Public Key Infrastructure (PKI) Engineer (Project Post)
Job Summary
1. SUMMARY
The BICES Group Executive (BGX) a NATO entity is the executive body of the BICES Group (BG). The BG exists to enable the sharing and exchange of intelligence and information between and amongst NATO nations with NATO and with other non-NATO nations and organisations. Under the leadership of the Director BGX is composed of the Intelligence and Enterprise Services (IES) Division the Programmes Engineering and Maintenance (PEM) Division the Operations and Security Services (OSS) Division and the Intelligence Surveillance and Reconnaissance (ISR) Cell.
The core mission of the PEM Division is to provide the primary expertise to manage the BICES Programme develop improve and manage the lifecycle of IT capabilities and implement and maintain those capabilities. PEM champions all IT aspects with integrated expert team members from the other BGX Divisions. The PEM Division is directed by the Deputy Director for PEM and is composed of three Branches in direct support of the mission: Programme and Project Management Engineering and Enterprise Architecture (EEA) and Maintenance and Implementation.
The EEA Branch drives BICES IT coherence and modernisation and is responsible for leading the planning definition maintenance and governance of BICES architectural baselines service coherency technical designs standards and solutions to ensure coherent secure and interoperable enterprise capabilities. The Branch drives the development of CIS solutions based on requirements and modernisation aspects with a view to provide focus of the solution through architectures develop designs taking specific system requirements into account (e.g. cyber security operational) support transition of solutions into the system and provide service ownership.
Under the direction of the Head EEA Branch the PKI Engineer operates and maintains the BICES Enterprise Public Key Infrastructure (BEPKI) and is the service owner of the BEPKI. BEPKI comprises the organisational and technical aspects including roles policies hardware software and procedures used to manage the lifecycle of a medium-assurance asymmetric credential provider. The PKI Engineer advises integration of authentication integrity non-repudiation and confidentiality aspects to existing and upcoming operational services on BICES.
The incumbent installs configures maintains monitors and supports BEPKI systems including certification authority registration authority hardware security module directory certificate-status time-stamping and database services. S/He maintains the associated policies procedures accreditation evidence logs backups and performance information.
The incumbent provides second-level technical support investigates faults supports service modifications and integration and coordinates with vendors and external certification authority teams. S/He supports BICES exercises and missions and trains registration authority personnel in the correct operation of BEPKI services.
Operational travel may be required in accordance with the BG Deployment Policy and national requirements.
2. QUALIFICATIONS AND EXPERIENCE
Essential
University degree in Computer Science Computer Engineering Systems Engineering Mathematics or related discipline;
At least 3 years post-related experience;
Experience in operation and configuration of Information Security and Cryptography such as PKI based symmetric and asymmetric encryption hash functions digital signatures digital certificates PKI system development design and day-to-day management in complex IT environments with multiple domains;
Experience in management of certified/accredited PKI CA (deployment installation configuration and maintenance) solutions;
Experience in deployment installation configuration and maintenance of digital certificates auto-enrolment services and HSM;
Experience in the management of PKI RAs;
Experience in CIS certification and accreditation in complex IT environments;
Experience in certificate-based Multi-Factor Authentication (MFA) tokens and its integration in Windows Linux systems for user access;
Knowledge of the principles of computer and communications security networking and vulnerabilities of modern operating systems and applications;
Experience in drafting security policies including PKI related policies for complex IT environments;
Demonstrated experience of analysing and interpreting system security and application logs in order to diagnose faults and spot abnormal behaviours of the BICES PKI CA and related services;
Extensive experience in SSL TLS and OpenSSL.
Level V (Advanced) proficiency in the English language.
Desirable
Knowledge of and experience in the NATO security policy and the related directives;
Practical experience for Multi-Factor Authentication with use of PKI based user hardware tokens;
Practical experience in VMware and holding system administration certificates;
Knowledge of NATO PKI certificate policy and certification practice statement;
Prior experience of working in an international environment comprising both military and civilian elements;
Experience with on-premises PKI platforms such as Entrust Certificate Authority and/or Red Hat Certificate System;
Extensive experience in operating systems backup and restore;
Practical experience in scripting (PowerShell).
French Level II (Basic).
3. MAIN ACCOUNTABILITIES
Expertise Development
Maintain the technical expertise required for the reliable and secure operation of BEPKI services. Keep current with the PKI platforms cryptographic mechanisms operating systems directory services hardware security modules and protocols used within BEPKI. Apply established practices to resolve technical issues and support approved service improvements. Provide practical PKI guidance and training to registration authority personnel.
Knowledge Management
Maintain authoritative BEPKI operating knowledge to support consistent administration and service continuity. Draft and update security policies standard operating procedures certificate policy and certification practice statement documentation. Record technical solutions configuration guidance and lessons identified from service incidents testing exercises and audits. Make approved information available to personnel who operate or support BEPKI services. Support the integration of PKI enablers in user services in support of authentication integrity non-repudiation and confidentiality.
Information Management
Maintain complete and accurate BEPKI service information to support secure operations assurance and audit requirements. Monitor certification authority logs system alarms errors and user activity and investigate anomalous behaviour. Maintain configuration records accreditation documentation audit evidence and service-performance information. Report qualitative and quantitative service performance through agreed key performance indicators.
Organisational Efficiencies
Improve the reliability and efficiency of BEPKI operations through disciplined maintenance automation and problem resolution. Perform regular backups restoration tests upgrades database maintenance and other recurring administration. Analyse equipment software and configuration problems and propose sustainable technical solutions within the established service design. Use scripting and available administration tools to improve repeatability of operational measures and reduce avoidable operational overhead.
