Senior AI Engineer – Cybersecurity

Spektrum

Henegouwen

Hybride

EUR 90 000 - 130 000

Plein temps

Il y a 2 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature complète en une minute — CV personnalisé et lettre de motivation, prêts à envoyer.

Passez les filtres ATS

Avantages offerts par ce poste

Hybrid work policy

Résumé du poste

Spektrum in Belgium is seeking a seasoned on-prem AI security engineer to support the NATO NCIA/NCSC missions. You will harden the AI server, integrate enterprise authentication, design RBAC with least privilege, and build a robust Retrieval-Augmented Generation pipeline with secure data governance.

The role requires 3+ years Linux administration, 1+ years AI/ML platforms on-prem, and experience with security logging, Confluence/SOPs, and cross-domain collaboration.

Qualifications

  • Demonstrable 3+ years experience as a Red Hat Linux system administrator / platform engineer operating on-prem environments (servers, storage, networking, hardening, patching, backup/restore).
  • Demonstrable 1+ years experience building and operating AI/ML platforms on-prem (GPU servers, CUDA stack, containers, model serving).
  • Demonstrable 2+ years experience integrating enterprise authentication and authorization (AD/LDAP/SAML/OIDC), including RBAC and least- privilege design.
  • Demonstrable experience delivering AI-enabled cyber security use cases in at least two of the following domains: SOC, Threat Hunting, Malware Analysis.
  • Demonstrable experience implementing Retrieval-Augmented Generation (RAG) in production-like environments, including grounding/citations and evaluation methods.

Responsabilités

  • Design and implement a secure on-prem AI server capability for cyber security operations (SOC, DFIR, Threat Hunting, IR).
  • Perform system hardening, patching, and authentication integration (IdP/LDAP/AD).
  • Define RBAC roles with least privilege and manage secrets securely.
  • Build and optimize a multi-model, multi-user RAG pipeline and integrated data sources (SIEM, EDR, ticketing, knowledge bases).
  • Maintain operational docs in Confluence and facilitate workshops with SOC/DFIR teams.

Connaissances

System administration
AI/ML platforms on-prem
RBAC and least privilege
Security logging and auditability
Cross-domain collaboration

Formation

CISSP / CISM / CCSP or equivalent
RHCSA / RHCE or equivalent

Outils

Docker/Podman
CUDA stack
LLM runtimes (vLLM/TGI/llama.cpp)
Confluence documentation

Description du poste

Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.

Who we are supporting

The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.

The NCIA provides a wide range of services, including:

  • Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.
  • Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.
  • Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
  • Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.
  • Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers.

Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities.

The program
Assistance and Advisory Service (AAS)

The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.

To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.

Role ID – 2026-0137
Role Background

The NATO Cyber Security Centre (NCSC) is a team of over 200 members working to monitor and protect NATO networks. In the NCSC’s role to deliver robust security services to the NATO Enterprise and NATO Allied Operations and Missions (AOM), the centre executes a portfolio of programmes and projects around 219 MEUR euros per year, in order to uplift and enhance critical cyber security services.

The Portfolio ranges from Programme of Work (POW) activities funded via the NATOMilitary Budget (MB) to Critical / Urgent Requirements (CURs/URs) and NATO Security Investment Programme (NSIP) projects funded via the Investment Budget(IB). In some edge cases, projects are also funded via the Civilian Budget (CB). Projects can span multiple years and are governed by various frameworks, including the Common Funded Capability Development Governance Framework (CFCDGM).

In order to execute this work, the NCI Agency requires support with the work undertaken by the NATO Cyber Security Centre (NCSC) in the area of Communications and Information System (CIS) security, cyber defence and cyberspace operations. This Statement of Work (SoW) specifies the required skillset and experience.

Objectives

This Statement of Work (SoW) outlines the services to be provided by the Supplier to enable and operate an on-premise AI server capability supporting cyber security services, including SOC, Digital Forensics, Malware Analysis, Threat Hunting and Incident Response.

The work focuses on:

  • Implementing and optimizing AI use cases aligned with cyber security operations,
  • Proposing and testing new models and approaches
  • Designing and implementing a robust Retrieval-Augmented Generation (RAG) pipeline,
  • implementing authentication and limitation of rights (role-based access, least privilege), and performing a risk analysis on Confidentiality, Integrity and Availability (CIA) for the data, toolset and models used.

