MISP Senior Data Engineer

Mons, BE Deadline: 16-09-2026 Posted: 03-09-2026 #17482

C005317, MISP Senior Data Engineer

 

Location: Mons, Belgium
Work arrangement: Full-time on-site, with limited remote work subject to approval
Security clearance: NATO Secret

Primary duties

  • Design, build, and maintain pipelines that ingest cyber-threat information from multiple sources.
  • Develop and maintain Python scripts integrating MISP with NATO systems such as SIEM and IDS platforms.
  • Define, document, and implement information-dissemination rules.
  • Support threat-information process management.
  • Normalize heterogeneous threat feeds into a consistent data schema.
  • Maintain data quality through deduplication, confidence scoring, indicator lifecycle management, provenance tracking, and filtering of low-quality sources.
  • Integrate established cyber-threat information standards.
  • Document commonly used MISP taxonomies, galaxies, and data-entry best practices.
  • Serve as a subject-matter expert for NATO MISP communities.
  • Advise users on data curation and dissemination options, including their benefits and limitations.
  • Support users of NATO-managed MISP instances and provide regular feedback, including daily feedback during exercises.
  • Lead teams of MISP Operators during exercises, overseeing information flow, quality control, and user management.
  • Plan, prepare, and deliver online MISP training.
  • Help prepare training packages and validate that training objectives have been achieved.

Mandatory experience and skills

  • At least 10 years of practical experience designing, building, and managing data pipelines involving:
    • Data transformation
    • Data models and schemas
    • Metadata
    • Workload management
  • Experience supporting, leading, or managing data-focused operations and projects.
  • Experience applying data-engineering tools to data science, analytics, and visualization.
  • Strong Python scripting capability.
  • Good understanding of cybersecurity principles, technologies, concepts, and best practices.
  • Ability to work independently and collaboratively.
  • Excellent organizational, communication, and writing skills.
  • English proficiency at NATO STANAG 6001 Level 3 or higher.

Education requirement

Either:

  • A bachelor’s degree from a nationally recognized university in a related discipline, plus at least three years of relevant post-degree experience; or
  • In exceptional cases, at least 10 years of extensive and progressively responsible experience related to the Statement of Work, demonstrating abilities of particular interest to NCIA.

Desirable experience

  • MISP core format and STIX
  • Cyber-threat intelligence analysis
  • Splunk
  • Incident response
  • Handling cyber-threat information
  • Open-source communities
  • Multinational cyber exercises, such as Locked Shields, Crossed Swords, or Cyber Coalition
  • Administration of a MISP Threat Sharing platform
  • Developing Python or PHP code for MISP

Working conditions

  • Normal office environment using NCIA-provided equipment for restricted information.
  • The contractor must provide suitable equipment for public and unclassified work performed remotely, including support for Microsoft-based video collaboration.
  • Remote work from another NATO nation may be allowed for up to 20% of total working time, subject to prior approval.
  • Home working within the duty location may be permitted under NCIA teleworking policy and with Resource Manager coordination.
  • Travel to other NCIA locations may be required, normally for no more than two days per trip and no more than twice per month.
  • Authorized travel is reimbursed under NATO regulations and must begin from the designated duty station.

Apply for this position

Back