hirly

Spektrum

Senior AI Engineer – Cybersecurity

Mons, Belgium

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Spektrum first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Senior
Country
BE
Work mode
On-site / unstated
First seen by hirly
25 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.

Who we are supporting

The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.

The NCIA provides a wide range of services, including:

Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.

Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.

Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.

Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.

Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers.

Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities.

The program

Assistance and Advisory Service (AAS)

The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.

To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.

Role ID – 2026-0137

Role Background

The NATO Cyber Security Centre (NCSC) is a team of over 200 members working to monitor and protect NATO networks. In the NCSC’s role to deliver robust security services to the NATO Enterprise and NATO Allied Operations and Missions (AOM), the centre executes a portfolio of programmes and projects around 219 MEUR euros per year, in order to uplift and enhance critical cyber security services.

The Portfolio ranges from Programme of Work (POW) activities funded via the NATO Military Budget (MB) to Critical / Urgent Requirements (CURs/URs) and NATO Security Investment Programme (NSIP) projects funded via the Investment Budget(IB). In some edge cases, projects are also funded via the Civilian Budget (CB). Projects can span multiple years and are governed by various frameworks, including the Common Funded Capability Development Governance Framework (CFCDGM).

In order to execute this work, the NCI Agency requires support with the work undertaken by the NATO Cyber Security Centre (NCSC) in the area of Communications and Information System (CIS) security, cyber defence and cyberspace operations. This Statement of Work (SoW) specifies the required skillset and experience.

Objectives

This Statement of Work (SoW) outlines the services to be provided by the Supplier to enable and operate an on-premise AI server capability supporting cyber security services, including SOC, Digital Forensics, Malware Analysis, Threat Hunting and Incident Response.

The work focuses on:

Implementing and optimizing AI use cases aligned with cyber security operations,

Proposing and testing new models and approaches

Integrating relevant data sources

Designing and implementing a robust Retrieval-Augmented Generation (RAG) pipeline,

implementing authentication and limitation of rights (role-based access, least privilege), and performing a risk analysis on Confidentiality, Integrity and Availability (CIA) for the data, toolset and models used.

They shall integrate with existing operational processes and documentation (e.g., existing SOPs/SOIs in Confluence, existing access management processes, logging/monitoring practices) and shall prioritise updating/aligning existing documentation rather than creating parallel artefacts

Deliverables

Deliverable 1:

Capture the current state (“as-is”) of the on-premise AI server capability and the supporting processes, including:

Current architecture and deployment (hardware, virtualization/containers, GPU stack, storage, network zoning, backups, patching approach).

Current AI toolset (frameworks, model runtimes/serving, vector DB, embedding models, LLMs, orchestration, prompt tooling, pipelines).

Current security controls (authentication, RBAC, secrets management, certificate management, host hardening, network controls).

Current data sources used or planned for use (SOC telemetry, EDR, SIEM, ticketing/case mgmt, threat intel, forensics repositories, malware sandboxes, knowledge bases/Confluence, etc.).

Current logging/monitoring (system, application, model usage/audit logs), incident handling integration.

Current documentation: review and map existing SOPs/SOIs in Confluence and identify documentation gaps and misalignments with actual practice.

Workshops: organise up to 3 workshops with stakeholders (SOC/DFIR/Threat Hunting/IR/Platform admins) to validate the as-is workflow and priorities.

Deliverable 2:

Based on the approved recommendations from D1, implement agreed improvements to make the AI server capability operational and secure, including:

System hardening and baseline configuration (OS/container runtime, GPU drivers, patching approach).

Authentication integration (e.g., enterprise IdP/LDAP/AD as applicable).

Limitation of rights: RBAC roles, least privilege, separation of duties (admins vs users vs auditors) and how this applies to specific AI dataset.

Secrets management and secure configuration handling.

Implementation of a multi-model multi user approach to best serve the potential use cases.

Audit logging enabling traceability of:

user access,

data access,

model usage (prompt/response metadata as policy allows),

administrative actions.

Update existing SOPs/SOIs in Confluence to reflect the implemented operational model (do not create parallel SOPs unless required).

Deliverable 3:

Design and implement (as agreed) data integrations and an operational RAG pipeline to enable and optimize AI use cases, including:

Identify priority use cases and required data (e.g., alert summarization, case enrichment, IOC/TTP retrieval, playbook guidance, forensic artefact Q&A, malware triage support, threat hunting hypothesis support).

Implement data ingestion/connectors (as feasible) aligned with existing systems and permissions such as SIEM, Forensics Lab, internal wiki etc.

Build RAG pipeline components:

ingestion, chunking strategy, metadata schema,

embedding strategy and vector store configuration,

retrieval strategy (filters, hybrid search where applicable),

grounding/citation strategy,

evaluation approach (quality, hallucination reduction, regression tests on curated datasets).

Propose/validate models:

recommend model families/serving approach suitable for on-prem constraints,

propose new models where beneficial (e.g., embeddings, rerankers, small task models),

optimize existing ones (latency, throughput, context management

Original posting on Spektrum's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job