Senior Data Engineer (Cyber Threat Feeds and Taxonomies) for NATO with security clearance
WLG Mons, Wallonia, Belgium
Financial Services · 2-10 employees
About the role
You will design, build, and maintain data pipelines to ingest and normalize heterogeneous cyber threat information into a consistent schema. Additionally, you will lead platform operations during exercises and provide expert guidance on threat curation and dissemination.
What they look for
Requirements
The role requires at least ten years of practical experience in data engineering, including pipeline development, Python scripting, and data modeling. Candidates must possess a strong grasp of security principles and the ability to work effectively within a defense alliance environment.
Full description
Every threat feed is a different shape. Somebody has to make them onething, and make it trustworthy.
You would engineer the data side of a defence alliance's threat-intelligence sharing platform inMons, Belgium — the pipelines feeding it, the schema underneath it, and the quality rules thatdecide what is worth keeping.
What you would be doing
- Designing, building and maintaining the pipelines that ingest threat information from a widerange of sources
- Developing and maintaining Python scripts that automate the platform and integrate it with thesystems around it, including security monitoring and detection
- Defining, documenting and implementing the rules by which information is disseminated
- Supporting the work around threat-information process management
- Normalising heterogeneous feed structures into one consistent schema
- Enforcing data quality — deduplication, confidence scoring, indicator lifecycle, provenance,and tracking and filtering the low-quality sources
- Contributing to and integrating existing cyber threat information standards
- Creating and maintaining the documentation on the taxonomies and galaxies people actuallyuse
- Writing and keeping current the best-practice guidance for data entry
- Being the expert the internal communities come to on curation and dissemination options — whateach one buys them and what it costs
- Supporting the user community — regular feedback normally, daily feedback during exercises
- Leading a team of platform operators during exercises, covering information flow, qualitycontrol and user management
- Planning, preparing and delivering online training, and helping build the individual trainingpackages that prove the objectives were met
What you would bring
- At least ten years of practical experience across the areas below
- Designing, building and managing data pipelines — transformation, data models, schemas,metadata and workload management
- Supporting, leading or managing data-focused operations and projects, using data engineeringtooling behind data science, analytics and visualisation
- Python scripting
- A good grasp of security principles, practice, concepts and technology
- The ability to work alone and in a team
- Excellent organisation, communication and writing
- Professional English
- A bachelor's degree in a related discipline with three years of related experience — or,exceptionally, ten years of progressive expertise in this kind of work
Nice to have
- The platform's own core format, and STIX
- Work as a cyber threat intelligence analyst, or as an incident responder
- Splunk
- Handling cyber threat information at scale
- Work with open-source communities, and multinational cyber exercises
- Administering a threat-sharing platform, or writing code for one in Python or PHP
Why this one is worth a look
Data engineering where the data is adversarial and the quality rules genuinely matter — notanother warehouse.