EXPERIENCE AND EDUCATION:
Essential Qualifications/Experience:
Knowledge and experience (more than 5 years) in the following areas:
Very good technical understanding of the cyber threats to web based products
Demonstrated experience as sysadmin with LAMP servers Linux Apache MySQL/MariaDB PHP
Experience with RedHat is an asset
Excellent python scripting
Experience in MVC software development and code review of web applications mostly in PHP language and with SQL
Experience with CakePHP is an asset
Prior experience as sysadmin of a MISP Threat Sharing platform is a very strong asset
Prior experience in developing code (python PHP) for MISP is an even stronger asset
Prior experience in multinational cyber exercises like Locked Shields Crossed Swords Cyber Coalition etc. is an important asset
Good understanding of cyber security principles best practices concepts and technology
DUTIES/ROLE:
System administration:
Proactively manage and maintain the multiple servers running the MISP software ensuring the necessary confidentiality integrity and availability of the tool and information
Stand up configure and manage dedicated MISP instances in support to multiple NATO exercises
Regularly update the MISP software to the latest version and support the test and validation effort for change management process
Configure and extend the system monitoring of those MISP installations
Maintain the ansible playbooks related to the MISP setup and configuration
Maintain and improve documentation related to the MISP installations within NATO
Content Management:
Developing (python) and maintain scripts to further automate and integrate MISP with other subsystems within NATO such as the SIEM IDS
Support the quality management effort by creating and maintaining content quality checking rules
User and Community Management:
Provide support to the usercommunity of the NATO managed MISP instances
Provide feedback to the usercommunity on regular basis and on dailybasis during exercises execution
During exercises lead a team of multiple MISP Operators to support information flow quality control and user management
Support the streamlining and automation of user management process with a combination of IT Service Management tools (ITSM) and Identity and Access Management (IDAM) tools like Cerebrate and/or Keycloak
MISP Training support
Plan for prepares and delivers a series of online MISP training Sessions to an exercise audience
Support the preparation of individual training packages for specific training audience to validate the training objectives have been met