2024-0272 Support for SIEM (Splunk) (NS) BELGIUM - 2 Sep RELAUNCH

2024-0272 Support for SIEM (Splunk) (NS) BELGIUM - 2 Sep RELAUNCH

Contract Type:

Contractor

Location:

Mons - Mons, Belgium

Industry:

NATO

Contact Name:

Tim Lane

Contact Email:

tim@plr.ltd

Contact Phone:

Tim Lane

Date Published:

20-Aug-2025

Deadline Date:  Tuesday 2 September 2025
 
Requirement:   Support in SIEM (Splunk) Infrastructure Management and Log Collection
 
Location:  Mons, BELGIUM
 
Full Time On-Site:  Yes
 
Time On-Site:  100%
 
Not to Exceed:  BASE 2025 NTE: 3,105 EUR/week (max.10 weeks, max NTE: 31,050 EUR)
2026, 2027, 2028 OPTIONS
 
Period of Performance:  Base period: 13 October 2025
 
Required Security Clearance:  NATO Secret
 

Please do  NOT  apply for any NATO contract positions unless you meet ALL the following criteria:
  1. Current National or NATO SECRET clearance
  2. Nationality of one of the NATO member countries
  3. Current work visa for the specific location if applying for an in-country position
Any applications that do NOT meet all the above - and do not CLEARLY show these on the CV - will be deleted.

Background:
  • The NATO Communications and Information Agency (NCI Agency) is dedicated to acquiring, deploying, and defending communication systems for NATO's political decision-makers and Commands. It operates on the frontlines against cyber-attacks, collaborating closely with governments and industry to prevent future debilitating attacks. The NCI Agency plays a crucial role in maintaining NATO's technological edge and ensuring the collective defence and crisis management capabilities of the Alliance. In pursuit of our mission, we require specialized advisory services to enhance our interim workforce capacity.
  • The NCI Agency has been established with a view to meeting the collective requirements of some or all NATO nations in the fields of capability delivery and service provision related to Consultation, Command & Control as well as Communications, Information and Cyber Defence functions, thereby also facilitating the integration of Intelligence, Surveillance, Reconnaissance, Target Acquisition functions and their associated information exchange.
Introduction:
As part of NCI Agency, the NATO Cyber Security Centre (NCSC) represents one of the largest fully integrated global Cyber Defence capabilities in the world. This capability requires a combined international team of 250+ NATO and Industry analysts as well as engineers, to operate and maintain the wide range of Cyber Security services and the complex infrastructure on which they run, installed at over 100 sites in all 30 NATO member countries.
 
Objectives:
The main objective of this Statement of Work (SOW) is to secure advisory services that provide expert guidance and support in SIEM (Splunk) infrastructure management and log collection.
 
Scope of work:
The aim of this SOW is to support NCSC with technical expertise specifically related to the operation and maintenance of CYBER SECURITY Support in SIEM (Splunk) infrastructure management and log collection with a deliverable based (completion-type) contract to be executed in 2025.
 
