2025-0227 Support for Cloud Security and Compliancy (NS) - FRI 25 Jul at EMW, Inc.

We are redirecting you to the source. If you are not redirected in 3 seconds, please click here.

2025-0227 Support for Cloud Security and Compliancy (NS) - FRI 25 Jul at EMW, Inc..  Deadline Date:. Friday 25 July 2025 . Requirement:. Support for Cloud Security and Compliancy. Location:. Off-Site. Note: . Please refer to your Subcontract Agreement, article 6.4.1.a, which states “Off-Site Discount: 5% (this discount is applicable to all requirements, and applies when the assigned personnel are permitted to work Off-Site, such as at- home)". Please be sure to price this discount in your overall price proposal when submitting bids against off-site RFQs. Period of Performance:. 2025 BASE period: As soon as possible but not later than 1st September 2025 – 31st December 2025, with the possibility to exercise following options:. • 2026 Options: 1st January 2026 until 31st December 2026. • 2027 Options: 1st January 2027 until 31st December 2027. • 2028 Options: 1st January 2028 until 31st December 2028. Required Security Clearance:. NATO SECRET. Special Terms and Conditions:. Non-disclosure undertaking to be signed.  . 1 INTRODUCTION. Supporting NATO throughout all its geographical locations, NCIA is looking for Support for Cloud Security and Compliancy, supporting the journey of NATO’s modernization of IT services, through leveraging the public cloud (Microsoft Azure, M365 and Amazon AWS), delivering managed, protected, security-centric and reliable IT Services.. NCIA – Cloud Operations Team. The NATO Communications and Information Agency (NCIA) is dedicated to supporting NATO's strategic objectives, including the ambitious NATO 2030 agenda. As part of this commitment, we are spearheading the modernization and digital transformation of NATO’s IT services. Our focus is on leveraging public cloud technologies like Microsoft 365 and Intune, incorporating a security-by-design approach, and ensuring a seamless transition to a modern, collaborative workplace environment.. To achieve these goals, we are building a Cloud Operations team under the Cloud Portfolio, operating under the NATO Enterprise Cloud Operating Model (NECOM) and under the guidance of the Cloud Center of Excellence (CCoE). The NECOM framework provides a standardized approach for cloud service management, ensuring. interoperability, scalability, and security across NATO's IT infrastructure. The Cloud Center of Excellence will serve as a hub for best practices, innovation, and expertise, driving the adoption and optimization of cloud technologies within NATO. This team will play a crucial role in our journey towards providing managed, protected, and reliable End User Services.. Embracing the latest technological advancements, this initiative will foster innovation and ensure NATO remains at the cutting edge of IT capabilities. By continuously evolving and integrating new technologies, we aim to enhance operational efficiency and readiness for future challenges. This remote support offers an exciting opportunity to be at the forefront of NATO's technological evolution and contribute to the security and efficiency of our operations.. NCIA – Cloud Centre of Excellence (CCoE). The Cloud Centre of Excellence (CCoE) within NCIA is focused on driving successful cloud adoption and maximizing the potential of cloud technologies across the organization. It serves as a central governing body, promoting best practices, enabling knowledge sharing, and ensuring alignment between business objectives and cloud initiatives. The CCoE supports various cloud-based solutions, ensuring their effective and efficient implementation and management. By fostering a culture of continuous improvement and innovation, the CCoE helps NCIA leverage cloud technologies to enhance operational efficiency, scalability, and agility.. The ideal service will offer expertise in Microsoft Defender, Sentinel, Purview, DLP, PowerShell scripting, Infrastructure as Code, Azure Policies, and Conditional Access Policies.. This service is crucial for maintaining a secure and efficient environment, supporting internal users, external collaborators, and third-party stakeholders.. 2 OBJECTIVES. NCIA is embracing cloud services by transitioning to Microsoft 365 with a security-centric design. This shift aims to enhance operational efficiency, collaboration, and security across the organization.. The objective of this statement of work is to establish a support and operating model for End User Services operating in the Public Cloud, with a focus on Microsoft 365 services.. 3 SCOPE OF WORK. Under the direction / guidance of the local NCIA Point of Contact or the Cloud Operations Center Manager, the Contractor will perform the following activities:. 1) Security Policy Development:. a) Develop and implement comprehensive security policies for the M365 environment.. b) Ensure policies align with organizational and regulatory requirements.. c) Regularly review and update security policies to address emerging threats.. d) Communicate and enforce security policies across the organization.. 