Policy Officer
MAKE A DIFFERENCE - JOIN THE EUROPEAN COMMISSION Do you want to help shape the future of the European Union? Make the planet greener, promote a fair...
5 positions at EU institutions
Cybersecurity roles inside the European Union institutions cover everything from defending the EU's classified communications networks to drafting the implementing acts of the NIS2 Directive, certifying products under the Cybersecurity Act schemes, running the EU's joint cyber-incident response capability under the Cyber Solidarity Act, and conducting threat intelligence for Europol's European Cybercrime Centre (EC3). If you're a SOC analyst, a red-teamer, a cryptographer, a cybersecurity policy specialist, a CSIRT engineer, a cyber threat intelligence analyst, or a cybersecurity auditor, the EU institutions have invested heavily in their cyber workforce over the past five years and now represent a serious, fast-growing employer with deep technical work and direct exposure to European cybersecurity regulation.
5 positions found
MAKE A DIFFERENCE - JOIN THE EUROPEAN COMMISSION Do you want to help shape the future of the European Union? Make the planet greener, promote a fair...
MAKE A DIFFERENCE - JOIN THE EUROPEAN COMMISSION Do you want to help shape the future of the European Union? Make the planet greener, promote a fair...
* [Skip to content](https://curia.europa.eu/site/jcms/p1_1000084651/en/cybersecurity-expert#a11y-global-content) [](https://curia.europa.eu/site/)...
Reserve lists [Reserve Lists](https://cybersecurity-centre.europa.eu/document/download/90f27907-8361-466d-a20e-a7d82cf802c7_en?filename=Reserve%20Lis...
This site uses cookies. Visit our [cookies policy page](https://www.enisa.europa.eu/about-enisa/cookies) or click the link in any footer for more info...
The largest hiring categories include cybersecurity policy officers at ENISA in Athens and at DG CNECT at the Commission (drafting and implementing NIS2, the Cyber Resilience Act, the Cyber Solidarity Act, the EU Cybersecurity Certification framework), cybersecurity analysts and engineers at the Computer Emergency Response Team for the EU Institutions, Bodies and Agencies (CERT-EU) defending the EU institutions' networks, cyber operators at Europol's EC3 investigating cybercrime, threat-intelligence analysts at the INTCEN Hybrid Fusion Cell, security architects and engineers at the Council's General Secretariat protecting classified communications, IT-security specialists at EU-LISA (protecting large-scale border-management systems), EUSPA (protecting Galileo and EGNOS), and the European Central Bank (TIBER-EU framework). Specialised tracks include cryptography engineers, IAM specialists, application-security testers, cloud-security architects, and certification specialists working on the EU Cybersecurity Certification Schemes (EUCC, EUCS, EU5G).
ENISA in Athens is the EU agency for cybersecurity, with around 200 staff covering policy, certification, capacity building, operational cooperation, and the Cybersecurity Hub. CERT-EU defends around 80 EU institutions, bodies, and agencies, with a team of around 90 cybersecurity specialists. DG CNECT at the Commission drafts cybersecurity policy and runs the cybersecurity certification framework. DG HOME handles cybercrime policy. Europol in The Hague runs the European Cybercrime Centre (EC3) and the Joint Cybercrime Action Taskforce (J-CAT). EU-LISA in Tallinn maintains substantial cybersecurity teams for SIS, VIS, EURODAC, ETIAS, and EES. EUSPA protects Galileo and EGNOS. The ECB runs TIBER-EU red-teaming, EBA cybersecurity supervisory work, and the Eurosystem Cyber Resilience Strategy. The European Defence Agency hires cyber-defence specialists for member-state cooperation projects.
Cybersecurity salaries follow standard EU staff scales. AD5 entry-level cybersecurity policy officers earn around €5,000 to 5,700 per month gross at step 1. AD7 senior cybersecurity specialists earn €7,400 to 8,500. AD9 senior security architects and senior threat-intelligence analysts earn €9,500 to 10,500. AD12 heads of unit at ENISA, CERT-EU, or DG CNECT reach €13,000 to 14,500. Function Group IV (FG IV) Contract Agents working as SOC analysts, security engineers, or pen-testers typically earn €4,200 to 6,800/month, which is meaningfully below market rates for equivalent private-sector cyber roles in Western Europe. The European Central Bank operates a separate scale typically 15 to 25% above EU institutional pay for comparable seniority, making ECB cyber roles among the best-paid in the EU institutions. Standard EU benefits (expatriation allowance (16%), household and education allowances, EU community tax) substantially increase effective net pay. Correction coefficients adjust pay at non-Brussels duty stations: Athens (ENISA) applies a lower coefficient, Tallinn (EU-LISA) also lower, while Frankfurt (ECB) is close to 100. Security clearance allowances also apply for cleared roles.
