Overslaan naar inhoud

Sollicitatieformulier

Provide either a resume file or a linkedin profile
Functieomschrijving
Vacature
KCSM OPS Engineer (SRQ158174)
Locatie
--BNP PARIBAS FORTIS SA/NV--
Afdeling
BNP / Prod Sec. - Operational Security Eng 1 - Francesco Di Ciccio

Join our Key, Certificate, and Key Management squad within the Production Security BE tribe! We’re a team of about 15 experts based in Belgium, specializing in the lifecycle management of cryptographic keys, certificates (internal/group/public), and application secrets (via Hashicorp Vault).

Our mission? To secure electronic transactions, authentications, and cloud-hosted applications while ensuring full compliance with EU/Group regulations (e.g. PSD2, PCI) and industry standards.

As part of the broader System Security Cluster, we operate and support Hardware Security Modules (HSMs) like Adyton and nCipher, enabling a trustworthy environment for both internal and external customers. Innovation drives us; we’re the go-to partners for stakeholders, delivering cost-efficient, reliable security solutions that keep the bank and its clients safe.

1. Operations

  • Manage the lifecycle of cryptographic keys, digital certificates, and application secrets (e.g., rotation, revocation, access control).
  • Monitor and maintain HSM infrastructures (Adyton, nCipher, mainframe TKE) to ensure high availability and compliance.
  • Troubleshoot incidents and collaborate with teams to resolve security gaps in authentication, encryption, or secret storage.

2. Expertise & Projects

  • Act as a Crypto Design Authority (Advise on cryptographic standards, algorithms, and best practices (e.g., NIST, PCI-DSS, PSD2)).
  • Lead or contribute to strategic projects, including:
    • Post-Quantum Cryptography (Assess risks, contribute to the migration of quantum resistant solutions)
    • EKU Readiness (Prepare systems for Extended Key Usage (EKU) compliance)
    • HSM Lifecycle Management (LCM) (Operate HSM support and configuration)
    • HSM : Key Ceremonies
    • Crypto Agility: Improve certificate and key lifecycle mgmt. processes
    • Platform Integration: Align with Group tools (Certis, Horizon)
  • Partner with COE Security, Group Security and other stakeholders like IT architects, IT application owners to translate regulatory and business requirements into technical solutions.

Language requirements

  • Dutch A plus
  • French Fluent spoken
  • English Fluent spoken and written

Telework

Expectation: 50% on site & 50% homeworking

Experience and skills

  • At least 5 years of relevant experience
  • Deep IT security expertise
  • Your foundation is technical mastery of HSMs (Adyton/nCipher), PKI, Hashicorp Vault, and cryptographic standards (NIST), paired with sharp operational oversight of high-availability infrastructures.
  • Technical experience Microsoft Office (Word, Excel and Powerpoint)
  • Scripting (Python, Bash, ?), preferable ServiceNow, Rally, Portunus, Adyton, nCipher, HashiCorpVault
  • Bridging tech and business: You turn abstract security requirements (e.g., from COE experience / Security) into feasible IT solutions, balancing cost efficiency, compliance, and developer practicality.
  • Agile in action: In a fast-evolving landscape (e.g., crypto-agility, IoT onboarding automation), you anticipate change, prioritize flexibly, and contribute to iterative enhancements; without compromising production stability.
  • Collaboration and results drive you: You work closely with stakeholders (IT architects, application owners, COE & Group Security) to deliver tangible security solutions that meet both business needs and regulatory demands; without losing sight of operational realities.
  • Client-centric by design: Whether supporting internal teams or external partners, you translate complex cryptographic requirements (e.g., PSD2, PCI-DSS) into practical, user-friendly implementations that ensure trust and compliance.

Soft skills

  • Proactive and analytical: Beyond spotting risks (e.g. in post-quantum cryptography or EKU readiness), you proactively enhance processes (e.g. improving key and certificate rotation protocols).