Vision and Expected Outcomes (Deliverables)
Under the direction of the CSDE Cell Head, SEC007 SDM or delegated authority, a contractor will be the part of the NCSC Team supporting the following activities:
Log collection
  • Manage log collection of new data log sources in SIEM which includes, but is not limited to, log ingestion process from various data sources located on premise or in the cloud, data mapping to Splunk Common Information Model, integration with existing Splunk data models, testing log ingestion, validating log ingestion quality with stakeholders.
  • Document all relevant information in Confluence in accordance with CSDE standards
  • Coordinate such activity with CSDE team and T3 customers
Outcome:
  • Assigned tasks shall be completed within the time allocated for this task by the requestor in the NCSC ticketing system(s). In case of an external request, the time to consider will be the time allocated by the CSDE cell  head, the SDM or one of their delegated authorities.
  • Quality of log collection shall be reviewed by Security Analysts and confirmed as in line with expectations in the ticket
Service availability and monitoring
  • Act as one of the engineers and Subject Matter Expert (SME) for SIEM and Log Collection services within the Cyber Security Data team
  • Monitoring the availability and performance of the SIEM environment including log collection
  • Detecting and reporting to SDM any service degradation
  • Taking appropriate actions to restore the environment to a fully operational state when a problem is detected.
  • Following best practices for maintaining the Splunk environment in a stable and reliable state with the objective of preventing any service degradation
  • Ensure that data security systems are installed, configured, and operating correctly and in line with dependencies with others systems or applications required
  • Ensure that data security systems operate within any KPI's, as defined in Service Level Agreements with NCSC customers
Outcome:
  • Service degradation must be detected in less than 2 hours during standard working hours. This measure will be based on the ticket creation time compared to the issue occurrence time.
  • Availability of the splunk environment must stay above 99.8% uptime in a fully operational state
  • SDM shall be informed by email less than 2 hours after problem occurrence. This shall be measured based on the information provided in the related ticket and time email has been sent.
Change management
  • Implement changes to the SIEM environment including but not limited to: software upgrades, new applications deployment, deploying new servers, modifying existing configuration of the SIEM environment, collecting new data sources, deploying new software.
  • Follow NCSC Change management process to get approval before implementing changes. This includes, but is not limited to, creating the change request, ensure all necessary information is provided in due diligence, following up the change request to ensure quick approval, attending to CAB meeting when necessary, providing impact assessment when required.
  • Coordinate all these changes with CSDE and external teams.
  • Develop and maintain documentation guidelines, standard operating procedures, system and service design documents and other relevant documentation that support management of the data security systems.
Outcome
  • Assigned tasks shall be completed within the time allocated for this task by the requestor in the NCSC ticketing system(s). In case of an external request, the time to consider will be the time allocated by the CSDE cell head, the SDM or one of their delegated authorities.
Reporting and advisory role
  • Attending meeting when there is a need for representing the cell, for providing technical advice or for reporting relevant information to the team or other stakeholders.
  • Reporting any relevant information to the cell head, the SDM or other team members.
Outcome:
  • Less than 1 working day after the meeting, an email containing the meeting minutes, all the relevant information and the required actions shall be sent to the relevant people including SDM and CSDE Cell Head.
  • Quality of the reporting to be assessed by the Cell Head or the SDM.
Providing support to customers
  • Provide support to customers (mainly security analysts but not limited to them) facing issues or needing technical assistance
Outcome:
  • Tickets should be closed within the time allocated by the Cell Head, the SDM or their delegated authorities
  • Problem resolution shall be confirmed by the requestor in the ticket
Practical Arrangements:
  • The services will be performed by a contractor on site at SHAPE Mons Belgium. The contractor will be required to work 100% onsite in Mons / BEL as part of this engagement. The NCSC Team is located in Mons / BEL
  • Services will be provided on site during standard working days/hours.
  • Exceptionally, the contractor will be on call (max limit : 1 week per month) for this position (e.g. NATO summit)
On-Call Rotation Schedule
  • The schedule will be defined during sprint planning and will outline who is responsible for on-call activities duties each week
  • On-call duty will cover critical issues outside working hours, including weekend and national holidays.
  • The Contractor would cover maximum 1 week per month
  • Security Classification: NATO Secret
  • Regular travel costs to and from main location of the work (SHAPE) are out of scope and will be borne by the contractor.
  • This work must be accomplished by one contractor.
  • The Purchaser will provide the contractor with the following Purchaser-Furnished Equipment (PFE): Access to NATO sites, as required, for the purpose of executing this SOW;  Workspace (needed business IT at NCSC facility); NCIA "REACH" laptop to be used by the contractor for the execution of the contract.
Requirements:
Security and non-disclosure agreement:
  • Any proposed resource providing services under this SOW must be in possession of a security clearance NATO SECRET or above. The signature of a Non-Disclosure Agreement between any Service Provider's individuals contributing to this task and NCIA will be required prior to execution.
Required Profile:
The contractor that is going to perform the identified tasks as an Operation and Maintenance Expert in SIEM (Splunk) infrastructure management and log collection must have demonstrated skills, knowledge and experience as listed below:
  • A good understanding of IT Security
  • At least 2 years of relevant experience and strong technical skills in administering, deploying, installing, configuring and maintaining large distributed Splunk Enterprise environment
  • Good programming skills in at least one of these languages: Ansible.python or bash
  • A good understanding of networking and various protocols such as TCP/IP, HTTP(S), DNS.
  • Very good knowledge and proven experience of Linux system and application administration and troubleshooting
  • Ability to work autonomously
  • Accuracy and attention to detail
  • Each team member shall be dressed suitably for meetings with high ranked officials
  • Strong reporting skills to various levels of seniority
  • Language Proficiency: A thorough knowledge of English language, both written and spoken, is essential.
  • Responsible for complying with all applicable local employment laws, in addition to following all SHAPE & NCIA on boarding procedures. Delivery of the service cannot begin until these requirements are fulfilled.
  • The service provider shall be required to provide services on NCIA working days

APPLY NOW

Share this job

Interested in this job?
Save Job
CREATE AS ALERT

Similar Jobs

SCHEMA MARKUP ( This text will only show on the editor. )