Planning and Execution
Operate and maintain BEPKI components in accordance with approved security configuration and service requirements. Install and configure certification authority hardware security module directory online certificate status protocol time-stamping database and related services. Prepare and execute test scenarios for backups restoration upgrades configuration changes and service enhancements. Prepare BEPKI systems and evidence for vulnerability assessments compliance audits accreditation activities exercises and missions.
Project Management
Support approved BEPKI modifications and capability changes by providing technical input estimates test results and implementation evidence. Coordinate assigned technical activities with vendors and other contributors identify dependencies and risks and report progress to the Head of Branch. Support the design and integration of new BEPKI components and third-party products while maintaining configuration control and service continuity. Contribute PKI expertise to relevant BGX programme and project activities.
Stakeholder Management
Provide responsive PKI support and coordination to sustain trusted certificate services across BICES. Deliver second-level technical support and work with BEPKI vendors to diagnose and resolve service issues. Manage the top-level BICES registration authority and provide technical guidance to other registration authorities. Coordinate with national root certification authority operation teams BEPKI entities BGX staff and other personnel engaged in related activities.
4. INTERRELATIONSHIPS
The incumbent reports to the Branch Head and receives technical guidance from the Principal Engineers for Security Systems and Network. S/He coordinates with staff across PEM IES OSS and the ISR Cell in support of BEPKI operations changes exercises missions assurance and service continuity. The incumbent maintains working relationships with BEPKI entities registration authorities national root certification authority operation teams vendors and personnel engaged in related or similar activities.
Direct reports: 0
Indirect reports: 0
5. COMPETENCIES
Achievement
Works to meet expected performance standards and deliver outputs within agreed timelines. Completes PKI maintenance testing documentation and incident-resolution activities within agreed service security and operational requirements.
Analytical Thinking
Breaks down problems and information to identify relationships patterns and logical conclusions. Analyses system security and application logs configuration data alarms and test results to diagnose PKI faults and identify appropriate corrective action.
Clarity and Accuracy
Communicates information in a clear and precise manner and checks work carefully for accuracy. Maintains accurate certificate policies procedures configuration records accreditation evidence and technical reports recognising that errors may affect trust services across BICES.
Customer Service Orientation
Responds constructively to the needs and requests of internal and external users in support of service quality and mission needs. Provides timely second-level support practical guidance and training to BEPKI users and registration authorities while setting clear expectations for issue resolution.
Initiative
Takes action within own area of responsibility to address issues and improve results without waiting to be told. Investigates emerging service equipment and configuration problems proposes corrective measures and improves recurring administration through approved tools and automation.
Teamwork
Works cooperatively with others to achieve shared goals and supports a positive and collaborative team environment. Coordinates constructively with BGX staff vendors national certification authority teams and registration authority personnel during maintenance testing exercises audits and incident resolution.
6. CONTRACT
Contract to be offered to the successful applicant (if non-seconded): Definite Duration contract of three years.
Contract clause applicable:
This post is a limited duration project post. The first 6 months of the contract will be considered as probationary the successful candidate is seconded from the national administration of one of NATOs member States a three-year definite duration contract will be offered.
Serving staff will be offered a contract in accordance with the NATO Civilian Personnel Regulations.
7. USEFUL INFORMATION REGARDING APPLICATION AND RECRUITMENT PROCESS
Please note that we can only accept applications from nationals of NATO member must be submitted using e-recruitment system as applicable:
For NATO civilian staff members only: please apply via the internal recruitment portal (link);
For all other applications: you apply to any position we encourage you to click here and watch our video providing 6 tips to prepare you for your application and recruitment process.
Do you have questions on the application process in the system and not sure how to proceed Click here for a video containing the information you need to successfully submit your application on time.
When submitting your application please ensure that your Taleo Candidate Profile is updated and that your CV is correctly uploaded in the Taleo attachments section.
More information about the recruitment process and conditions of employment can be found at our website ( will be subject to receipt of asecurity clearance(provided by the national Authorities of the selected candidate) approval of the candidatesmedical fileby the NATO Medical Adviser verification of your study(ies) and work experience and the successful completion of theaccreditationand notification process by the relevant authorities.
NATO will not accept any phase of the recruitment and selection prepared in whole or in part by means of reference documents without proper quotes (plagiarism) or any tools available on internet including but not limited to translation facilities or generative artificial-intelligence (AI) tools. NATO reserves the right to screen applications to identify the use of such tools. All applications prepared in whole or in part by means of such tools will be rejected without further consideration and NATO reserves the right to take further steps in such cases as appropriate.
8. ADDITIONAL INFORMATION
NATO is committed to diversity and inclusion and strives to provide equal access to employment advancement and retention independent of gender age nationality ethnic origin religion or belief cultural background sexual orientation and disability. NATO welcomes applications of nationals from all member Nations and strongly encourages women to apply.
NATO is committed to fostering an inclusive and accessible working environment where all candidates living with disabilities can fully participate in the recruitment and selection process. If you require reasonable accommodation please inform us during your selection process.
Candidates will be required to provide documented medical evidence to support their request for accommodation.
Building Integrity is a key element of NATOs core tasks. As an employer NATO values commitment to the principles of integrity transparency and accountability in accordance with international norms and practices established for the defence and related security sector. Selected candidates are expected to be role models of integrity and to promote good governance through ongoing efforts in their work.
Applicants who are not successful in this competition may be offered an appointment to another post of a similar nature albeit at the same or a lower grade provided they meet the necessary requirements.
The nature of this position may require the staff member at times to be called upon to travel for work and/or to work outside normal office hours.
For information about the NATO Single Salary Scale (Grading Allowances etc.) please visit ourwebsite. Detailed data is available under the Salary and Benefits tab.
NATO does not charge any application processing training interviewing testing or other fee in connection with the application or recruitment process. For more info please click here.
Required Experience:
IC