Ref: 150825
Job description
This Statement of Work (SoW) outlines the services to be provided by the Supplier to enable and operate an on-premise AI server capability supporting cyber security services, including SOC, Digital Forensics, Malware Analysis, Threat Hunting and Incident Response.
The work focuses on:
• implementing and optimizing AI use cases aligned with cyber security operations,
• proposing and testing new models and approaches,
• integrating relevant data sources,
• designing and implementing a robust Retrieval-Augmented Generation (RAG) pipeline,
• implementing authentication and limitation of rights (role-based access, least privilege),
• and performing a risk analysis on Confidentiality, Integrity and Availability (CIA) for the data, toolset and models used.
The contractor shall integrate with existing operational processes and documentation (e.g., existing SOPs/SOIs in Confluence, existing access management processes, logging/monitoring practices) and shall prioritise updating/aligning existing documentation rather than creating parallel artefacts. Services under the current SOW are to be delivered by one or preferably multiple resources that must meet the following experience, qualities and qualifications:
• Demonstrable 3+ years experience as a Red Hat Linux system administrator / platform engineer operating on-prem environments (servers, storage, networking, hardening, patching, backup/restore).
• Demonstrable 1+ years experience building and operating AI/ML platforms onprem (GPU servers, CUDA stack, containers, model serving).
• Demonstrable 2+ years experience integrating enterprise authentication and authorization (AD/LDAP/SAML/OIDC), including RBAC and least-privilege design.
• Demonstrable experience delivering AI-enabled cyber security use cases in at
least two of the following domains: SOC, Threat Hunting, Incident Response, Digital Forensics, Malware Analysis.
• Demonstrable experience implementing Retrieval-Augmented Generation (RAG) in production-like environments, including:
o ingestion pipelines, chunking/metadata design,
o embeddings/vector databases,
o retrieval tuning (filters/hybrid search/reranking),
o grounding/citations and evaluation methods.
• Demonstrable experience integrating and governing multiple data sources such as SIEM/SOAR, EDR, case management, threat intel, knowledge bases
(e.g., Confluence), file shares/object stores, forensic repositories—while enforcing access controls.
• Demonstrable experience with security logging and auditability for AI systems
(access logs, admin activity logs, model usage telemetry as permitted by policy).
• Demonstrable experience producing and maintaining operational documentation in Atlassian Confluence (minimum 2 years), including SOP/SOI style documentation and runbooks.
• Good knowledge of OSI layers and core protocols (TCP/IP, VLANs, routing basics, TLS).
• Strong knowledge of containerization (Docker/Podman) including GPU scheduling concepts.
• Strong knowledge of model serving patterns (e.g., vLLM/TGI/llama.cpp-class runtimes, API gateways/reverse proxies, rate limiting).
• Knowledge of LLM security risks and mitigations:
o prompt injection, data exfiltration via RAG, insecure connectors,
o poisoning (data/model), supply-chain risks,
o secure prompt/data handling and redaction practices.
• Ability to perform a structured CIA risk analysis (Confidentiality, Integrity, Availability) for the chosen toolset/models/data flows, and translate this into actionable mitigations.
• At least one relevant certification in security / cloud / platform / AI security, such
as:
o CISSP, CISM, CCSP
o GIAC (e.g., GSEC, GCED, GCIH, GMON, GCIA, GDSA, etc.)
o Linux: RHCSA/RHCE or equivalent (Equivalent certifications may be accepted if demonstrably relevant.)
• Good English writing and speaking skills (NATO STANAG 3333)
• Soft skills: Accuracy and Attention to Details (Precision), Patience and Persistence, Methodical Organization, Time Management and Prioritization, Effective Communication
The work focuses on:
• implementing and optimizing AI use cases aligned with cyber security operations,
• proposing and testing new models and approaches,
• integrating relevant data sources,
• designing and implementing a robust Retrieval-Augmented Generation (RAG) pipeline,
• implementing authentication and limitation of rights (role-based access, least privilege),
• and performing a risk analysis on Confidentiality, Integrity and Availability (CIA) for the data, toolset and models used.
The contractor shall integrate with existing operational processes and documentation (e.g., existing SOPs/SOIs in Confluence, existing access management processes, logging/monitoring practices) and shall prioritise updating/aligning existing documentation rather than creating parallel artefacts. Services under the current SOW are to be delivered by one or preferably multiple resources that must meet the following experience, qualities and qualifications:
• Demonstrable 3+ years experience as a Red Hat Linux system administrator / platform engineer operating on-prem environments (servers, storage, networking, hardening, patching, backup/restore).
• Demonstrable 1+ years experience building and operating AI/ML platforms onprem (GPU servers, CUDA stack, containers, model serving).
• Demonstrable 2+ years experience integrating enterprise authentication and authorization (AD/LDAP/SAML/OIDC), including RBAC and least-privilege design.
• Demonstrable experience delivering AI-enabled cyber security use cases in at
least two of the following domains: SOC, Threat Hunting, Incident Response, Digital Forensics, Malware Analysis.
• Demonstrable experience implementing Retrieval-Augmented Generation (RAG) in production-like environments, including:
o ingestion pipelines, chunking/metadata design,
o embeddings/vector databases,
o retrieval tuning (filters/hybrid search/reranking),
o grounding/citations and evaluation methods.
• Demonstrable experience integrating and governing multiple data sources such as SIEM/SOAR, EDR, case management, threat intel, knowledge bases
(e.g., Confluence), file shares/object stores, forensic repositories—while enforcing access controls.
• Demonstrable experience with security logging and auditability for AI systems
(access logs, admin activity logs, model usage telemetry as permitted by policy).
• Demonstrable experience producing and maintaining operational documentation in Atlassian Confluence (minimum 2 years), including SOP/SOI style documentation and runbooks.
• Good knowledge of OSI layers and core protocols (TCP/IP, VLANs, routing basics, TLS).
• Strong knowledge of containerization (Docker/Podman) including GPU scheduling concepts.
• Strong knowledge of model serving patterns (e.g., vLLM/TGI/llama.cpp-class runtimes, API gateways/reverse proxies, rate limiting).
• Knowledge of LLM security risks and mitigations:
o prompt injection, data exfiltration via RAG, insecure connectors,
o poisoning (data/model), supply-chain risks,
o secure prompt/data handling and redaction practices.
• Ability to perform a structured CIA risk analysis (Confidentiality, Integrity, Availability) for the chosen toolset/models/data flows, and translate this into actionable mitigations.
• At least one relevant certification in security / cloud / platform / AI security, such
as:
o CISSP, CISM, CCSP
o GIAC (e.g., GSEC, GCED, GCIH, GMON, GCIA, GDSA, etc.)
o Linux: RHCSA/RHCE or equivalent (Equivalent certifications may be accepted if demonstrably relevant.)
• Good English writing and speaking skills (NATO STANAG 3333)
• Soft skills: Accuracy and Attention to Details (Precision), Patience and Persistence, Methodical Organization, Time Management and Prioritization, Effective Communication
Apply for this role
Hi I'm Dominque.
I manage this role
If you would like to know more about this role or similar jobs, please get in contact with me.
Recommend.
this role to a friend
Is this role revelant to any one you know?
Share it with them now.
