Public Key Infrastructure (PKI) Engineer (Project Post)
North Atlantic Treaty Organization
- Location:
- Brussels, Belgium
- Grade:
- NATO Grade G15
- Category:
- Professional Staff
Posted Aug 21, 2026Apply by Sep 27, 2026 (35d left)
See your match score & applyThe PKI Engineer operates and maintains the BICES Enterprise Public Key Infrastructure (BEPKI) and is the service owner of the BEPKI. The role involves installation, configuration, maintenance, monitoring, and support of BEPKI systems including certification authority, registration authority, hardware security module, directory, certificate-status, time-stamping, and database services. The incumbent provides second-level technical support, investigates faults, supports service modifications and integration, and coordinates with vendors and external certification authority teams.
Responsibilities
- Maintain the technical expertise required for the reliable and secure operation of BEPKI services
- Keep current with the PKI platforms, cryptographic mechanisms, operating systems, directory services, hardware security modules, and protocols used within BEPKI
- Apply established practices to resolve technical issues and support approved service improvements
- Provide practical PKI guidance and training to registration authority personnel
- Maintain authoritative BEPKI operating knowledge to support consistent administration and service continuity
- Draft and update security policies, standard operating procedures, certificate policy, and certification practice statement documentation
- Record technical solutions, configuration guidance, and lessons identified from service incidents, testing, exercises, and audits
- Make approved information available to personnel who operate or support BEPKI services
- Support the integration of PKI enablers in user services in support of authentication, integrity, non-repudiation and confidentiality
- Maintain complete and accurate BEPKI service information to support secure operations, assurance, and audit requirements
- Monitor certification authority logs, system alarms, errors, and user activity, and investigate anomalous behaviour
- Maintain configuration records, accreditation documentation, audit evidence, and service-performance information
- Report qualitative and quantitative service performance through agreed key performance indicators
- Improve the reliability and efficiency of BEPKI operations through disciplined maintenance, automation, and problem resolution
- Perform regular backups, restoration tests, upgrades, database maintenance, and other recurring administration
- Analyse equipment, software, and configuration problems and propose sustainable technical solutions within the established service design
- Use scripting and available administration tools to improve repeatability of operational measures and reduce avoidable operational overhead
- Operate and maintain BEPKI components in accordance with approved security, configuration, and service requirements
- Install and configure certification authority, hardware security module, directory, online certificate status protocol, time-stamping, database, and related services
- Prepare and execute test scenarios for backups, restoration, upgrades, configuration changes and service enhancements
- Prepare BEPKI systems and evidence for vulnerability assessments, compliance audits, accreditation activities, exercises, and missions
- Support approved BEPKI modifications and capability changes by providing technical input, estimates, test results, and implementation evidence
- Coordinate assigned technical activities with vendors and other contributors, identify dependencies and risks, and report progress to the Head of Branch
- Support the design and integration of new BEPKI components and third-party products while maintaining configuration control and service continuity
- Contribute PKI expertise to relevant BGX programme and project activities
- Provide responsive PKI support and coordination to sustain trusted certificate services across BICES
- Deliver second-level technical support and work with BEPKI vendors to diagnose and resolve service issues
- Manage the top-level BICES registration authority and provide technical guidance to other registration authorities
- Coordinate with national root certification authority operation teams, BEPKI entities, BGX staff, and other personnel engaged in related activities
Requirements
- University degree in Computer Science, Computer Engineering, Systems Engineering, Mathematics or related discipline
- At least 3 years post-related experience
- Experience in operation and configuration of Information Security and Cryptography, such as PKI based symmetric and asymmetric encryption, hash functions, digital signatures, digital certificates, PKI system development, design and day-to-day management in complex IT environments with multiple domains
- Experience in management of certified/accredited PKI CA (deployment, installation, configuration and maintenance) solutions
- Experience in deployment, installation, configuration and maintenance of digital certificates, auto-enrolment services, and HSM
- Experience in the management of PKI RAs
- Experience in CIS certification and accreditation in complex IT environments
- Experience in certificate-based Multi-Factor Authentication (MFA) tokens and its integration in Windows, Linux systems for user access
- Knowledge of the principles of computer and communications security, networking, and vulnerabilities of modern operating systems and applications
- Experience in drafting security policies, including PKI related policies for complex IT environments
- Demonstrated experience of analysing and interpreting system, security and application logs in order to diagnose faults and spot abnormal behaviours of the BICES PKI CA and related services
- Extensive experience in SSL, TLS, and OpenSSL
- Level V (Advanced) proficiency in the English language
- Knowledge of and experience in the NATO security policy and the related directives
- Practical experience for Multi-Factor Authentication with use of PKI based user hardware tokens
- Practical experience in VMware and holding system administration certificates
- Knowledge of NATO PKI certificate policy and certification practice statement
- Prior experience of working in an international environment comprising both military and civilian elements
- Experience with on-premises PKI platforms such as Entrust Certificate Authority and/or Red Hat Certificate System
- Extensive experience in operating systems backup and restore
- Practical experience in scripting (PowerShell)
- French Level II (Basic)
Skills
- Public Key Infrastructure
- PKI System Development
- PKI CA Management
- Digital Certificate Management
- Auto-enrolment Services
- Hardware Security Module
- PKI RA Management
- CIS Certification and Accreditation
- Multi-Factor Authentication Integration
- Network Security Principles
- Communications Security
- Network Security
- Security Policy Drafting
- System Log Analysis
- Security Log Analysis
- SSL
- TLS
- OpenSSL
- NATO Security Policies
- VMware
- System Administration
- Entrust Certificate Authority
- Red Hat Certificate System
- Operating Systems Backup
- Operating Systems Restore
- PowerShell Scripting
Languages
English, French