Deadline Date: Wednesday 5 March 2025
Requirement: Support Operation & Maintenance of Active Directory Security Assessment Tool
Location: Mons, BELGIUM
Full Time On-Site: Yes
Not to Exceed: 118,260 EUR
Required Start Date: 14 April 2025
Required Security Clearance: NATO COSMIC TOP SECRET
Purpose:
The objective of this statement of work (SoW) is to outline the scope of work and deliverables for the operation and maintenance of Active Directory Security Assessment Tool to be conducted by the selected company.
The purpose of the work package is to provide support to NATO Cyber Security Centre (NCSC) to fulfil identified Active Directory Security Assessment Tool operation and maintenance activities more effectively.
Background:
The Office of the CIO (OCIO) Enterprise Cyber Security Posture Improvement project focuses on acquisition and implementation of state‐of‐art tools to enhance Enterprise‐wide cybersecurity capabilities considering the key cybersecurity functions.
NCIA initiated a project and procured Active Directory Security Assessment Tool (Tenable Identity Exposure) providing identity unification and risk scoring, real-time attack detection and continually assessing directory services security in real-time, eliminate attack paths that lead to domain domination, and investigate and inform.
To support NCSC for the execution of tasks identified in the subject work package of the project, the NCIA is looking for subject matter expertise in the delivery of complex, foundational and novel Cybersecurity capability.
This contract is to provide consistent support on a deliverable‐based (completion‐type) contract, to NCSC contributing to its POW based on the deliverables that are described in the scope of work below.
Scope of Work:
The aim of this SOW is to support NCSC with technical expertise specifically related to the operation and maintenance of Active Directory Security Assessment Tool with a deliverable based (completion‐type) contract to be executed in 2025.
Service performed by a contractor include the lifecycle management of the Tenable Identity Exposure software (including all tasks related to A2SL inclusion), its configuration to ensure coverage of all in‐scope Active Directory servers, and the regular monitoring of the availability of the capability.
Under the direction / guidance of the NCSC Point of Contact, a contractor will be the part of the NCSC Team supporting the following activities:
System Installation and Configuration:
* Install and set up Tenable Identity Exposure,
* Ensure the software is deployed correctly across relevant environments,
* Set up integrations with identity systems like Active Directory, LDAP, or cloud‐based IAM solutions.
System Maintenance and Updates:
* Apply software updates and patches,
* Regularly update Tenable Identity Exposure and related systems to ensure the latest security patches and features are applied,
* Ensure that the platform is running smoothly by checking system logs, server performance, and availability,
* Request and build monitoring and alerting mechanisms to be aware of the issues, system resource consumption,
* Address technical issues, such as connectivity problems between Tenable Identity Exposure and other integrated systems or errors in scans or reports,
Manage Integrations:
* Ensure Tenable Identity Exposure is integrated with other security solutions like SIEM (Security Information and Event Management) systems, vulnerability management platforms, or ticketing systems,
* Set up proper data synchronization between identity systems and Tenable Identity Exposure to ensure accurate and up‐to‐date information.
User and Role Management:
* Configure access control for the Tenable Identity Exposure platform itself, ensuring that only authorized personnel have the right level of access,
* Set up appropriate permissions and roles for the identity systems being monitored, ensuring seamless integration.
Monitoring and Reporting:
* Proactively review logs and alerts generated by Tenable Identity Exposure to identify any technical issues, errors, or failures in the monitoring process,
* Produce and distribute reports related to system health, monitoring activities, and compliance status (e.g., audit logs, system performance metrics.
System Documentation:
* Document configuration and changes: Keep up‐to‐date documentation of all configurations, integration steps, troubleshooting procedures, and system maintenance tasks,
* Maintain an inventory of connected systems: Keep track of all integrated identity sources, IAM systems, and external tools connected to Tenable Identity Exposure.
Automation and Scripting:
* Automate tasks: Write scripts or configure automation tasks to streamline routine system management tasks, such as regular backups, system checks, or integrations.
* Improve system efficiency: Identify areas where automation could reduce manual intervention and improve operational efficiency.
Coordination and Reporting:
The contractor shall participate in daily status update meetings, activity planning and other meetings as instructed, physically in the office, or in person via digital means using conference call capabilities, according to the manager’s / team leader’s instructions.
