Legal Policy Officer (Cybersecurity Certification - TA/AD 8)

Job Category

Job Experience

Job Location

Expiration Date

07 Jun 2019

Lead Policy Officer-Cybersecurity Certification (TA/AD 8)

Ref. ENISA-TA55-AD-2019-07

The European Union Agency for Network and Information Security (ENISA) welcomes applications from highly motivated candidates to contribute to the development of the Agency.

Please send us your applications by no later than 7 June 2019 at 16:00 (Greece local time).

Please note that the filling of this position is conditional on the formal approval by the European Parliament and the Council of the EU and the publication in the EU Official Journal of the Cybersecurity Act.

However, as part of this process a reserve list will be formed that will also be used to identify candidates for any positions that may arise from the existing pool of positions.

1. The Agency

The Agency is a centre of expertise for cyber security in Europe.

Since it was set up in 2004 , ENISA has been actively contributing to a high level of network and information security (NIS) within the Union, to the development of a culture of NIS in society and in order to raise awareness of NIS, thus contributing to proper functioning of the internal market.

ENISA focuses on five main areas:

  • Collecting and analysing data on security incidents and emerging risks in Europe;
  • Assisting and advising the Commission and the Member States in their dialogue with industry to address security related problems and, when called upon, in the technical preparatory work for updating and developing Community legislation in the field of network and information security;
  • Promoting best practices, risk assessment and risk management, training and awareness raising actions;
  • Encouraging co-operation between different actors, developing and maintaining contact with institutions, the business community and consumer organisations, notably through public/private partnerships;
  • Tracking the development of standards for products and services in the field of network and information security and promoting their use

In addition, proposed in 2017 as part of a wide-ranging set of measures to deal with cyber-attacks and with a view to building strong cybersecurity in the EU, the draft Cybersecurity Act includes:

  • A permanent mandate for the EU Cybersecurity Agency, ENISA
  • A stronger basis for ENISA in the EU cybersecurity certification framework to assist Member States in effectively responding to cyber-attacks with a greater role in cooperation and coordination at Union level.

ENISA is located in Athens and in Heraklion, Crete, Greece.

The place of employment for the Lead Policy Officer-Cybersecurity Certification position is Athens.

ENISA’s staff are expected to be reasonably mobile in order to respond to the needs of the Member States on the basis of planned as well as ad hoc needs.

Further information about ENISA may be found on our website:

2. Job description

The Jobholder will be responsible for the following tasks:

  • Provide input into the design of cybersecurity certification schemes for specific products, services and processes.
  • Support the drafting of cybersecurity certification schemes on the basis of input provided by stakeholders in the private, and public sector organisations and the EU institutions.
  • Support the fostering of co-operation across various stakeholders involved in the cybersecurity certification framework, developing and maintaining contact with relevant private, and public sector organisations and the EU institutions.
  • Contribute to the design and implementation of an internal governance system including internal processes, procedures, systems (including information systems) and training to support the cybersecurity certification framework activities of the Agency. Identify suitable tools and practices to support the above.
  • Carry out analyses on the internal market impact of the cybersecurity certification framework.
  • Contribute to the support function of the Agency towards Member States and the European Commission within the European Cybersecurity Certification Group as well as the Industry Advisory Group.
  • Support the cooperation of the Agency with Standards Developing Organisations.
  • Contribute to the execution of the Union rolling plan on cybersecurity certification.
  • Co-ordinate tenders and supervise contracts related to the cybersecurity certification.
  • Assist the Agency in its dialogue with private, and public sector organisations and the EU institutions and other stakeholders as appropriate to address cybersecurity certification related challenges and, when called upon, in the framework of technical preparatory work to update and support proposals regarding European legislation in cybersecurity.
  • Promote and develop good practices, risk assessment, risk management and training actions.
  • Track the development of certification initiatives for products, services and processes in cybersecurity and promote their use.
  • Collaborate with peers and team members as appropriate.
  • Take on additional responsibilities as required in the interest of the service.

