MISP Senior Data Engineer
C005317, MISP Senior Data Engineer
Location: Mons, Belgium
Work arrangement: Full-time on-site, with limited remote work subject to approval
Security clearance: NATO Secret
Primary duties
- Design, build, and maintain pipelines that ingest cyber-threat information from multiple sources.
- Develop and maintain Python scripts integrating MISP with NATO systems such as SIEM and IDS platforms.
- Define, document, and implement information-dissemination rules.
- Support threat-information process management.
- Normalize heterogeneous threat feeds into a consistent data schema.
- Maintain data quality through deduplication, confidence scoring, indicator lifecycle management, provenance tracking, and filtering of low-quality sources.
- Integrate established cyber-threat information standards.
- Document commonly used MISP taxonomies, galaxies, and data-entry best practices.
- Serve as a subject-matter expert for NATO MISP communities.
- Advise users on data curation and dissemination options, including their benefits and limitations.
- Support users of NATO-managed MISP instances and provide regular feedback, including daily feedback during exercises.
- Lead teams of MISP Operators during exercises, overseeing information flow, quality control, and user management.
- Plan, prepare, and deliver online MISP training.
- Help prepare training packages and validate that training objectives have been achieved.
Mandatory experience and skills
- At least 10 years of practical experience designing, building, and managing data pipelines involving:
- Data transformation
- Data models and schemas
- Metadata
- Workload management
- Experience supporting, leading, or managing data-focused operations and projects.
- Experience applying data-engineering tools to data science, analytics, and visualization.
- Strong Python scripting capability.
- Good understanding of cybersecurity principles, technologies, concepts, and best practices.
- Ability to work independently and collaboratively.
- Excellent organizational, communication, and writing skills.
- English proficiency at NATO STANAG 6001 Level 3 or higher.
Education requirement
Either:
- A bachelor’s degree from a nationally recognized university in a related discipline, plus at least three years of relevant post-degree experience; or
- In exceptional cases, at least 10 years of extensive and progressively responsible experience related to the Statement of Work, demonstrating abilities of particular interest to NCIA.
Desirable experience
- MISP core format and STIX
- Cyber-threat intelligence analysis
- Splunk
- Incident response
- Handling cyber-threat information
- Open-source communities
- Multinational cyber exercises, such as Locked Shields, Crossed Swords, or Cyber Coalition
- Administration of a MISP Threat Sharing platform
- Developing Python or PHP code for MISP
Working conditions
- Normal office environment using NCIA-provided equipment for restricted information.
- The contractor must provide suitable equipment for public and unclassified work performed remotely, including support for Microsoft-based video collaboration.
- Remote work from another NATO nation may be allowed for up to 20% of total working time, subject to prior approval.
- Home working within the duty location may be permitted under NCIA teleworking policy and with Resource Manager coordination.
- Travel to other NCIA locations may be required, normally for no more than two days per trip and no more than twice per month.
- Authorized travel is reimbursed under NATO regulations and must begin from the designated duty station.