For each sprint to be considered as complete and payable, the contractor must report the outcome of his/her work during the sprint, first verbally during the retrospective meeting and then in written within three (3) days after the sprint’s end date. The format of this report shall be a short email to the NCIA Project Manager mentioning briefly the work held and the development achievements during the sprint.
At the end of the project, the Contractor shall provide a Project Closure Report that is summarizing the activities during the period of performance at high level.
Acceptance And Rejection Criteria:
Acceptance Criteria:
* Quality of work reached NATO standards,
* Tasks are completed within the assigned time,
* Performances are as defined by the line manager.
Rejection Criteria:
Quality of work is low,
Tasks are not completed within the assigned time,
Performances are not as defined by the line manager.
A replacement will be requested if the contractor cannot fulfil the tasks as explained in rejection criteria.
Payment will not be done if the sprint is not completed.
Penalty and Rejection Process:
If the contractor does not meet the work expectation based on the CV presented, the assigned tasks are not performed as expected based on NATO standards or the finalization of the assigned tasks are not done within the given time, the sprint will not be accepted and the service will not be paid.
If any of the above mentioned issues persist, the outsourcing partner will be asked to provide a replacement.
Constraints:
All the deliverables provided under this statement of work will be based on NCIA templates or agreed with the project point of contact.
All documentation etc. will be stored under configuration management and/or in the provided NCIA tools.
Security and Non-Disclosure:
It is mandatory to have the candidate be in possession of a NATO COSMIC TOP SECRET security clearance to facilitate follow‐on engagements and coordination at NATO venues.
The signature of a Non‐Disclosure Agreement between the contractor contributing to this task and NCIA will be required prior to execution.
Practical Arrangements:
The contractor will be required to work approximately 100% onsite in SHAPE ‐ Mons / BEL as part of this engagement. The NCSC Team is located in SHAPE ‐ Mons / BEL, with working hours to be adjusted accordingly.
The contractor will be required to work within a NATO country, following the rules and regulations applicable for the operations of NATO CIS.
The contractor may NOT be required to travel to other NATO locations as part of his role. Travel expenses for missions to other NATO/NCIA locations rather than SHAPE ‐ Mons / BEL will be reimbursed to the individual directly (outside this contract) under NATO rules.
This work must be accomplished by one contractor for the entire performance period.
The Purchaser will provide the contractor with the following Purchaser‐Furnished Equipment (PFE):
Access to NATO sites, as required, for the purpose of executing this SOW.
Workspace (needed business IT for both on‐ and off‐site work, hot‐desk at NCSC facility).
NCIA “REACH” laptop to be used by the contractor for the execution of the contract.
Requirements:
Security and Non-Disclosure Agreement:
* It is mandatory to have the candidate be in possession of a NATO COSMIC TOP SECRET security clearance to facilitate follow‐on engagements and coordination at NATO venues.
Required Profile:
The contractor(s) that is going to perform the identified tasks as an Operation and Maintenance Expert of Active Directory Security Assessment Tool must have demonstrated skills, knowledge and experience as listed below.
Activities performed by a contractor include the lifecycle management of the Tenable Identity Exposure software (including all tasks related to A2SL inclusion), its configuration to ensure coverage of all in‐scope Active Directory servers, and the regular monitoring of the availability of the capability.
* Bachelor's degree in Computer Science, Information Technology, or related field or equivalent experience.
* 3+ years of experience in IT security, with a focus on System Administration, Security Tools Management in large organisations.
* Strong understanding of security best practices and experience with Tenable products especially with Tenable Identity Exposure.
* IP switching and routing in a wired and wireless environment.
* Systems administration, ideally both with Windows and Linux.
* Good engineering skills including programming and/or scripting knowledge (python, shell scripting, PowerShell).
* Demonstrable experience of analysing and interpreting system, security and application logs in order to diagnose faults and spot abnormal behaviours.
* Experience with Service Management, monitoring and reporting tools, ideally Solarwinds.
* Database management skills, preferably MS SQL.
* Experience with system instrumentation solutions such as Ansible.
* Experience with Active Directory Management.
Desirable Profile:
The candidate should also ideally have knowledge and experience in the following areas:
* Experience in working with NATO.
* Experience of working with NATO Communications and Information Agency.
* Experience of working with national Defence or Government entities.