​3. Qualifications and experience required

3.1. Eligibility Criteria

  • A level of education which corresponds to completed university studies attested by a diploma when the normal period of university education is at least four years or more; OR
  • A level of education which corresponds to completed university studies attested by a diploma and appropriate professional experience of at least one year when the normal period of university education is at least three years;
  • In addition to the above, at least 9 years of proven full-time professional experience relevant to the duties concerned after the award of the university degree;
  • Thorough knowledge of one of the official languages of the European Union and a satisfactory knowledge of another official European language.

In addition, in order to be eligible a candidate must:

  • Be a national of one of the Member States of the European Union;
  • Be entitled to his/her full rights as a citizen ;
  • Have fulfilled any obligations imposed by the applicable laws concerning military service;
  • Be physically fit to perform the duties linked to the post.

3.2. Selection criteria

High Scoring Criteria (5 points per criterion)

  • University degree in a scientific/political science discipline.
  • Professional experience in analysing and drafting policy in the areas of cybersecurity certification and standardisation.
  • Proven experience in working in a comparable position in respect of tasks and level, with private and/or public stakeholders in the areas mentioned above (e.g. European Union Organisations, EU Agencies, Member States public authorities, European standardisation organisations or relevant private sector stakeholders).
  • Suitable professional skills certification issued by a reputable organisation or association, in areas related to the policy work of the Agency.
  • Excellent knowledge of Common Criteria based certification schemes.
  • Proven experience in engaging with policy makers and regulatory and standardisation bodies.
  • Strong priority setting and planning skills, orchestrating multiple activities at once to accomplish the objectives.
  • Excellent communication skills in English, both orally and in writing.
  • Experience working effectively in an international and multi-cultural environment.

Low Scoring Criteria (2 points per criterion) 

  • Good knowledge of the current regulatory and policy initiatives of the EU and/or EU Member States in the areas mentioned above.
  • Experience in project management proven by a suitable track record and/or a suitable evidence


All high scoring and low scoring criteria are evaluated in order to identify the candidates to be invited for an interview. The top candidates (number of the shortlisted candidates scoring above the threshold to be set by the selection board) will be invited for an interview and written test. Therefore, candidates are recommended to give evidence of their knowledge by specific examples and/or detailed professional experience in the application form in order to be evaluated in the best possible way. To that purpose candidates are requested to be as detailed and as clear as possible in the description of their professional experience and specific skills and competences.

4. Selection procedure

The selected candidate will be appointed to a position according to the needs of the Agency, on the basis of the reserve list of candidates, proposed by the Selection Board and established following an open selection process involving interviews and written tests.

More specifically, the Selection Board decides on those candidates who are admitted to the selection procedure in accordance with the requirements as specified in the vacancy notice. The applications of the candidates admitted to the selection procedure are reviewed and the Selection Board decides on those candidates who are invited to attend an interview and written test. The Selection Board adheres strictly to the conditions of admission laid down in the vacancy notice when deciding whether or not candidates are to be admitted. Candidates admitted to a previous selection procedure will not automatically be eligible. Should the Selection Board discover at any stage in the procedure that the candidate does not meet one or more of the general or special conditions for admission to the selection procedure or that the information on the application form does not correspond with the supporting documents, the candidate will be disqualified.

Shortlisted candidates will be asked to undergo a written test of which the candidates will be informed in advance. In addition, all shortlisted candidates might be requested to complete an online personality test. Shortlisted candidates will be required to submit electronically relevant supporting documentation demonstrating their educational qualifications and work experience. It is envisaged that the interviews and written test will take place in July 2019. Shortlisted candidates may also be required to provide work-related references upon request of the Agency. The activity of the Selection Board ends with the drawing of a reserve list of suitable applicants to occupy the position advertised. Candidates should note that inclusion on the reserve list does not guarantee recruitment.

