Red Team Operator

North Atlantic Treaty Organization

Location:
Mons, Belgium
Grade:
NATO Grade G17-G20
Category:
Professional Staff
Posted Aug 7, 2026Apply by Sep 6, 2026 (14d left)
See your match score & apply

Join the NATO Communications and Information Agency (NCIA) as a Red Team Operator based in Mons, Belgium. The role involves planning and executing red team engagements simulating adversarial tactics against enterprise systems, conducting offensive security operations, developing custom tools, and performing social engineering campaigns to assess defenses.

Responsibilities

  • Participate to the planning, design, and execution of red team engagements that simulate adversarial tactics, techniques and procedures against enterprise systems, covering network, applications and cloud domains.
  • Conduct reconnaissance, open-source intelligence (OSINT) gathering, vulnerability scanning, exploitation, lateral movement, persistence installation, and command & control management during offensive security operations.
  • Perform research and development activities with the goal of developing and utilizing custom tools, scripts, and malware to replicate sophisticated cyber threats and evade detection mechanisms.
  • Perform social engineering and phishing campaigns to assess the effectiveness of human and process defences.
  • Create clear and actionable reports for both technical teams and executive stakeholders.

Requirements

  • A Master’s degree at a nationally recognised/certified University in a related discipline and 5 years post-related experience or a Bachelor’s degree with 8 years post related experience (for the G20 role) OR A Bachelor’s degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience (for the G17 role). Exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate’s particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to the function of the post.
  • Cybersecurity oriented certification such as GRTP, GPEN, GWAPT, OSCP, OSCE, OSEE, GXPN, Red team operator related certification, GREM.
  • At least 5/3 years practical experience working in cybersecurity or a related field, such as information technology, network administration, or software development.
  • Extensive knowledge and experience (at least 5/3 years) in the following areas: Web application penetration testing; IT infrastructure penetration testing; Network security architecture design; Assessing security vulnerabilities within OS, software, protocols & networks; Researching and evaluating security products & technologies; Knowledge in system and network administration of UNIX and Windows systems; Use of penetration testing tools, techniques, and recognized testing methodologies; Scripting skills in at least one of the following: Perl, Python, Ruby, shell (bash, sh).
  • Relevant practical experience identifying vulnerabilities and discovering potential 0days.
  • Proven experience in penetration testing, adversary emulation or Red teaming for at least 3 years.
  • Understanding of the principles of adversary emulation.
  • Understanding of tactics, techniques and procedures of threat actors based on MITRE ATT&CK Framework.
  • Ability to create and execute custom scripts to simulate attack activities.
  • Understanding of the various types of detections available (defence in depth) and how to bypass it.
  • Knowledge of the latest security trends and best practices.
  • Ability to create and use custom tools to automate and optimize red team engagements.
  • Experience with security testing tools and methodologies, such as fuzzing, static and dynamic application security testing, and penetration testing.
  • Technical knowledge in system and network security, authentication and security protocols, cryptography and application security.
  • Proven ability to write clear and structured technical reports including executive summary, technical findings and remediation plan for several different audiences.
  • Fluency in English, both written and spoken.

Skills

  • Web Application Penetration Testing
  • IT Infrastructure Penetration Testing
  • Network security architecture design
  • Security Vulnerability Assessment
  • System and network administration
  • UNIX system administration
  • System Administration
  • Penetration Testing Tools
  • Scripting in Perl
  • Scripting in Python
  • Scripting Ruby
  • Scripting in shell
  • Adversary Emulation
  • MITRE ATT&CK Framework
  • Custom Script Development
  • Security detection evasion
  • Security trends knowledge
  • Security testing tools
  • Fuzzing
  • Static Application Security Testing
  • Dynamic Application Security Testing
  • Cryptography Technology
  • Security Protocols
  • Application Security
  • Technical Report Preparation

Languages

English