Background:

Following up on previous successful cybercrime-related capacity-building activities implemented in 2023, 2024, and 2025, and based on consultations and a needs assessment received from the Kosovo Police in 2025, the OSCE Mission in Kosovo (the OSCE), through the Serious and Organized Crime Section’s (SOCS) Unified Budget (UB) project “Strengthening capacities of local law enforcement institutions to tackle serious and organized crime and violent extremism (Phase VI)” (Project No. 2101288), will organize Activity 2.2.2,  Training on Cloud Security Attacker Techniques, Monitoring and Threat Detection.

The four-day training, scheduled from 22 to 25 September 2026, will bring together 17 representatives from the Kosovo Police and the Prosecutor’s Office. The activity aims to strengthen participants’ capacity to identify, analyse, and respond to cyber threats targeting cloud environments, while enhancing their understanding of attacker techniques commonly used against modern cloud infrastructures. Particular emphasis will be placed on cloud security monitoring, threat detection methodologies, incident response procedures, and the legal considerations associated with handling digital evidence stored in cloud environments.

The training will further strengthen co-operation and information exchange between investigators and prosecutors involved in cybercrime investigations, contributing to a more co-ordinated and effective institutional response to cyber-enabled and cyber-dependent crimes. Through a combination of theoretical instruction and practical exercises, participants will develop the technical and analytical competencies required to detect malicious activities, investigate cloud-based incidents, and support the collection and preservation of digital evidence originating from cloud platforms.

The added value of the expert lies in their advanced knowledge and practical experience in cloud security, cyber threat detection, incident response, and cybercrime investigations. The expert will provide participants with specialized expertise on attacker methodologies, cloud monitoring tools, threat-hunting techniques, and investigative approaches applicable to cloud-based environments. By delivering both conceptual and hands-on training, the expert will support the development of sustainable institutional capacities within the Kosovo Police and Prosecutor’s Office, enabling participants to effectively investigate cyber incidents involving modern cloud infrastructure.

The OSCE will engage an international expert with extensive experience in cloud security, cyber threat detection, incident response, and digital investigations to design and deliver the training programme. The expert will be responsible for providing practical and scenario-based instruction tailored to the operational needs of participating institutions and aligned with internationally recognized cyber security and digital investigation standards.

Objective of Assignment: 

Strengthen the knowledge and practical skills of representatives from the Kosovo Police and the Prosecutor’s Office in identifying, monitoring, detecting, and responding to cyber threats targeting cloud environments.

This will be achieved by enhancing their ability to understand attacker techniques, conduct cloud-based investigations, handle and preserve cloud-stored digital evidence in accordance with legal and forensic requirements, and support effective incident response activities.

Promote closer operational co-operation between investigators and prosecutors, contributing to more effective cybercrime investigations and prosecutions involving modern cloud infrastructure and cloud-enabled criminal activities.

Duration of Assignment:

The Consultant will be hired for 5 working days.

Tasks and Responsibilities:

  • Develop the training methodology and materials in consultation with the OSCE activity manager, including the agenda, presentations, case studies, and pre and post-training survey questions.
  • Revise and finalize the training materials on Cloud Security Attacker Techniques, Monitoring and Threat Detection based on SOCS feedback.
  • Deliver a four-day training for 17 participants on Cloud Security Attacker Techniques, Monitoring and Threat Detection.
  • Prepare and deliver the final report. 


Deliverables:

  • By 9 September 2026, develop and submit the training agenda, presentations, case studies, pre-training survey questions, and other relevant training materials to the OSCE activity manager for review and approval, including any required amendments. 

    Performance Indicator: Training materials are submitted on time and meet the quality standards agreed with the activity manager.

  • By 14 September 2026, incorporate SOCS comments and submit the final training package to the OSCE activity manager for approval. 

    Performance Indicator: All comments provided by SOCS are duly addressed and fully integrated into the final training materials submitted for approval.

  • From 22 to 25 September 2026, successfully deliver a four-day training for 17 participants from the Kosovo Police and the Prosecutor’s Office. 

    Performance Indicator - Training delivered as scheduled, in the agreed format, and in line with the requirements of the activity manager.

  • By 2 October 2026, submit a final report to the OSCE activity manager summarizing the training delivered, key observations, identified capacity gaps, lessons learned, and recommendations for future activities. 

    Performance Indicator - A concise, analytical, and high-quality final report submitted within the agreed timeline.

Necessary Qualifications:

  • University degree in Cyber Security, Computer Science, Information Technology, Digital Forensics, Information Security, Law Enforcement, Criminal Investigation, or a related field. A first-level university degree combined with extensive relevant professional experience may be accepted in lieu of an advanced degree;
  • Minimum of eight (8) years of professional experience in cyber security, cybercrime investigations, cloud security, threat detection, security monitoring, incident response, or related fields;
  • At least four (4) years of practical experience in cloud security operations, cyber threat detection, incident response, threat hunting, cyber investigations, or related operational cyber security functions;
  • Demonstrated expertise in identifying, analysing, monitoring, and responding to cyber threats targeting cloud-based environments and modern information systems;
  • Proven experience in designing and delivering specialized training programmes on cloud security, attacker techniques, threat detection, security monitoring, incident response, cyber investigations, or related cyber security topics for law enforcement, prosecutorial, or governmental institutions;
  • Experience working with law enforcement agencies, prosecutors, judicial institutions, or national cyber security authorities on cybercrime, cyber security, or digital evidence matters is considered a strong asset;
  • Fluency in English; knowledge of Albanian and/or Serbian is an additional asset;
  • Strong communication and presentation skills, including the ability to deliver practical and scenario-based training to adult learners;
  • Demonstrated cultural sensitivity, sound professional judgment, and ability to work effectively in a multicultural environment.

Remuneration Package:

Remuneration will be based on the selected consultant's/expert's qualifications, experience, the tasks and deliverables for this position and in accordance with the OSCE established rates.


In order to apply for this position, you must complete the OSCE's online application form, found under OSCE Careers- Jobs. Applicants are encouraged to use the online recruitment and only fully completed OSCE applications will be accepted. However, if you have technical difficulties with the system, you may use the offline application form found at Offline application form | OSCE Employment and forward the completed form quoting the vacancy number by email to: consultancy.omik@osce.org. In line with your qualifications please indicate a preference for one or more fields of expertise listed above (while using the online application the field of expertise preference can be indicated in the cover letter part). Kindly note that applications received after the deadline, submitted in different formats than the OSCE Application Form or other languages than the English language would not be considered. The OSCE is committed to diversity and inclusion within its workforce and encourages qualified female and male candidates from all national, religious, ethnic, and social backgrounds to apply.

Additional Information
  • Issued by: OSCE Mission in Kosovo
  • Requisition ID: KOS000509
  • Contract Type: Special Service Agreement (SSA) / Consultant
  • Grade: No grade
  • Job Type: Consultant
  • Number of posts: one
  • Location: KOS - OSCE Mission in Kosovo, Prishtine / Pristina
  • Issue Date: Aug 13, 2026
  • Closing Date: Aug 27, 2026
  • Education Level: Bachelor's Degree (First-level university degree or equivalent)
  • Target Start Date: As soon as possible

At Impactpool we do our best to provide you the most accurate info, but closing dates may be wrong on our site. Please check on the recruiting organization's page for the exact info. Candidates are responsible for complying with deadlines and are encouraged to submit applications well ahead.
Before applying, please make sure that you have read the requirements for the position and that you qualify. Applications from non-qualifying applicants will most likely be discarded by the recruiting manager.