TLDR; the NTR was incorrect, and all starting security members have an NDA that just applies to anything they're later informed on.
For the sake of gameplay and being able to address threats promptly, all STARTING security officers are assumed to, like starting Command, be under an NDA. (Security members who join later will need to be given an NDA.)
SEC's NDA does not require them to be given another one to sign even when told about threats in the command guidebook (changeling, heretic, cult, etc.). It is just assumed due to their current NDA that anything the HOS or other command gives them information-wise is protected under that NDA.
So, for example, if SEC is briefed on changelings, they do not need an NDA to sign. NTR should not be forcing this as well, as it is already assumed you are under NDA.