2) Compliance Management:. a) Ensure compliance with regulatory requirements and organizational standards.. b) Implement and manage data loss prevention (DLP) policies.. c) Conduct regular compliance audits and risk assessments.. d) Develop and maintain compliance documentation and records.. 3) Advanced Threat Protection:. a) Configure and manage Microsoft Defender products and services (i.e. Microsoft Defender XDR. Microsoft Defender for Endpoint, Microsoft Defender for office 365 , Microsoft Defender for Identity, Microsoft Sentinel). b) Implement Advanced Threat Protection (ATP) policies to detect and mitigate threats.. c) Monitor threat analytics and respond to security incidents.. d) Conduct regular security assessments and vulnerability scans.. 4) Data Encryption and Information Protection:. a) Configure and manage data encryption policies.. b) Configure and manage Microsoft Purview for data governance.. c) Ensure data protection policies are applied to sensitive information.. d) Monitor and report on data protection compliance.. 5) eDiscovery and Legal Hold Management:. a) Implement and manage eDiscovery and legal hold processes.. b) Ensure that data required for legal proceedings is preserved.. c) Conduct regular audits of eDiscovery and legal hold configurations.. d) Provide training and support for eDiscovery users.. 6) Security Monitoring and Reporting:. a) Monitor the security health of the M365 environment using Microsoft 365 Security Center.. b) Generate security reports and provide insights for improvement.. c) Utilize security information and event management (SIEM) tools.. d) Identify and address security incidents promptly.. 7) Automation and Scripting:. a) Develop and maintain scripts (i.e. PowerShell, KQL) to automate security and compliance tasks.. b) Implement automated workflows using Power Automate.. c) Create automated solutions for compliance reporting and monitoring.. d) Maintain and update existing automation scripts.. 8) User Training and Awareness:. a) Develop and deliver security training programs for end-users.. b) Promote security awareness and best practices across the organization.. c) Provide guidance on secure use of M365 tools.. d) Conduct regular security awareness campaigns.. 9) Continuous Improvement:. a) Stay up-to-date with the latest M365 security and compliance features.. b) Continuously improve security and compliance processes.. c) Participate in security and compliance forums and training.. d) Propose and implement new security measures and enhancements. Due to the AGILE approach of this project, the specific deliverables and associated acceptance criteria will be defined for each sprint between NCIA and the contractor. This includes sprint planning, execution and review processes, which are detailed below:. Sprint Planning:. Objective: Plan the objectives for the upcoming sprint.. Kick-off meeting: Conduct a bi-weekly (every two weeks) meeting with the contractor to plan the objectives of upcoming sprint and review contractor`s manpower to meet the agreed deliverables.. Set sprint goals: Define clear, achievable goals for the sprint and associated acceptance criteria, including specific delivery targets, Quality standards as well as Key Performance Indicators (KPIs) for each task to be recorded in the sprint meeting minutes.. Agree on the required level of effort for the various sprint tasks.. Backlog Review: Review and prioritise the backlog of tasks, issues, and improvements from previous sprints.. Assess each payment milestone cycle duration of two sprints. State of completion and validation of each sprint status and sign off sprints to be submitted for payment as covered in Section 4.. Sprint Execution. Objective: Contractor to execute the agreed “sprint plans” with continuous monitoring and adjustments.. Regular meetings between NCIA and the contractor to review sprint progress, address issues, and make necessary adjustments to the processes or production methodology. The Meetings will be physically in the office.. Continuous improvement: Contractor to establish a continuous feedback loop to gather input from all stakeholders for ongoing improvements and their subsequent implementation depending on NCIA approval.. Progress Tracking: Contractor to use a shared dashboard or tool to track the status of the sprint deliveries and any issues.. Quality Assurance/Quality Check: Contractor shall ensure that the quality standards agreed for the sprint deliverables are maintained throughout the sprint.. Quality Control: NCIA to perform the Final Quality Control of the agreed deliverables and provide feedback on any issues.. Sprint Review. Objective: Review the sprint performance and identify areas for improvement.. At the end of each sprint, there will be a meeting between the NCIA and the Contractor to review the outcomes against the acceptance criteria comprising sprint goals, agreed quality criteria and Key Performance Indicators (KPIs).. Define specific actions to address issues and enhance the next sprint.. Sprint Payment. For each sprint to be considered as complete and payable, the contractor must report the outcome of their service during the sprint, first verbally during the sprint review meeting and then in writing within