Cybersecurity Compliance Architect
Summary
The Cybersecurity Compliance Architect will support NATO's transition to continuous authorization to operate (cATO) by digitizing security controls and mapping technical cloud triggers to OSCAL models. The role involves working with the RegScale platform to automate system security plans and ensure regulatory compliance.
Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.
Who we are supporting
The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.
The NCIA provides a wide range of services, including:
- Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.
- Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.
- Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
- Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.
- Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers.
Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities.
The program
Assistance and Advisory Service (AAS)
The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.
To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.
Role ID – 2026-0129
Role Background
The NATO Communications and Information Agency (NCIA) located in The Hague, The Netherlands, is providing technical support to the NATO HQ Cyber and Digital Transformation (CDT) Division and Supreme Allied Command Transformation (SACT) by moving away from manual point-in-time audits, authorization to operate and security accreditation towards Continuous Governance, Risk and Compliance Auditing leading to Continuous Authorization to Operate (cATO) and Continuous Security Accreditation via EaC (Everything as Code) + Regulatory Operations (RegOps) using NIST OSCAL (Open Security Controls Assessment Language ) data models with the ultimate goal to deploy the RegScale platform as a workload and establish a Minimum Viable Product (MVP) for Continuous Authorization to Operate (cATO)
Role Duties and Responsibilities
They shall perform the following activities in support of the deliverables. These activities are not considered deliverables in themselves.
- Review the existing SRS, D32/CSRS, NIST/ISO baseline for OSCAL conversion.
- Identify and document relevant technical triggers from the cloud environ.
- Review sampled automated evidence to confirm completeness, accuracy and suitability for supporting System Security Plan (SSP) content.
- Conduct Stakeholder Review Sessions to validate assumptions, mappings, evidence sources, and SSP generation logic.
- Issue tracking and remediation support
Deliverables
D001 – Catalog Digitization
- Import the organization's SRS (D32 / CSRS) or NIST/ISO baseline into OSCAL format.
- Acceptance: Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.
D002 – Policy-as-Code (PaC) Mapping
- Map technical triggers from cloud to specific OSCAL Control IDs.
- Acceptance: Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.
D003 – Digital SSP Generation
- Use RegScale to output the first full System Security Plan based on automated evidence.
- Acceptance: Approval by the NCIA PM in coordination with the CDT project sponsor or designated authority.
Essential Skills, Experience and Certifications
- A minimum of 3 years’ experience in all of the following items:
- NIST/ISO frameworks, JSON/YAML proficiency, regulatory mapping.
- Compliance-to-code translation.
- Documented (or demonstrable) experience in process analysis, and design techniques,
Desirable Skills, Experience and Certifications
- Robust technical knowledge of NATO operations, responsibilities and organization – with specific focus on how NATO achieves technical interoperability on the battlefield.
- Comprehensive understanding of NATO’s Cloud strategies.
- Knowledge of ITIL, COBIT, or equivalent.
- Familiarity with current and evolving capabilities and trends in military and civilian communication protocols and standards.
Desirable Competencies
- Deciding and Initiating Action - Takes responsibility for actions, projects and people; takes initiative and works under own direction; initiates and generates activity and introduces changes into work processes; makes quick, clear decisions which may include tough choices or considered risks.
- Adhering to Principles and Values - Upholds ethics and values; demonstrates integrity; promotes and defends equal opportunities, builds diverse teams; encourages organizational and individual responsibility towards the community and the environment.
- Relating and Networking - Easily establishes good relationships with customers and staff; relates well to people at all levels; builds wide and effective networks of contacts; uses humor appropriately to bring warmth to relationships with others.
- Formulating Strategies and Concepts - Works strategically to realize organizational goals; sets and develops strategies; identifies, develops positive and compelling visions of the organization’s future potential; takes account of a wide range of issues across, and related to, the organization.
- Achieving Personal Work Goals and Objectives - Accepts and tackles demanding goals with enthusiasm; works hard and puts in longer hours when it is necessary; seeks progression to roles of increased responsibility and influence; identifies own development needs and makes use of developmental or training opportunities.
Education
- A minimum requirement of a Bachelor’s degree at a nationally recognized/certified University in a related discipline and 3 years post-related experience
Language Proficiency
- Business English
Working Location
- The Hague, Netherlands
Working Policy
- On-site
Travel
- Some travel to other NATO sites may be required
Security Clearance
- Valid National or NATO Secret personal security clearance
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Location
- Please provide your LinkedIn Profile address? optional
- What is your Nationality/Citizenship status from the below list? choose one
- Do you hold a second Nationality/Citizenship in addition to the one that you identified previously? choose one
- If you identified "Other" as a Nationality/Citizenship status, please identify which country is this? optional
- What is your current notice period from your existing employer choose one
- Do you currently hold a Personal Security Clearance (PSC)? choose one
- What is your current Personal Security Clearance (PSC) level to the best of your knowledge?