.In any case, future contract extensions are subject to performance of the contractor and related NATO regulations.
6. SPECIFIC WORKING CONDITIONS
Secure environment with standard working hours, with the exception of working in non-standard working hours up to 360 hours annually.
In addition, it may exceptionally be required to work non-standard hours in support of a major Cyber Incident or on a shift system for a limited period due to urgent operational needs.
7. TRAVEL
No travel is required.
8. SECURITY AND NON-DISCLOSURE AGREEMENT
The contracted individual must be in possession or capable of possessing a security clearance of NATO Secret.
A signed Non-Disclosure Agreement will be required.
Annex A – Special Terms and Conditions
Requirements
3. PROFILE
Mandatory
Desirable