The reserve list will be valid until 31/12/2020 and may be extended by decision of the Executive Director for a further 12 months. This list may be used to recruit Staff for other positions in the areas referred to in this vacancy.

Candidates invited to an interview will be informed by e-mail whether or not he/she has been placed on the reserve list. Candidates on the reserve list will be asked to fill a specific form informing the Appointing Authority of any actual or potential conflict of interest . If a letter of intention is issued, the candidate must undergo a compulsory medical examination to establish that he/she meets the standard of physical fitness necessary to perform the duties involved and the candidate must provide original or certified copies of all relevant documents.

In line with the European Ombudsman’s recommendation, ENISA publishes the names of the Selection Board on its website once established. It is strictly forbidden for the candidates to make any contact with the Selection Board, either directly or indirectly. Any infringement to this rule will disqualify the candidate from the competition.

All enquiries or requests for information in relation to the competition, including details about candidates’ results9 should be addressed to the following email address

5. Conditions of Employment

The successful candidate will be recruited as a Temporary Agent, pursuant to Article 2(f) of the Conditions of Employment of Other Servants of the European Union (CEOS), for a period of five (5) years or until the end of the Agency’s mandate whichever is the earliest . After the five (5) years, the contract may be renewed for an indefinite period.

The appointment will be in grade AD 8. The step will be determined in accordance with the number of years of experience of the successful candidate.

Successful candidates, who are recruited, shall undergo an initial probation period of 9 months. For reasons related to the Agency's operational requirements, the successful candidate will be required to be available at the shortest possible notice.

The remuneration of staff members consists of a basic salary and where applicable allowances.

The indicative basic monthly salary for grade AD 8, step 1, is 6,934.02 EUR and 7,225.39 EUR for step 2. This salary will be weighted by the corrective coefficient applicable to the hosting country of the agency. The current corrective coefficient is 81.8 %, which will be reviewed yearly with retroactive effect from 1 July.

The staff member depending on its personal situation may be entitled to various allowances, in particular to an expatriation (16 % of basic gross salary) or to a foreign residence allowance (4 % of basic gross salary) and to family allowances (depending on personal situation) such as household allowance, dependent child allowance, pre-school allowance. In addition, the successful candidate might be entitled to temporary daily allowance, installation allowance etc.

Other benefits include:

  • Special ID card, issued by the Greek Ministry of Foreign Affairs;
  • Special car license plates (applicable to certain type of contracts);
  • Education allowance;
  • Home visit allowance;
  • Additional financial support for the education of children “subject to budget availability and conditions”;
  • VAT exemption allowance on certain goods for a period of 2 years from the starting date of employment;
  • Importation/purchase of 1 or more vehicles depending on the circumstances without taxes of VAT (“special conditions apply”);
  • Staff is entitled to annual leave of two working days per each complete calendar month of service plus additional days for the grade, age, home leaves for expatriates and an average of 19 public holidays per year;
  • In addition, staff may be granted special leave for certain circumstances such as marriage, birth, adoption of a child, moving, elections, serious sickness of spouse, etc.;
  • ENISA staff members benefit of health insurance 24/7 and worldwide by the EU Joint Insurance Scheme (JSIS);
  • Statutory staff who have completed at least 10 years of service or reached pensionable age, are entitled to a pension under the pension scheme of the European Union institutions (PSEUI).
  • Where it is considered in the interest of the service, statutory staff may avail of the ENISA teleworking policy and flexible working time arrangements.
  • With regard to professional development opportunity to its staff, ENISA provides a wide range of learning and development opportunities.

6. Community Tax

The salaries of staff members are subject to a Community tax deducted at source. They are exempt from national tax on salary and are members of the Community social security and pension schemes.

For additional information about salaries, deductions and allowances please consult the Staff Regulations of Officials and the Conditions of Employment of Other Servants of the European Union.

