hirly

Apply with hirly

Senior AI Engineer – Cybersecurity

Spektrum · Mons, Belgium

Upload your resume to see how well you match this job — free, in seconds, no account needed.

Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.

Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects. Who we are supporting The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium. The NCIA provides a wide range of services, including:

  • Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.
  • Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.
  • Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
  • Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.
  • Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers. Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities. The program Assistance and Advisory Service (AAS) The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V. To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce. Role ID – 2026-0137 Role Background The NATO Cyber Security Centre (NCSC) is a team of over 200 members working to monitor and protect NATO networks. In the NCSC’s role to deliver robust security services to the NATO Enterprise and NATO Allied Operations and Missions (AOM), the centre executes a portfolio of programmes and projects around 219 MEUR euros per year, in order to uplift and enhance critical cyber security services. The Portfolio ranges from Programme of Work (POW) activities funded via the NATO Military Budget (MB) to Critical / Urgent Requirements (CURs/URs) and NATO Security Investment Programme (NSIP) projects funded via the Investment Budget(IB). In some edge cases, projects are also funded via the Civilian Budget (CB). Projects can span multiple years and are governed by various frameworks, including the Common Funded Capability Development Governance Framework (CFCDGM). In order to execute this work, the NCI Agency requires support with the work undertaken by the NATO Cyber Security Centre (NCSC) in the area of Communications and Information System (CIS) security, cyber defence and cyberspace operations. This Statement of Work (SoW) specifies the required skillset and experience. Objectives This Statement of Work (SoW) outlines the services to be provided by the Supplier to enable and operate an on-premise AI server capability supporting cyber security services, including SOC, Digital Forensics, Malware Analysis, Threat Hunting and Incident Response. The work focuses on:
  • Implementing and optimizing AI use cases aligned with cyber security operations,
  • Proposing and testing new models and approaches
  • Integrating relevant data sources
  • Designing and implementing a robust Retrieval-Augmented Generation (RAG) pipeline,
  • implementing authentication and limitation of rights (role-based access, least privilege), and performing a risk analysis on Confidentiality, Integrity and Availability (CIA) for the data, toolset and models used. They shall integrate with existing operational processes and documentation (e.g., existing SOPs/SOIs in Confluence, existing access management processes, logging/monitoring practices) and shall prioritise updating/aligning existing documentation rather than creating parallel artefacts Deliverables Deliverable 1: Capture the current state (“as-is”) of the on-premise AI server capability and the supporting processes, including:
  • Current architecture and deployment (hardware, virtualization/containers, GPU stack, storage, network zoning, backups, patching approach).
  • Current AI toolset (frameworks, model runtimes/serving, vector DB, embedding models, LLMs, orchestration, prompt tooling, pipelines).
  • Current security controls (authentication, RBAC, secrets management, certificate management, host hardening, network controls).
  • Current data sources used or planned for use (SOC telemetry, EDR, SIEM, ticketing/case mgmt, threat intel, forensics repositories, malware sandboxes, knowledge bases/Confluence, etc.).
  • Current logging/monitoring (system, application, model usage/audit logs), incident handling integration.
  • Current documentation: review and map existing SOPs/SOIs in Confluence and identify documentation gaps and misalignments with actual practice.
  • Workshops: organise up to 3 workshops with stakeholders (SOC/DFIR/Threat Hunting/IR/Platform admins) to validate the as-is workflow and priorities. Deliverable 2: Based on the approved recommendations from D1, implement agreed improvements to make the AI server capability operational and secure, including:
  • System hardening and baseline configuration (OS/container runtime, GPU drivers, patching approach).
  • Authentication integration (e.g., enterprise IdP/LDAP/AD as applicable).
  • Limitation of rights: RBAC roles, least privilege, separation of duties (admins vs users vs auditors) and how this applies to specific AI dataset.
  • Secrets management and secure configuration handling.
  • Implementation of a multi-model multi user approach to best serve the potential use cases.
  • Audit logging enabling traceability of:
  • user access,
  • data access,
  • model usage (prompt/response metadata as policy allows),
  • administrative actions.
  • Update existing SOPs/SOIs in Confluence to reflect the implemented operational model (do not create parallel SOPs unless required). Deliverable 3: Design and implement (as agreed) data integrations and an operational RAG pipeline to enable and optimize AI use cases, including:
  • Identify priority use cases and required data (e.g., alert summarization, case enrichment, IOC/TTP retrieval, playbook guidance, forensic artefact Q&A, malware triage support, threat hunting hypothesis support).
  • Implement data ingestion/connectors (as feasible) aligned with existing systems and permissions such as SIEM, Forensics Lab, internal wiki etc.
  • Build RAG pipeline components:
  • ingestion, chunking strategy, metadata schema,
  • embedding strategy and vector store configuration,
  • retrieval strategy (filters, hybrid search where applicable),
  • grounding/citation strategy,
  • evaluation approach (quality, hallucination reduction, regression tests on curated datasets).
  • Propose/validate models:
  • recommend model families/serving approach suitable for on-prem constraints,
  • propose new models where beneficial (e.g., embeddings, rerankers, small task models),
  • optimize existing ones (latency, throughput, context management
Apply: Senior AI Engineer – Cybersecurity at Spektrum