IT Services
Contract
Belgium
Mons
Needed
NCIA
Essential Qualifications/Experience:
· Demonstrable 3+ years experience as a Red Hat Linux system administrator / platform engineer operating on-prem environments (servers, storage, networking, hardening, patching, backup/restore)
· Demonstrable 1+ years experience building and operating AI/ML platforms on-prem (GPU servers, CUDA stack, containers, model serving)
· Demonstrable 2+ years experience integrating enterprise authentication and authorization (AD/LDAP/SAML/OIDC), including RBAC and least-privilege design
· Demonstrable experience delivering AI-enabled cyber security use cases in at least two of the following domains: SOC, Threat Hunting, Incident Response, Digital Forensics, Malware Analysis
· Demonstrable experience implementing Retrieval-Augmented Generation (RAG) in production-like environments, including:
ü ingestion pipelines, chunking/metadata design
ü embeddings/vector databases
ü retrieval tuning (filters/hybrid search/reranking)
ü grounding/citations and evaluation methods
· Demonstrable experience integrating and governing multiple data sources, such as SIEM/SOAR, EDR, case management, threat intel, knowledge bases (e.g., Confluence), file shares/object stores, forensic repositories—while enforcing access controls
· Demonstrable experience with security logging and auditability for AI systems (access logs, admin activity logs, model usage telemetry as permitted by policy)
· Demonstrable experience producing and maintaining operational documentation in Atlassian Confluence (minimum 2 years), including SOP/SOI style documentation and runbooks
· Good knowledge of OSI layers and core protocols (TCP/IP, VLANs, routing basics, TLS)
· Strong knowledge of containerization (Docker/Podman) including GPU scheduling concepts
· Strong knowledge of model serving patterns (e.g., vLLM/TGI/llama.cpp-class runtimes, API gateways/reverse proxies, rate limiting)
· Knowledge of LLM security risks and mitigations:
ü prompt injection, data exfiltration via RAG, insecure connectors
ü poisoning (data/model), supply-chain risks
ü secure prompt/data handling and redaction practices
· Ability to perform a structured CIA risk analysis (Confidentiality, Integrity, Availability) for the chosen toolset/models/data flows, and translate this into actionable mitigations
· At least one relevant certification in security / cloud / platform / AI security, such as:
ü CISSP, CISM, CCSP
ü GIAC (e.g., GSEC, GCED, GCIH, GMON, GCIA, GDSA, etc.)
ü Linux: RHCSA/RHCE or equivalent (Equivalent certifications may be accepted if demonstrably relevant.)
DUTIES/ROLE:
· Capture the current state (“as-is”) of the on-premise AI server capability and the supporting processes, including:
ü Current architecture and deployment (hardware, virtualization/containers, GPU stack, storage, network zoning, backups, patching approach)
ü Current AI toolset (frameworks, model runtimes/serving, vector DB, embedding models, LLMs, orchestration, prompt tooling, pipelines)
ü Current security controls (authentication, RBAC, secrets management, certificate management, host hardening, network controls)
ü Current data sources used or planned for use (SOC telemetry, EDR, SIEM, ticketing/case mgmt, threat intel, forensics repositories, malware sandboxes, knowledge bases/Confluence, etc.)
ü Current logging/monitoring (system, application, model usage/audit logs), incident handling integration
ü Current documentation: review and map existing SOPs/SOIs in Confluence and identify documentation gaps and misalignments with actual practice
ü Workshops: organise up to 3 workshops with stakeholders (SOC/DFIR/Threat Hunting/IR/Platform admins) to validate the as-is workflow and priorities
All the mandatory requirements have to be met in order to apply.