They shall integrate with existing operational processes and documentation (e.g., existing SOPs/SOIs in Confluence, existing access management processes, logging/monitoring practices) and shall prioritise updating/aligning existing documentation rather than creating parallel artefacts

Capture the current state (“as‑is”) of the on‑premise AI server capability and the supporting processes, including:

  • Current architecture and deployment (hardware, virtualization/containers, GPU stack, storage, network zoning, backups, patching approach).
  • Current AI toolset (frameworks, model runtimes/serving, vector DB, embedding models, LLMs, orchestration, prompt tooling, pipelines).
  • Current security controls (authentication, RBAC, secrets management, certificate management, host hardening, network controls).
  • Current data sources used or planned for use (SOC telemetry, EDR, SIEM, ticketing/case mgmt, threat intel, forensics repositories, malware sandboxes, knowledge bases/Confluence, etc.).
  • Current logging/monitoring (system, application, model usage/audit logs), incident handling integration.
  • Current documentation: review and map existing SOPs/SOIs in Confluence and identify documentation gaps and misalignments with actual practice.
  • Workshops: organise up to 3 workshops with stakeholders (SOC/DFIR/Threat Hunting/IR/Platform admins) to validate the as‑is workflow and priorities.

Based on the approved recommendations from D1, implement agreed improvements to make the AI server capability operational and secure, including:

  • System hardening and baseline configuration (OS/container runtime, GPU drivers, patching approach).
  • Authentication integration (e.g., enterprise IdP/LDAP/AD as applicable).
  • Limitation of rights: RBAC roles, least privilege, separation of duties (admins vs users vs auditors) and how this applies to specific AI dataset.
  • Secrets management and secure configuration handling.
  • Implementation of a multi-model multi user approach to best serve the potential use cases.
  • Audit logging enabling traceability of:
  • user access,
  • model usage (prompt/response metadata as policy allows),
  • administrative actions.
  • Update existing SOPs/SOIs in Confluence to reflect the implemented operational model (do not create parallel SOPs unless required).

Design and implement (as agreed) data integrations and an operational RAG pipeline to enable and optimize AI use cases, including:

  • Identify priority use cases and required data (e.g., alert summarization, case enrichment, IOC/TTP retrieval, playbook guidance, forensic artefact Q&A, malware triage support, threat hunting hypothesis support).
  • Implement data ingestion/connectors (as feasible) aligned with existing systems and permissions such as SIEM, Forensics Lab, internal wiki etc.
  • Build RAG pipeline components:
  • embedding strategy and vector store configuration,
  • retrieval strategy (filters, hybrid search where applicable),
  • evaluation approach (quality, hallucination reduction, regression tests on curated datasets).
  • recommend model families/serving approach suitable for on‑prem constraints,
  • propose new models where beneficial (e.g., embeddings, rerankers, small task models),
  • optimize existing ones (latency, throughput, context management).
  • Update existing documentation (SOPs/SOIs) to include operational steps for maintaining the RAG pipeline and integrations.

Conduct a risk analysis focused on Confidentiality, Integrity and Availability (CIA) for the AI server environment, considering:

  • Data classification and sensitivity (SOC data, IR case data, forensics artefacts, malware samples, intel feeds, internal knowledge bases).
  • Threat model relevant to on-prem AI workloads (insider misuse, prompt injection/data exfiltration, supply‑chain, model poisoning, insecure connectors, misconfiguration, credential theft, lateral movement).
  • CIA risks introduced by:
  • selected models and runtimes,
  • RAG pipeline and vector store,
  • ingestion pipelines and connectors,
  • storage and backup strategy,
  • authentication/RBAC design and audit logging,
  • admin operations and patching.
  • Mitigation plan: technical, procedural and documentation changes, aligned with existing security governance.
Deliverable 5 (Training package and knowledge Transfer)

Best usage of the on-premise AI server

  • How to access the platform (authentication, MFA where applicable) and comply with limitation of rights (RBAC).
  • Operational do’s/don’ts: data handling, prompt hygiene, safe usage patterns, auditability expectations.
  • How to use and interpret logs/audit trails relevant to AI usage (as permitted by policy).
  • How to report issues, request access changes, and request new integrations/models through existing processes.

How to extend existing AI use cases

  • How to onboard a new use case (intake template, success criteria, risk considerations).
  • How to add/modify RAG sources (connectors, metadata, access filters, retention).
  • How to adjust chunking, embeddings, retrieval strategies, and citation/grounding.
  • How to introduce evaluation and regression tests for use cases (quality and safety).

Fine-tuning adaptation fundamentals

  • When fine‑tuning is appropriate vs RAG / prompt engineering / tool use.
  • Data preparation and governance (dataset curation, PII/secret handling, licensing).
  • Fine‑tuning workflow on‑prem (as supported by the implemented toolset): training runs, validation, versioning, rollback.
  • Model lifecycle management: documenting changes, performance tracking, and approval workflow.

Use of commercial off‑the‑shelf products for Cyber Threat Intelligence with non‑classified data

  • Practical usage patterns for tools such as Anthropic Claude (and equivalent services) strictly with non‑classified data.
  • Data handling rules and redaction/anonymisation approach (what must never be submitted).
  • Example CTI workflows (e.g., summarising public reports, extracting IOCs from open sources, mapping to ATT&CK, drafting non‑classified briefs).
  • Decision guidance: when to use on‑prem models vs external COTS services.
  • Interactive format including demonstrations and hands‑on exercises using approved datasets and non‑sensitive content.