five days after the sprint’s end date. A report must be sent by email to the NCIA service manager, listing all the achievements against the agreed tasking list set for the sprint.. The contractor's payment for each sprint will be depending upon the achievement of agreed Acceptance Criteria for each task, defined at the sprint planning stage. This will include specific delivery targets, quality standards as well as Key Performance Indicators (KPIs) for each task.. The payment shall be dependent upon successful acceptance as set in the above planning/review meetings. This will follow the payment milestones that shall include a completed Delivery Acceptance Sheet (DAS) . Invoices shall be accompanied with a Delivery Acceptance Sheet (DAS) signed by the Contractor and project authority.. If the contractor fails to meet the agreed Acceptance criteria for any task, the NCIA reserves the right to withhold payment for that task/sprint.. Each sprint has a duration of 5 working days. The content and scope of each sprint will be agreed during the sprint‐planning meetings as covered above.. The contractor’s personnel will be part of a team providing Technical Level 2 and 3 support, ensuring the secure, available, managed and compliant delivery of Public Cloud Services to NATO and its Strategic Commands.. The measurement of execution for this work is sprints, with each sprint planned for a duration of 5 working days.. 4 DELIVERABLES AND PAYMENT MILESTONES. The following deliverables are expected from this statement of work:. 1. Complete the activities/tasks agreed in each sprint meeting as per section 3 above.. 2. Produce sprint completion reports (format: e-mail update) or the formal documentation required per specific task;. 3. The Contractor will participate in the daily reporting and planning activities (daily stand-ups) as well as the required participation in workshops, events and conferences related to the supported services, as requested by the Senior Service Delivery Manager.. The Purchaser (NCIA) reserves the right to exercise a number of options of one or more sprints based on the same scrum deliverables, at a later time, depending on the project priorities and requirements, at the following cost: for base year (2025) at the same cost, for outer years (2026-2028) the Price Adjustment Formula will be applied in accordance with paragraph 6.5 of the Framework Contract Special Provisions. The payment shall be dependent upon successful acceptance of the Delivery Acceptance Sheet (DAS) – (Annex B). Invoices shall be accompanied with a Delivery Acceptance Sheet (Annex B) signed by the Contractor and the NCIA PoC.. Payment Schedule will be according to payment milestones upon completion of 4 consecutive sprints. Upon completion and validation of each sprint and at the end of the monthly milestone, following the acceptance of the sprint report.. The following deliverables are expected from the work on this statement of work. Deliverable: 18 sprints . Payment Milestones: Upon completion of each fourth sprint and at the end of the work. Completion of each sprint shall be documented in the Delivery Acceptance Sheet (DAS) – (Annex B), signed for acceptance by the Purchaser’s authorized point of contact and the Contractor.. 2026 OPTIONS: 01 January 2026 to 31 December 2026. Deliverable: Up to 46 sprints. Cost Ceiling: Price will be determined by applying the price adjustment formula as outlined in CO‐115786‐ AAS+ Special Provisions article 6.5.. Payment Milestones: Upon completion of each fourth sprint and at the end of the work. Completion of each sprint shall be documented in the Delivery Acceptance Sheet (DAS) – (Annex B), signed for acceptance by the Purchaser’s authorized point of contact and the Contractor.. 2027 OPTIONS: 01 January 2027to 31 December 2027. Deliverable: Up to 46 sprints. Cost Ceiling: Price will be determined by applying the price adjustment formula as outlined in CO‐115786‐ AAS+ Special Provisions article 6.5.. Payment Milestones: Upon completion of each fourth sprint and at the end of the work. Completion of each sprint shall be documented in the Delivery Acceptance Sheet (DAS) – (Annex B), signed for acceptance by the Purchaser’s authorized point of contact and the Contractor.. 2028 OPTIONS: 01 January 2028 to 31 December 2028. Deliverable: Up to 46 sprints. Cost Ceiling: Price will be determined by applying the price adjustment formula as outlined in CO‐115786‐ AAS+ Special Provisions article 6.5.. Payment Milestones: Upon completion of each fourth sprint and at the end of the work. Completion of each sprint shall be documented in the Delivery Acceptance Sheet (DAS) – (Annex B), signed for acceptance by the Purchaser’s authorized point of contact and the Contractor.. 