Every threat feed is a different shape. Somebody has to make them one thing, and make it trustworthy.
You would engineer the data side of a defence alliance's threat-intelligence sharing platform in Mons, Belgium — the pipelines feeding it, the schema underneath it, and the quality rules that decide what is worth keeping.
What you would be doing
Designing, building and maintaining the pipelines that ingest threat information from a wide range of sources
Developing and maintaining Python scripts that automate the platform and integrate it with the systems around it, including security monitoring and detection
Defining, documenting and implementing the rules by which information is disseminated
Supporting the work around threat-information process management
Normalising heterogeneous feed structures into one consistent schema
Enforcing data quality — deduplication, confidence scoring, indicator lifecycle, provenance, and tracking and filtering the low-quality sources
Contributing to and integrating existing cyber threat information standards
Creating and maintaining the documentation on the taxonomies and galaxies people actually use
Writing and keeping current the best-practice guidance for data entry
Being the expert the internal communities come to on curation and dissemination options — what each one buys them and what it costs
Supporting the user community — regular feedback normally, daily feedback during exercises
Leading a team of platform operators during exercises, covering information flow, quality control and user management
Planning, preparing and delivering online training, and helping build the individual training packages that prove the objectives were met
What you would bring
At least ten years of practical experience across the areas below
Designing, building and managing data pipelines — transformation, data models, schemas, metadata and workload management
Supporting, leading or managing data-focused operations and projects, using data engineering tooling behind data science, analytics and visualisation
Python scripting
A good grasp of security principles, practice, concepts and technology
The ability to work alone and in a team
Excellent organisation, communication and writing
Professional English
A bachelor's degree in a related discipline with three years of related experience — or, exceptionally, ten years of progressive expertise in this kind of work
Nice to have
The platform's own core format, and STIX
Work as a cyber threat intelligence analyst, or as an incident responder
Splunk
Handling cyber threat information at scale
Work with open-source communities, and multinational cyber exercises
Administering a threat-sharing platform, or writing code for one in Python or PHP
Why this one is worth a look
Data engineering where the data is adversarial and the quality rules genuinely matter — not another warehouse.
Maak een vacature-alert aan voor deze zoekopdracht
Senior Data Engineer (Cyber Threat Feeds and Taxonomies) for NATO with security clearance • Mons, Wallonia, Belgium