Deadline: November 30, 2026

Multi-Factor Authentication on Internet facing portals Proof of Concept

Location: OFF-SITE, with potential requirements to travel to NATO HQ (Brussels), NATO The Hague (NL), Braine L’Alleud (BE), and/or SHAPE Mons (BE)

Duties & Roles:

  • Proof of Concept (POC) Architecture & Configuration: Build and test a Proof of Concept environment based on a single Entra ID Identity Provider connected to multiple MFA technologies acting as brokers (Moodle, SharePoint, Keycloak, Cognito). Validate, confirm, and prepare the most fit-for-purpose solution for accreditation. Align the architecture with ongoing IT modernization, NATO Cloud programs, and Protected Business Network initiatives.
  • Preparation & Business Analysis: Document and export existing production configurations, production MFA set-ups, user lifecycle processes, self-registration/onboarding models, and user login/logout UI/UX environments. Inventory application interfaces, perform user account audits, map dependencies, and draft the target security architecture.
  • Execution Phase Integration: Create non-production Entra ID app registrations, configure branding, customize sign-in/sign-out text, and establish MFA registration policies. Design self-service signups, browser authentications, and account linking strategies for existing users. Configure custom attributes, identity provider mappers, custom email templates, and Terms of Use. Set up logging monitoring, alerts, and detailed rollback procedures.
  • Security and Logging Governance: Coordinate security and accreditation requirements with NCSC and NISC teams. Conduct logging analysis, perform system administrator log mapping, monitor log forwarding, and design log storage repositories to meet Type 4 Security Audit standardization requirements.
  • Testing and Verification Support: Develop test strategies and test scripts. Support security penetration testing, test Entra ID branding matches, and validate MFA enrollment, self-registration, and authentication flows. Confirm with the Cyber Security department that logging functionality is fully fit for purpose.
  • Service Delivery Enablement: Produce high-standard runbooks, migration plans for each technology provider, and service delivery training materials to enable eventual operational transition. Participate in regular technical exchange and coordination meetings with NCSC and NCIA staff.

Skill, Knowledge & Experience:

  • Identity & Access Management (IAM): Minimum of 5 years of professional experience in IAM. Strong knowledge of authentication protocols, specifically SAML and OIDC. Sound knowledge of federated identity management and Single Sign-On (SSO) solutions (e.g., Okta, Entra ID).
  • MFA Deployment Expertise: Proven experience designing and rolling out Multi-Factor Authentication at scale in an enterprise environment supporting 5,000+ users. Comprehensive experience with certificate-based MFA smart cards, YubiKeys, passkeys/webauthn, TOTP, and push-based MFA applications (e.g., Microsoft Authenticator, Duo). Strong understanding of risk-based or adaptive authentication strategies.
  • Web Security Architecture: Robust understanding of securing web applications and APIs, including TLS, client certificates, reverse proxies, and Zero Trust principles. Solid experience with SSO integration of web applications.
  • Specific Platform Broker Experience: Direct, recent experience configuring MFA technologies following specific platforms as brokers: Moodle, SharePoint, Keycloak, and Cognito. Proven experience configuring Entra ID explicitly as an MFA Provider to those brokers.
  • Soft Skills & Professional Documentation: Proven track record of producing high-quality technical documentation for testing, architecture runbooks, and service delivery. Excellent verbal and written communication skills in English. Strong customer relationship skills with the ability to negotiate complex, sensitive situations under pressure.
  • Demographics: Must possess the nationality of one of the NATO member nations.
  • Clearance: A valid NATO Secret security clearance is mandatory for the entire duration of the contract.

    By sending this form, you agree with our Privacy Policy and Terms and Conditions.

     

    If you’re interested in this opportunity and would like to learn more, please fill out the form below, and a member of our team will get in touch with you shortly.