Most cybersecurity technical positions require a master's in computer science, cybersecurity, mathematics, or a related quantitative field, plus 4 to 6 years of operational cybersecurity experience (SOC, incident response, red team, threat intelligence, or security architecture). Professional certifications carry significant weight: CISSP, CISM, OSCP, GIAC certifications (GCIH, GCFA, GPEN, GSE), CEH, CCSP. For policy roles, a master's in law, public policy, or computer science plus cybersecurity-policy experience is the typical profile. For certification roles, ISO 27001 lead auditor, Common Criteria evaluator experience, and familiarity with the EU Cybersecurity Certification Schemes are highly valued. Security clearance up to EU SECRET or higher is required for most CERT-EU, Council Security Office, and INTCEN roles, and is increasingly required at EU-LISA, EUSPA, and Europol. Working English is essential; French is helpful for policy roles; a third EU language is required for permanent statutory posts. Operational hands-on technical skills (Linux, scripting, network forensics, malware analysis, cloud security) remain the strongest differentiator for technical roles.
EU cybersecurity is shaped by an unusually dense legal framework. NIS2 (Directive (EU) 2022/2555) sets cybersecurity obligations on operators of essential and important services across 18 sectors. The Cyber Resilience Act sets cybersecurity obligations on manufacturers of products with digital elements. The Cybersecurity Act establishes ENISA's permanent mandate and the EU Cybersecurity Certification framework. The Cyber Solidarity Act creates the European Cybersecurity Shield (cross-border SOCs network) and the Cybersecurity Reserve. DORA (Digital Operational Resilience Act) sets cybersecurity obligations on the financial sector. eIDAS2 governs trust services and the European Digital Identity Wallet. Working in EU cybersecurity means engaging continuously with these frameworks plus their national transpositions and the work of national CSIRTs and competent authorities. Operational cooperation runs through the CSIRTs Network (national CSIRTs plus CERT-EU and ENISA), EU-CyCLONe (large-scale cyber crisis coordination), and EC3 for cybercrime. The institutional environment is process-heavy and multilingual; technical excellence is essential but must be paired with the ability to translate operational findings into regulatory language. Career mobility between ENISA, CERT-EU, DG CNECT, Europol EC3, EU-LISA, and the ECB is increasingly common.
Technical positions typically require a master's in computer science, cybersecurity, or a related quantitative field plus 4 to 6 years of operational experience (SOC, incident response, red team, security architecture). Certifications like CISSP, CISM, OSCP, and GIAC carry significant weight. Policy roles need a master's in law, public policy, or computer science plus cybersecurity-policy experience. Security clearance up to EU SECRET is often required. Working English is essential; a third EU language is required for permanent posts.
ENISA in Athens is the EU agency for cybersecurity with around 200 staff. CERT-EU defends around 80 EU institutions and bodies. DG CNECT and DG HOME at the Commission handle cybersecurity policy. Europol's EC3 in The Hague investigates cybercrime. EU-LISA in Tallinn protects large border systems. EUSPA protects Galileo. The ECB runs TIBER-EU and supervisory cyber work. The EDA hires for cyber defence.
AD5 around €5,000 to 5,700/month gross, AD7 €7,400 to 8,500, AD9 €9,500 to 10,500, AD12 €13,000 to 14,500. FG IV contract agents earn €4,200 to 6,800/month, below private-sector cyber rates but with substantial allowances, EU community tax, and excellent pension and family benefits. The ECB pays 15 to 25% above standard EU scales.
ENISA is in Athens. CERT-EU and DG CNECT cybersecurity teams are in Brussels and Luxembourg. Europol's EC3 is in The Hague. EU-LISA cybersecurity is in Tallinn. EUSPA cybersecurity is in Prague. The ECB is in Frankfurt. The EDA is in Brussels. Most positions require relocation, with 2 to 3 days of telework per week typical after onboarding.
Permanent statutory positions and most Temporary/Contract Agent posts require EU citizenship. Cleared cybersecurity roles always require EU citizenship plus security clearance. The ECB regularly hires non-EU citizens for cybersecurity positions. Some specialised technical roles can be filled by non-EU contractors. The most realistic non-citizen paths into EU cybersecurity work involve ECB recruitment, contractor work supporting the institutions, or pursuing EU citizenship through residency.