Role ID – C005045
Role Background
We are seeking a hands-on Cyber Security Software Engineer to support the Cyber Defence Situational Awareness (CDSA) platform. This role combines software development, platform maintenance, and operational support, with a strong focus on Splunk development. You will work closely with Cyber Operations Centre (CyOC) users and development partners to enhance dashboards, improve data integrations, and ensure the platform continues to meet operational needs.
Role Duties and Responsibilities
- Develop and maintain CDSA dashboards, visualizations, and user interface components in Splunk.
- Design and maintain Splunk data models, KVStore collections, scheduled searches, and macros.
- Implement enhancements, bug fixes, and improvements based on operational requirements and user feedback.
- Integrate new data sources and security tools into the CDSA platform.
- Develop automation scripts to improve data processing and platform operations.
- Provide day-to-day technical and operational support to Cyber Operations Centre (CyOC) users.
- Act as the technical liaison between CyOC users and the external development contractor.
- Validate and test new dashboards, features, and platform updates before production deployment.
- Gather, prioritize, and translate user feedback into technical development tasks.
- Support Early Life Support (ELS) activities for new releases and platform enhancements.
- Monitor dashboard performance, data quality, and overall platform health.
- Identify opportunities to improve dashboards, data pipelines, and platform capabilities.
- Contribute to the ongoing technical roadmap and future development of the CDSA platform.
Essential Skills and Experience
- Minimum 3 years of hands-on experience with Splunk, including:
- Dashboard development
- Data models
- KVStore
- Scheduled searches
- Macros
- Experience developing Splunk user interfaces and visualizations.
- Experience with scripting languages such as Python, Bash, or similar.
- Experience working with REST APIs.
- Experience interacting with databases.
- Good understanding of cybersecurity concepts, including:
- Vulnerability Management
- Threat Intelligence
- Incident Management
- Strong analytical and problem-solving skills.
- Excellent communication skills with the ability to explain technical concepts to operational users.
- Ability to balance operational support with software development responsibilities.
- Professional English proficiency equivalent to NATO STANAG 6001 Level 3.
- At least 3 years of practical experience in Splunk development and administration.
- Experience in software scripting and automation.
- Experience with API integrations and database connectivity.
- Experience supporting cybersecurity platforms or security operations.
Desirable Skills and Experience
- Experience with CDSA or similar large-scale Splunk platforms.
- Experience with data integration technologies such as REST APIs, DB Connect, and Cribl.
- Knowledge of MITRE ATT&CK Framework and vulnerability scoring methodologies.
- Experience with Machine Learning and Artificial Intelligence.
- Previous experience working in NATO, military, defence, or other high-security environments.
Education
- Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, or a related discipline
- OR A minimum of 10 years of progressive professional experience in relevant cybersecurity or software engineering roles may be accepted in place of a university degree.
Desirable Certifications
- Splunk Enterprise Certification.
- Machine Learning and/or Artificial Intelligence Certification.
Language Proficiency
Working Location
Working Policy
- Full-time, primarily on-site.
- Remote work of up to 20% may be permitted with prior approval and subject to NCIA policies.