Threat Information Data Engineer
Il y a 1 semaine
Mons, Wallonia, Belgique
WLG
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
Every threat feed is a different shape. Somebody has to make them onething, and make it trustworthy.
You would engineer the data side of a defence alliance's threat-intelligence sharing platform inMons, Belgium — the pipelines feeding it, the schema underneath it, and the quality rules thatdecide what is worth keeping.
What you would be doing
Designing, building and maintaining the pipelines that ingest threat information from a widerange of sources
Developing and maintaining Python scripts that automate the platform and integrate it with thesystems around it, including security monitoring and detection
Defining, documenting and implementing the rules by which information is disseminated
Supporting the work around threat-information process management
Normalising heterogeneous feed structures into one consistent schema
Enforcing data quality — deduplication, confidence scoring, indicator lifecycle, provenance,and tracking and filtering the low-quality sources
Contributing to and integrating existing cyber threat information standards
Creating and maintaining the documentation on the taxonomies and galaxies people actuallyuse
Writing and keeping current the best-practice guidance for data entry
Being the expert the internal communities come to on curation and dissemination options — whateach one buys them and what it costs
Supporting the user community — regular feedback normally, daily feedback during exercises
Leading a team of platform operators during exercises, covering information flow, qualitycontrol and user management
Planning, preparing and delivering online training, and helping build the individual trainingpackages that prove the objectives were met
What you would bring
At least ten years of practical experience across the areas below
Designing, building and managing data pipelines — transformation, data models, schemas,metadata and workload management
Supporting, leading or managing data-focused operations and projects, using data engineeringtooling behind data science, analytics and visualisation
Python scripting
A good grasp of security principles, practice, concepts and technology
The ability to work alone and in a team
Excellent organisation, communication and writing
Professional English
A bachelor's degree in a related discipline with three years of related experience — or,exceptionally, ten years of progressive expertise in this kind of work
Nice to have
The platform's own core format, and STIX
Work as a cyber threat intelligence analyst, or as an incident responder
Splunk
Handling cyber threat information at scale
Work with open-source communities, and multinational cyber exercises
Administering a threat-sharing platform, or writing code for one in Python or PHP
Why this one is worth a look
Data engineering where the data is adversarial and the quality rules genuinely matter — notanother warehouse.