Formulaire de recrutement
KCSM OPS Engineer (SRQ158174)
--BNP PARIBAS FORTIS SA/NV--
BNP / Prod Sec. - Operational Security Eng 1 - Francesco Di Ciccio
Join our Key, Certificate, and Key Management squad within the Production Security BE tribe! We’re a team of about 15 experts based in Belgium, specializing in the lifecycle management of cryptographic keys, certificates (internal/group/public), and application secrets (via Hashicorp Vault).
Our mission? To secure electronic transactions, authentications, and cloud-hosted applications while ensuring full compliance with EU/Group regulations (e.g. PSD2, PCI) and industry standards.
As part of the broader System Security Cluster, we operate and support Hardware Security Modules (HSMs) like Adyton and nCipher, enabling a trustworthy environment for both internal and external customers. Innovation drives us; we’re the go-to partners for stakeholders, delivering cost-efficient, reliable security solutions that keep the bank and its clients safe.
1. Operations
- Manage the lifecycle of cryptographic keys, digital certificates, and application secrets (e.g., rotation, revocation, access control).
- Monitor and maintain HSM infrastructures (Adyton, nCipher, mainframe TKE) to ensure high availability and compliance.
- Troubleshoot incidents and collaborate with teams to resolve security gaps in authentication, encryption, or secret storage.
2. Expertise & Projects
- Act as a Crypto Design Authority (Advise on cryptographic standards, algorithms, and best practices (e.g., NIST, PCI-DSS, PSD2)).
- Lead or contribute to strategic projects, including:
- Post-Quantum Cryptography (Assess risks, contribute to the migration of quantum resistant solutions)
- EKU Readiness (Prepare systems for Extended Key Usage (EKU) compliance)
- HSM Lifecycle Management (LCM) (Operate HSM support and configuration)
- HSM : Key Ceremonies
- Crypto Agility: Improve certificate and key lifecycle mgmt. processes
- Platform Integration: Align with Group tools (Certis, Horizon)
- Partner with COE Security, Group Security and other stakeholders like IT architects, IT application owners to translate regulatory and business requirements into technical solutions.
Language requirements
- Dutch A plus
- French Fluent spoken
- English Fluent spoken and written
Telework
Expectation: 50% on site & 50% homeworking
Experience and skills
- At least 5 years of relevant experience
- Deep IT security expertise
- Your foundation is technical mastery of HSMs (Adyton/nCipher), PKI, Hashicorp Vault, and cryptographic standards (NIST), paired with sharp operational oversight of high-availability infrastructures.
- Technical experience Microsoft Office (Word, Excel and Powerpoint)
- Scripting (Python, Bash, ?), preferable ServiceNow, Rally, Portunus, Adyton, nCipher, HashiCorpVault
- Bridging tech and business: You turn abstract security requirements (e.g., from COE experience / Security) into feasible IT solutions, balancing cost efficiency, compliance, and developer practicality.
- Agile in action: In a fast-evolving landscape (e.g., crypto-agility, IoT onboarding automation), you anticipate change, prioritize flexibly, and contribute to iterative enhancements; without compromising production stability.
- Collaboration and results drive you: You work closely with stakeholders (IT architects, application owners, COE & Group Security) to deliver tangible security solutions that meet both business needs and regulatory demands; without losing sight of operational realities.
- Client-centric by design: Whether supporting internal teams or external partners, you translate complex cryptographic requirements (e.g., PSD2, PCI-DSS) into practical, user-friendly implementations that ensure trust and compliance.
Soft skills
- Proactive and analytical: Beyond spotting risks (e.g. in post-quantum cryptography or EKU readiness), you proactively enhance processes (e.g. improving key and certificate rotation protocols).