7. Data protection

All personal data shall be processed in accordance with Regulation (EU) No 2018/1725 of the European Parliament and of the Council (OJ L 295, 21.11.2018, p. 39–98) on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data. ENISA is supervised by EDPS. For any further enquiries you may contact the Data Protection Officer at:

Candidates are invited to consult the privacy statement which explains how ENISA processes personal data in relation to recruitment selections.

8. Equal opportunity

ENISA is an equal opportunities employer and accepts applications without distinction on the grounds of sex, racial or ethnic origin, religion or belief, age or sexual orientation, marital status or family situation. Applications from women and disabled candidates are encouraged. The staff is recruited on the broadest possible geographical basis from among nationals of all Member States of the European Union.

9. Complaints

If a candidate considers that he or she has been adversely affected by a particular decision, he or she can lodge a complaint under Article 90(2) of the Staff Regulations of Officials and Conditions of Employment of Other Servants of the European Union, within 3 months from the date of notification to the following address:

Executive Director


1 Vasilissis Sofias

Marousi 151 24

Attica, Greece

Should the complaint be rejected, pursuant to Article 270 of the Treaty of the Functioning of the European Union and Article 91 of the Staff Regulations of Officials and Conditions of Employment of Other Servants of the European Union, a candidate may request judicial review of the act. The appeal must be lodged within 3 months from the date of notification, to the following address:


The General Court

Rue du Fort Niedergrünewald

L-2925 Luxembourg


Please note that the Appointing Authority does not have the power to amend the decisions of a Selection Board. The General Court has consistently held that the wide discretion enjoyed by Selection Boards is not subject to review by The General Court unless rules which govern the proceedings of Selection Boards have been infringed. For details of how to submit an appeal, please consult the website of the Court of Justice of the European Union.

It is also possible to complain to the European Ombudsman pursuant to Article 228 of the Treaty on the Functioning of the European Union as well as the Statute of the Ombudsman and the implementing Provisions adopted by the Ombudsman under Article 14 of the Statute.

European Ombudsman

1 Avenue du President Robert Schuman

CS 30403

67001 Strasbourg Cedex


Please note that complaints made to the Ombudsman have no suspensive effect on the period laid down in Articles 90 (2) and 91 of the Staff Regulations for lodging complaints or for submitting appeals to the General Court pursuant to Article 270 of the Treaty of the Functioning of the European Union. Please note also that under Article 2(4) of the General conditions governing the performance of the Ombudsman’s duties, any complaint lodged with the Ombudsman must be preceded by the appropriate administrative approaches to the institutions and bodies concerned.

10. Submission of applications

For an application to be valid candidates shall:

  • Use the official application form published with this vacancy. Applicants may use any of the official languages of the European Union to complete the form, however it is highly recommended to submit the applications in English, which is the working language of ENISA. The format of the PDF application form must not be changed.
  • Send their application within the set deadline by e-mail to:
  • Indicate in the subject of the e-mail: FAMILY NAME-FIRST NAME-2019-07

Incomplete applications will be disqualified and treated as non-eligible. Candidates should submit a separate application for each vacancy they want to apply for.

At this stage of the selection procedure candidates are not required to send any additional supporting documents with the application (i.e.: copies of your ID-card, educational certificates, evidence of previous professional experience etc.). Candidates are reminded not to wait until the final days before the closing date for applications.

Please note that the selection process may take several months. Status of the selection procedures can be consulted here.

The closing date and time for the submission of applications is: 7 th June 2019 (16h00 Greece local time).

Before you apply, read the latest news about EU policies on EURACTIV.COM.

Employers want to know how you found their job advert so please state that you found this position advertised on the EURACTIV JobSite.

The JobSite can give you more...
Get a bi-weekly newsletter featuring the latest jobs published online here.
Become the JobSite's fan on Facebook.
Follow us on Twitter and receive the latest news and job of the day.


Disclaimer: EURACTIV is not responsible for the content of the job vacancies published. Reproduction or redistribution of the above text, in whole, part or in any form, requires the prior consent of the original source. Terms and Conditions apply.