Location: Mons, BE (Full time on-site; remote work allowed up to 20% from another NATO nation subject to approval, with travel up to twice per month for department meetings)
Duties & Roles:
- System Administration: Proactively manage and maintain multiple Linux servers running the MISP (Malware Information Sharing Platform & Threat Sharing) software, ensuring confidentiality, integrity, and availability. Stand up and configure dedicated MISP instances for NATO exercises, update platforms to current releases, extend monitoring, and maintain Ansible playbooks for automated deployment.
- Architecture & Community Advisory: Act as the subject matter expert for NATO MISP communities, providing architectural guidance on deployment benefits and limitations. Maintain and improve technical platform documentation.
- Content Management & Automation: Develop and maintain Python scripts to automate workflows and integrate MISP with other subsystems (such as SIEM and IDS). Establish content quality rules to support quality management initiatives.
- User, Exercise & Community Support: Provide technical support and regular feedback to user communities (daily during exercises). Lead teams of MISP Operators during cyber exercises to oversee information flow, user management, and quality control. Streamline and automate user lifecycle processes using ITSM and IDAM tools (e.g., Cerebrate or Keycloak).
- Training & Engineering Coordination: Prepare and deliver online MISP training courses and training validation packages. Coordinate the technical activities of a small group of engineers.
Skill, Knowledge & Experience:
- Professional Experience: At least 10 years of practical experience in architecting deployment solutions, coordinating engineering teams, and administering LAMP servers (Linux, Apache, MySQL/MariaDB, PHP).
- Development & Scripting: 10+ years of experience in configuring web applications, Python scripting, and MVC software development/code review in PHP and SQL.
- Cybersecurity Acumen: Deep understanding of cybersecurity principles, best practices, and threat vectors targeting web-based platforms.
- Education: Bachelor’s degree from a recognized university in a related discipline with 3 years of post-related experience; alternatively, at least 10 years of extensive and progressive relevant expertise can compensate for the lack of a degree.
- Languages: English proficiency meeting or exceeding NATO STANAG 6001 Level 3 (“Professional Proficiency”).
- Desirable Assets: Prior experience administering a MISP Threat Sharing platform, developing code (Python/PHP/CakePHP) for MISP, and working with RedHat environments (RHCSA certification or similar). Experience engaging with open-source communities and participating in multinational cyber exercises (e.g., Locked Shields, Crossed Swords, Cyber Coalition).
- Clearance: A valid NATO Secret security clearance is mandatory.
