- Software Engineer
- Cyber Security
- Technical Development
Duties & Role:
We are looking for a hands-on Cyber Security Software Engineer to support the Cyber Defense Situational Awareness (CDSA) platform.
The role combines technical development work (mainly in Splunk) with operational support and close coordination with both the development contractor and CyOC users. The engineer will contribute to the continuous improvement of CDSA dashboards, data integrations, and operational capabilities.
Under the direction of the DICE Team Lead the contractor shall:
Technical Development & Maintenance
- Develop and maintain CDSA dashboards, visualizations, and UI components in Splunk.
- Perform hands-on work on data models, KVStore collections, scheduled searches, and macros.
- Implement small to medium enhancements and fixes based on operational needs and user feedback.
- Support the integration of new data sources and tools into CDSA (e.g. PLM, ACPV, Cribl, etc.).
- Develop scripts and automation to improve data processing and platform operations.
Operational Support & CyOC Coordination
- Provide technical and operational support to CyOC users on a day-to-day basis.
- Act as a technical bridge between CyOC operational needs and the development contractor (Infigo/King ICT).
- Validate and test new dashboards and features delivered by the contractor before they go into production.
- Collect and prioritize user feedback from CyOC and translate it into actionable technical tasks.
- Support Early Life Support (ELS) activities for new features and releases.
Platform Health & Improvement
- Monitor dashboard performance, data quality, and overall platform health.
- Identify opportunities for improvement in existing dashboards and data pipelines.
- Contribute to the technical roadmap and evolution of the CDSA platform.
Requirements
Skills, Knowledge & Experience:
- The candidate must have a currently active NATO SECRET security clearance
- A minimum requirement of a Bachelor's degree at a nationally recognized/certified University in a related discipline and 3 years post-related experience;
- Or exceptionally, the lack of a university degree may be compensated by he demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work.
- At least 3 years practical and hands-on experience in Splunk (dashboard development, data models, KVStore, macros, scheduled searches).
- At least 3 years practical and hands-on experience in Splunk UI development and visualization best practices.
- At least 3 years practical and hands-on experience in scripting (Python, Bash, or similar).
- At least 3 years practical and hands-on experience in interacting with REST APIs or similar
- At least 3 years practical and hands-on experience in interacting with Databases
- Good understanding of cybersecurity concepts (vulnerability management, threat intelligence, incident management).
- Good communication and analytical skills — able to translate technical topics for operational users and vice versa.
- Strong analytical and problem-solving skills.
- Ability to work operationally with end users while also performing technical development work.
- Language proficiency in English: meet or exceed the NATO STANAG 6001 Level 3 "Professional Proficiency".
Desirable Experience and Education:
- Certification in Splunk Enterprise
- Certification in Machine Learning and/or Artificial Intelligence
- Previous experience with CDSA or similar large Splunk-based platforms.
- Experience with data integration projects (REST APIs, DB Connect, Cribl, etc.).
- Knowledge of MITRE ATT&CK or vulnerability scoring methodologies.
- Prior experience with Machine Learning and Artificial Intelligence
- Previous work in NATO, military, or high-security environments.