PKI Infrastructure Specialist
Mons, Belgium
Full Time Mid-level / Intermediate Clearance required EUR 34K - 79K * est.
Spektrum have a wide range of exciting opportunities in several global locations.
We are always looking to add great new talent to our team and look forward to hearing from you.
Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.
Who we are supporting
The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.
The NCIA provides a wide range of services, including:
- Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.
- Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.
- Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
- Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.
- Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers.
Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities.
The program
Assistance and Advisory Service (AAS)
The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.
To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.
Role Duties and Responsibilities
- Lead the design, implementation, and continuous improvement of enterprise PKI solutions, including Certificate Authorities (CAs), Registration Authorities (RAs), and Hardware Security Modules (HSMs).
- Define and enforce PKI security policies, standards, and best practices to align with NATO policy and industry requirements.
- Develop a strategic roadmap for PKI evolution, including cloud- based cryptographic services and post-quantum cryptography readiness.
- Proven ability to define and execute PKI strategies at an enterprise level.
- Strong analytical and problem-solving skills with a risk-based approach to security.
- Excellent communication skills to engage both technical and executive stakeholders.
- Experience in mentoring teams and driving security best practices across project teams.
Operational Duties
- Install, configure and maintain the day-to-day NATO wide PKI systems and components;
- Install, configure and maintain NATO PKI (NPKI) virtualized infrastructure;
- Install, configure and maintain NPKI networking components;
- Install, configure and maintain NPKI hardware infrastructure;
- Install, configure and maintain NPKI LDAP directory service and support HTTP service;
- Responsible for Enterprise Mobile Mobility configuration, integration, maintenance;
- Responsible for LDAP directory service configuration and maintenance;
- Responsible for Online Certificate Status Protocol (OCSP) and Time Stamp management;
- Responsible for Database maintenance, dedicated for NPKI;
- Responsible for Card Management System deployment, integration and day-to-day management;
- Responsible for Hardware Security Module (HSM) firmware upgrade and management;
- Responsible for the creation of PKI related guidance;
- Certificate Authority Log analysis, (Troubleshoot the system ALARM/ERRORS and monitor user activity);
- Support Smart Card enrolment and certificate creation process;
- Maintain the day-to-day operations /management /backup/restore of the PKI systems;
- Provide technical support and assistance to ITM Operating Authorities and NPKI-Mitigation project team;
- Provide 2nd and 3rd level technical support of CIS services to the NPKI customers;
- Designing of new PKI components;
- Responsible for the creation and maintenance of Standard Operating Procedures within the NPKI as part of modifications or additions to current capabilities;
- Documenting of all new PKI services;
- Installation and maintenance of NPKI components;
- Be flexible to work outside normal office hours in response to crises, operational requirements;
Essential Skills and Experience
- Extensive knowledge of modern communication and Internet Protocol (IP) based networking technologies and systems including security aspects.
- 5 years extensive experience with PKI System development, design, management.
- Extensive knowledge of Information security and Cryptography (symmetric and asymmetric encryption, public key infrastructure (PKI) encryption, public key encryption, hash functions, digital signatures, digital certificates).
- Working knowledge of router and switches configuration.
- Practical experience in Windows Servers, RHEL and VMware system administration.
- Knowledge of the principles of computer and communications security, networking, and vulnerabilities of modern operating systems and applications.
- Experience with SQL database administration.
- Extensive experience in operating systems backup and restore.
- Practical experience in scripting (Python, Powershell).
- Practical experience in SSL, TLS, and OpenSSL.
Desirable Skills and Experience
- VMware (VCA, VCP) and Linux RHEL system administration
- CISCO CCNA
- Microsoft Certified Solution Associate (MCSA).
- Microsoft Certified Solutions Expert (MCSE).
- Experience in development and implementation of computer security policies.
Working Location
- Mons, Belgium
Working Policy
- On-Site
Travel
- Some travel to other NATO sites may be required
Security Clearance
- Valid National or NATO Secret personal security clearance
We never know what new opportunities might be just over the horizon. If this opportunity isn't for you please feel free to send us your resume anyway and be the first to know if something suitable for your skills and experience comes up.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Clearance Cloud Cryptography Encryption LDAP Linux Log analysis NATO PKI PowerShell Python Scripting Security Clearance SQL TLS VMware Vulnerabilities Windows
Perks/benefits: Career development Flex hours
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.