Public Key Infrastructure

Il y a 18 heures

Ixelles, Brussels, Belgique NATO-OTAN Temps plein
Description1. SUMMARYThe BICES Group Executive (BGX), a NATO entity, is the executive body of the BICES Group (BG). The BG exists to enable the sharing and exchange of intelligence and information between and amongst NATO nations, with NATO and with other non-NATO nations and organisations. Under the leadership of the Director, BGX is composed of the Intelligence and Enterprise Services (IES) Division, the Programmes, Engineering and Maintenance (PEM) Division, the Operations and Security Services (OSS) Division and the Intelligence, Surveillance and Reconnaissance (ISR) Cell.
The core mission of the PEM Division is to provide the primary expertise to manage the BICES Programme, develop, improve and manage the lifecycle of IT capabilities, and implement and maintain those capabilities. PEM champions all IT aspects with integrated expert team members from the other BGX Divisions. The PEM Division is directed by the Deputy Director for PEM and is composed of three Branches in direct support of the mission: Programme and Project Management, Engineering and Enterprise Architecture (EEA), and Maintenance and Implementation.
The EEA Branch drives BICES IT coherence and modernisation, and is responsible for leading the planning, definition, maintenance, and governance of BICES architectural baselines, service coherency, technical designs, standards, and solutions to ensure coherent, secure, and interoperable enterprise capabilities. The Branch drives the development of CIS solutions, based on requirements and modernisation aspects with a view to provide focus of the solution through architectures, develop designs taking specific system requirements into account (e.
G. cyber security, operational), support transition of solutions into the system and provide service ownership.
Under the direction of the Head EEA Branch, the PKI Engineer operates and maintains the BICES Enterprise Public Key Infrastructure (BEPKI) and is the service owner of the BEPKI. BEPKI comprises the organisational and technical aspects including roles, policies, hardware, software, and procedures used to manage the lifecycle of a medium-assurance asymmetric credential provider. The PKI Engineer advises integration of authentication, integrity, non-repudiation and confidentiality aspects to existing and upcoming operational services on BICES.
The incumbent installs, configures, maintains, monitors, and supports BEPKI systems, including certification authority, registration authority, hardware security module, directory, certificate-status, time-stamping, and database services. S/He maintains the associated policies, procedures, accreditation evidence, logs, backups, and performance information.
The incumbent provides second-level technical support, investigates faults, supports service modifications and integration, and coordinates with vendors and external certification authority teams. S/He supports BICES exercises and missions and trains registration authority personnel in the correct operation of BEPKI services.
Operational travel may be required in accordance with the BG Deployment Policy and national requirements.2. QUALIFICATIONS AND EXPERIENCEEssentialUniversity degree in Computer Science, Computer Engineering, Systems Engineering, Mathematics or related discipline; At least 3 years post-related experience; Experience in operation and configuration of Information Security and Cryptography, such as PKI based symmetric and asymmetric encryption, hash functions, digital signatures, digital certificates, PKI system development, design and day-to-day management in complex IT environments with multiple domains; Experience in managementof certified/accredited PKI CA (deployment, installation, configuration and maintenance) solutions; Experience in deployment, installation, configuration and maintenance of digital certificates, auto-enrolment services, and HSM; Experience in the management of PKI RAs; Experience in CIS certification and accreditation in complex IT environments; Experience in certificate-based Multi-Factor Authentication (MFA) tokens and its integration in Windows, Linux systems for user access; Knowledge of the principles of computer and communications security, networking, and vulnerabilities of modern operating systems and applications; Experience in drafting security policies, including PKI related policies for complex IT environments; Demonstrated experience of analysing and interpreting system, security and application logs in order to diagnose faults and spot abnormal behaviours of the BICES PKI CA and related services; Extensive experience in SSL, TLS, and OpenSSL.
Level V (Advanced) proficiency in the English language.
DesirableKnowledge of and experience in the NATO security policy and the related directives; Practical experience forMulti-Factor Authentication with use of PKI based user hardware tokens; Practical experience in VMware and holding system administration certificates; Knowledge of NATO PKI certificate policy and cer