5 COORDINATION AND REPORTING. The contractor shall participate in daily status update meetings, activity planning and other meetings as instructed, via electronic means using Conference Call capabilities, according to the Operation Managers / Team Leaders instructions.. For each sprint to be considered as complete and payable, the contractor must report the outcome of his/her work during the sprint, first verbally during the retrospective meeting and then in written within three (3) days after the sprint’s end date. The format of this report shall be a short email to the NCIA Point of Contact mentioning briefly the work held and the development achievements during the sprint.. The contractor, providing services included under this SoW, will be part of the NCIA Cloud Operations Team.. 6 SCHEDULE. This task order will be active immediately after signing of the contract by both parties. The 2025 BASE period of performance is as soon as possible but not later than 1st September 2025 and will end no later than 31st December 2025.. If the 2026 option is exercised, the period of performance is 01st January 2026 to 31st December 2026.. If the 2027 option is exercised, the period of performance is 01st January 2027 to 31st December 2027.. If the 2028 option is exercised, the period of performance is 01st January 2028 to 31st December 2028.. 7 CONSTRAINTS. All the deliverables provided under this statement of work will be based on NCIA templates or agreed with the project point of contact.. All code, scripts, documentation, etc. will be stored under configuration management and/or in the provided NCIA tools.. 8 SECURITY. To deliver services under this SoW require a valid NATO SECRET security clearance.. All the deliverables of this project will be considered NATO UNCLASSIFIED, while access to networks exceeding this classification level is required.. With this role being of technical nature providing administrative support, a security clearance at the NATO Secret level is required prior to the start of the engagement.. The Contractor’s personnel will have to sign the enclosed non-disclosure undertaking attached under Annex C.. 9 PRACTICAL ARRANGEMENTS. The contractor will be required to work 100% off site NCIA.. The contractor will be required to work within a NATO country, following the rules and regulations applicable for the operations of NATO CIS.. NCIA Recognised Business hours/Holidays: NCIA-Braine L’Alleud (BLA), Belgium official holiday schedule applies and will be provided to the contractor.. NCIA Hours of Operations: Monday to Thursday 0830 – 1730 and Friday 0830 – 1530 (CET). Contractor Furnished Services: Contractor shall furnish everything required to perform the contract except for the items specified and covered under NCIA Furnished Property and Services below.. NCIA Furnished Property and Services: Access to relevant networks and environments will be provided by NCIA. The support services depicted in this SOW are expected to be carried by a SINGLE RESOURCE.. 10 TRAVEL. The contractor is required to travel for on-boarding and off-boarding to NATO offices in NATO HQ or Braine-l'Alleud as part of this role, for periods not exceeding 1 week.. Travel arrangements will be the responsibility of the contractor and the expenses will be reimbursed in accordance with Article 5.5 of AAS Framework Contract and within the limits of the NCIA Travel Directive.. 11 QUALIFICATIONS. [See Requirements]. 8 SECURITY. With this role being of technical nature providing administrative support, a security clearance at the NATO Secret level is required prior to the start of the engagement.. 11 QUALIFICATIONS. The Support for Cloud Security and Compliancy require an experienced Cloud Security and Compliancy Engineer with the following qualifications:. . Technical Expertise (Minimum 5 years of experience): In-depth knowledge of Microsoft Defender products and services (i.e. Microsoft Defender XDR. Microsoft Defender for Endpoint, Microsoft Defender for office 365, Microsoft Defender for Identity, Microsoft Sentinel). Proficiency in scripting and automation tools (e.g., PowerShell, KQL). In-depth knowledge of Microsoft Purview for data governance. Experience in security monitoring and compliancy. . Analytical and Problem-Solving Skills (Minimum 3 years of experience): Strong analytical skills to assess and improve security processes and workflows. Ability to troubleshoot complex security issues and implement effective solutions.. . Security and Compliance Knowledge (Minimum 4 years of experience): Understanding of security best practices and compliance requirements. Experience conducting audits and ensuring adherence to regulatory standards.. . Communication and Collaboration (Minimum 3 years of experience): Excellent communication skills to effectively collaborate with IT teams, stakeholders, and end-users.Ability to document processes clearly and provide training on Security and Compliancy tools and practices.. . Organizational Skills (Minimum 3 years of experience): Strong organizational skills to manage multiple tasks and priorities effectively. Attention to detail in managing user accounts, groups, and access controls.. . Team Collaboration (Minimum 2 years of experience): Ability to work effectively as part of a team and share knowledge and resources. Willingness to collaborate with colleagues to solve complex issues.. . Others:. . The Contractor has strong customer relationship skills, including negotiating complex and sensitive situations under pressure.. . Full proficiency in the English language. French language proficiency is of advantage.. . Company Location: Belgium.