MISP Platform Engineer (System Administration, Ansible and Automation) for NATO with security clearance
Run and grow the threat-intelligence sharing platform a defence alliance depends on — servers, automation, integrations, and the community that uses it. Mons, hybrid.
Threat intelligence is only as good as the platform carrying it, and this one carries a lot.
You would own the engineering behind a defence alliance's core instances of an open-source threat-intelligence sharing platform in Mons, Belgium — keeping them running, extending them, and helping the people who live in them day to day. Your immediate colleagues would be the service delivery and engineering managers, system administrators, developers, testers and data engineers, plus the open-source community around the product.
What you would be doing
- Proactively managing and maintaining the servers behind the platform, with the confidentiality, integrity and availability the information demands
- Standing up, configuring and running dedicated instances in support of exercises
- Keeping the software current and supporting the test and validation work behind change management
- Configuring and extending the monitoring around every installation
- Maintaining the Ansible playbooks that build and configure it all
- Writing and improving the documentation, and keeping it worth reading
- Being the expert the internal communities come to on deployment architectures — what each one buys you and what it costs
- Developing and maintaining Python scripts that automate the platform and integrate it with the systems around it, including security monitoring and detection
- Supporting quality management by creating and maintaining content quality rules
- Supporting the user community — regular feedback normally, daily feedback during exercises
- Leading a team of platform operators during exercises, where the need and your own strengths suit it, covering information flow, quality control and user management
- Streamlining and automating user management across service management and identity tooling such as Cerebrate or Keycloak
- Planning, preparing and delivering online training, and helping build the individual training packages that prove the objectives were met
- Coordinating the work of a small group of engineers
What you would bring
- At least ten years of practical experience across the areas below
- Architecting deployment solutions
- Coordinating the work of a small engineering group
- System administration on LAMP servers — Linux, Apache, MySQL or MariaDB, PHP
- Configuring web applications, and scripting in Python
- Building and reviewing MVC web applications, mainly in PHP with SQL behind them
- A good grasp of security principles, practice, concepts and technology
- The ability to work alone and in a team, including monitoring and supporting the people around you
- Excellent organisation, communication and analysis
- A real technical understanding of the threats web-based products face
- Professional English
- A bachelor's degree in a related discipline with three years of related experience — or, exceptionally, ten years of progressive expertise in this kind of work
Nice to have
- Administering a threat-sharing platform in production
- Writing code for one, in Python or PHP
- Red Hat experience, and an RHCSA or similar certification
- Work with open-source communities
- Multinational cyber exercises
- CakePHP
Why this one is worth a look
It is a rare mix: deep system engineering, open-source community work, and a platform whose output people actually act on.
- Department
- Security
- Locations
- Mons
- Remote status
- Hybrid
Mons
About WLG
Work Life Group Sp. z o.o., agencja zatrudnienia (employment agency) KRAZ no. 19578. NIP 7010247728. ul. Nowogrodzka 50/54 lok. 515, 00-695 Warszawa, Poland.