About this C005317 MISP Senior Data Engineer (NS) - TUE 15 Sep role at EMW, Inc.
Deadline Date: Tuesday 15 September 2026
Requirement: MISP Senior Data Engineer
Location: Mons, BE
Full Time On-Site: Yes
Time On-Site: 100%
Total Scope of the request (hours): 395
Required Start Date: 21 October 2026
End Contract Date: 31 December 2026
Required Security Clearance: NATO SECRET
Duties & Role:
Under the direction of the CIMAT team lead the contractor shall perform the following tasks:
Threat information pipeline engineering:
- Design, build, and maintain pipelines that ingest threat information from diverse sources
- Develop (python) and maintain scripts to further automate and integrate MISP with other subsystems within NATO such as the SIEM, IDS, etc.
- Define, document and implement information dissemination rules
- Support initiatives around threat information process management
Data normalization
- Normalize heterogeneous feed structures into a consistent schema
- Enforce data quality: deduplication, confidence scoring, indicator lifecycle management, provenance tracking, tracking and filtering of low-quality data sources
- Provide input on, and integrate existing cyber threat information standards
- Create and maintain documentation on commonly used MISP taxonomies and galaxies
User and Community Management:
- Create and maintain documentation on "best practices for MISP data entry"
- Act as a subject matter expert for NATO MISP communities, providing community members with guidance on potential data curation and dissemination options and their benefits and limitations
- Provide support to the user-community of the NATO managed MISP instances
- Provide regular feedback to the user-community, and daily feedback during exercises
- During exercises, lead a team of multiple MISP Operators to support information flow, quality control and user management.
MISP Training support
- Plan for, prepare and deliver online MISP training sessions.
- Support the preparation of individual training packages to validate the training objectives have been met.
Specific Working Conditions: The contractor may be permitted to perform work remotely, from a different NATO nation than the duty location, for up to a maximum of twenty percent (20%) of their total working time, subject to prior approval by their NCIA designated Resource Manager. If working from a remote location, the contractor shall provide IT equipment for the processing of public and unclassified information in support of their duties, including the capability to participate in video meetings using Microsoft based collaboration tools.
Travel required: The contractor may be required to travel to other NCIA locations for in-person or department meetings. In such cases the contractor will be reimbursed for travel costs according to NATO regulations for traveling on NATO duty. Each travel will be a maximum of 2 days lengths and happening no more than twice per month. Contractors traveling for work purposes shall initiate travel requests from their designated duty station only.
Requirements
Skills, Knowledge & Experience:
- The candidate must have a currently active NATO SECRET security clearance
- A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience;
- Or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work.
- At least 10 years practical experience in designing, building and managing data pipelines for data structures encompassing data transformation, data models, schemas, metadata and workload management.
- At least 10 years practical experience in supporting, leading and/or managing data focused operations and projects, using data engineering tools to support data science, data analytics and data visualisation.
- At least 10 years practical experience in Python scripting
- Good understanding of cyber security principles, best practices, concepts and technologies
- Ability to work independently and in a team
- Excellent organization, communication and writing skills
- Language proficiency in English: meet or exceed the NATO STANAG 6001 Level 3 "Professional Proficiency".
Desirable Experience:
- Experience with MISP core format and STIX format
- Experience as a cyber threat intelligence analyst
- Experience with Splunk
- Experience as an incident responder
- Experience handling cyber threat related information
- Experience working with open-source communities
- Experience with multinational cyber exercises e.g. Locked Shields, Crossed Swords, Cyber Coalition, etc.
- Experience as sysadmin of a MISP Threat Sharing platform
- Experience in developing code (python, PHP) for MISP