This part of the work is dependent on work already done under D2, D3 and D4 and identified as agreed follow‑up activities in the realm of:

  • implementation support
  • maintenance
  • monitoring improvements
Essential Skills, Experience and Certifications
  • Demonstrable 3+ years experience as a Red Hat Linux system administrator / platform engineer operating on‑prem environments (servers, storage, networking, hardening, patching, backup/restore).
  • Demonstrable 1+ years experience building and operating AI/ML platforms on‑prem (GPU servers, CUDA stack, containers, model serving).
  • Demonstrable 2+ years experience integrating enterprise authentication and authorization (AD/LDAP/SAML/OIDC), including RBAC and least‑privilege design.
  • Demonstrable experience delivering AI‑enabled cyber security use cases in at least two of the following domains:
  • SOC
  • Threat Hunting
  • Malware Analysis
  • Demonstrable experience implementing Retrieval‑Augmented Generation (RAG) in production‑like environments, including:
  • grounding/citations and evaluation methods.
  • Demonstrable experience integrating and governing multiple data sources, such as:
  • SIEM/SOAR,
  • EDR,
  • case management,
  • threat intel,
  • knowledge bases (e.g., Confluence),
  • forensic repositories,
  • while enforcing access controls.
  • Demonstrable experience with security logging and auditability for AI systems (access logs, admin activity logs, model usage telemetry as permitted by policy).
  • Demonstrable experience producing and maintaining operational documentation in Atlassian Confluence (minimum 2 years), including SOP/SOI style documentation and runbooks.
  • Good knowledge of OSI layers and core protocols (TCP/IP, VLANs, routing basics, TLS).
  • Strong knowledge of containerization (Docker/Podman) including GPU scheduling concepts.
  • Strong knowledge of model serving patterns (e.g., vLLM/TGI/llama.cpp‑class runtimes, API gateways/reverse proxies, rate limiting).
  • Knowledge of LLM security risks and mitigations:
  • insecure connectors,
  • secure prompt/data handling and redaction practices.
  • Ability to perform a structured CIA risk analysis (Confidentiality, Integrity, Availability) for the chosen toolset/models/data flows, and translate this into actionable mitigations.
  • At least one relevant certification in security / cloud / platform / AI security, such as:
  • CISSP, CISM, CCSP
  • Linux: RHCSA/RHCE or equivalent
  • Equivalent certifications may be accepted if demonstrably relevant.
Working Policy
  • Hybrid (50% remote, 50% onsite)
Travel
  • Frequent travel to NATO site in Mons is required
Security Clearance
  • Valid National or NATO Secret personal security clearance
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

CYBERSPACE OPERATIONS GENERATIVE ARTIFICIAL
CYBERSPACE OPERATIONS GENERATIVE ARTIFICIAL

Brevco Services • Henegouwen

Hybride
EUR 90 000 - 115 000
Cybersecurity Tools Engineer – Linux & Docker
Cybersecurity Tools Engineer – Linux & Docker

Spektrum • Henegouwen

Sur place
EUR 55 000 - 90 000
Cyber Security Senior Project Manager
Cyber Security Senior Project Manager

Spektrum • Eigenbrakel

Sur place
EUR 70 000 - 90 000
Senior Cyber Security Specialist
Senior Cyber Security Specialist

Spektrum • Henegouwen

Sur place
EUR 90 000 - 120 000
C005231 Adversary Emulation Tool Management Support Service (CTS) - THU 8 Oct
C005231 Adversary Emulation Tool Management Support Service (CTS) - THU 8 Oct

EMW • Henegouwen

Sur place
EUR 60 000 - 90 000
[6380] Adversary Emulation Tool Management Support Service
[6380] Adversary Emulation Tool Management Support Service

GardPass Consulting & Space • Henegouwen

Sur place
EUR 70 000 - 110 000
Senior Cyber Security Specialist 5
Senior Cyber Security Specialist 5

Brevco Services • Henegouwen

Hybride
EUR 70 000 - 110 000
DFIR / XDR Tools Engineer – Digital Forensics & Incident Response
DFIR / XDR Tools Engineer – Digital Forensics & Incident Response

Spektrum • Henegouwen

Sur place
EUR 60 000 - 90 000
C005378 Senior Cyber Security Specialist (NS) - MON 28 Sep
C005378 Senior Cyber Security Specialist (NS) - MON 28 Sep

EMW • Henegouwen

Hybride
EUR 65 000 - 90 000
Data Lead - Data Governance
Data Lead - Data Governance

Spektrum • Eigenbrakel

Sur place
EUR 70 000 - 110 000