Log in/Create account

CYBERSPACE OPERATIONS GENERATIVE ARTIFICIAL

Apply now
Industry

IT Services

Type

Contract

Country

Belgium

City

Mons

Security

Needed

Company

NCIA

Essential Qualifications/Experience:

·       Demonstrable 3+ years experience as a Red Hat Linux system administrator / platform engineer operating on-prem environments (servers, storage, networking, hardening, patching, backup/restore)

·       Demonstrable 1+ years experience building and operating AI/ML platforms on-prem (GPU servers, CUDA stack, containers, model serving)

·       Demonstrable 2+ years experience integrating enterprise authentication and authorization (AD/LDAP/SAML/OIDC), including RBAC and least-privilege design

·       Demonstrable experience delivering AI-enabled cyber security use cases in at least two of the following domains: SOC, Threat Hunting, Incident Response, Digital Forensics, Malware Analysis

·       Demonstrable experience implementing Retrieval-Augmented Generation (RAG) in production-like environments, including:

ü  ingestion pipelines, chunking/metadata design

ü  embeddings/vector databases

ü  retrieval tuning (filters/hybrid search/reranking)

ü  grounding/citations and evaluation methods

·       Demonstrable experience integrating and governing multiple data sources, such as SIEM/SOAR, EDR, case management, threat intel, knowledge bases (e.g., Confluence), file shares/object stores, forensic repositories—while enforcing access controls

·       Demonstrable experience with security logging and auditability for AI systems (access logs, admin activity logs, model usage telemetry as permitted by policy)

·       Demonstrable experience producing and maintaining operational documentation in Atlassian Confluence (minimum 2 years), including SOP/SOI style documentation and runbooks

·       Good knowledge of OSI layers and core protocols (TCP/IP, VLANs, routing basics, TLS)

·       Strong knowledge of containerization (Docker/Podman) including GPU scheduling concepts

·       Strong knowledge of model serving patterns (e.g., vLLM/TGI/llama.cpp-class runtimes, API gateways/reverse proxies, rate limiting)

·       Knowledge of LLM security risks and mitigations:

ü  prompt injection, data exfiltration via RAG, insecure connectors

ü  poisoning (data/model), supply-chain risks

ü  secure prompt/data handling and redaction practices

·       Ability to perform a structured CIA risk analysis (Confidentiality, Integrity, Availability) for the chosen toolset/models/data flows, and translate this into actionable mitigations

·       At least one relevant certification in security / cloud / platform / AI security, such as:

ü  CISSP, CISM, CCSP

ü  GIAC (e.g., GSEC, GCED, GCIH, GMON, GCIA, GDSA, etc.)

ü  Linux: RHCSA/RHCE or equivalent (Equivalent certifications may be accepted if demonstrably relevant.)

DUTIES/ROLE:

·       Capture the current state (“as-is”) of the on-premise AI server capability and the supporting processes, including:

ü  Current architecture and deployment (hardware, virtualization/containers, GPU stack, storage, network zoning, backups, patching approach)

ü  Current AI toolset (frameworks, model runtimes/serving, vector DB, embedding models, LLMs, orchestration, prompt tooling, pipelines)

ü  Current security controls (authentication, RBAC, secrets management, certificate management, host hardening, network controls)

ü  Current data sources used or planned for use (SOC telemetry, EDR, SIEM, ticketing/case mgmt, threat intel, forensics repositories, malware sandboxes, knowledge bases/Confluence, etc.)

ü  Current logging/monitoring (system, application, model usage/audit logs), incident handling integration

ü  Current documentation: review and map existing SOPs/SOIs in Confluence and identify documentation gaps and misalignments with actual practice

ü  Workshops: organise up to 3 workshops with stakeholders (SOC/DFIR/Threat Hunting/IR/Platform admins) to validate the as-is workflow and priorities

Job requirements

All the mandatory requirements have to be met in order to apply.

• Demonstrable 3+ years experience as a Red Hat Linux system administrator / platform engineer operating on-prem environments (servers, storage, networking, hardening, patching, backup/restore) (Mandatory)
• Demonstrable 1+ years experience building and operating AI/ML platforms on-prem (GPU servers, CUDA stack, containers, model serving) (Mandatory)
• Demonstrable 2+ years experience integrating enterprise authentication and authorization (AD/LDAP/SAML/OIDC), including RBAC and least-privilege design (Mandatory)
• Demonstrable experience delivering AI-enabled cyber security use cases in at least two of the following domains: SOC, Threat Hunting, Incident Response, Digital Forensics, Malware Analysis (Mandatory)
• Demonstrable experience implementing Retrieval-Augmented Generation (RAG) in production-like environments, including: (Mandatory)
 ingestion pipelines, chunking/metadata design (Mandatory)
 embeddings/vector databases (Mandatory)
 retrieval tuning (filters/hybrid search/reranking) (Mandatory)
 grounding/citations and evaluation methods (Mandatory)
• Demonstrable experience integrating and governing multiple data sources, such as SIEM/SOAR, EDR, case management, threat intel, knowledge bases (e.g., Confluence), file shares/object stores, forensic repositories—while enforcing access controls (Mandatory)
• Demonstrable experience with security logging and auditability for AI systems (access logs, admin activity logs, model usage telemetry as permitted by policy) (Mandatory)
• Demonstrable experience producing and maintaining operational documentation in Atlassian Confluence (minimum 2 years), including SOP/SOI style documentation and runbooks (Mandatory)
• Good knowledge of OSI layers and core protocols (TCP/IP, VLANs, routing basics, TLS) (Mandatory)
• Strong knowledge of containerization (Docker/Podman) including GPU scheduling concepts (Mandatory)
• Strong knowledge of model serving patterns (e.g., vLLM/TGI/llama.cpp-class runtimes, API gateways/reverse proxies, rate limiting) (Mandatory)
• Knowledge of LLM security risks and mitigations: (Mandatory)
 prompt injection, data exfiltration via RAG, insecure connectors (Mandatory)
 poisoning (data/model), supply-chain risks (Mandatory)
 secure prompt/data handling and redaction practices (Mandatory)
• Ability to perform a structured CIA risk analysis (Confidentiality, Integrity, Availability) for the chosen toolset/models/data flows, and translate this into actionable mitigations (Mandatory)
• At least one relevant certification in security / cloud / platform / AI security, such as: (Mandatory)
 CISSP, CISM, CCSP (Mandatory)
 GIAC (e.g., GSEC, GCED, GCIH, GMON, GCIA, GDSA, etc.) (Mandatory)
 Linux: RHCSA/RHCE or equivalent (Equivalent certifications may be accepted if demonstrably relevant.) (Mandatory)
Apply to the job
Overview
Details
Requirements
Apply