1. SUMMARY
The BICES Group Executive (BGX), a NATO entity, is the executive body of the BICES Group (BG). The BG exists to enable the sharing and exchange of intelligence and information between and amongst NATO nations, with NATO and with other non-NATO nations and organisations. Under the leadership of the Director, BGX is composed of the Intelligence and Enterprise Services (IES) Division, the Programmes, Engineering and Maintenance (PEM) Division, the Operations and Security Services (OSS) Division and the Intelligence, Surveillance and Reconnaissance (ISR) Cell.
The core mission of the PEM Division is to provide the primary expertise to manage the BICES Programme, develop, improve and manage the lifecycle of IT capabilities, and implement and maintain those capabilities. PEM champions all IT aspects with integrated expert team members from the other BGX Divisions. The PEM Division is directed by the Deputy Director for PEM and is composed of three Branches in direct support of the mission: Programme and Project Management, Engineering and Enterprise Architecture (EEA), and Maintenance and Implementation.
The EEA Branch drives BICES IT coherence and modernisation, and is responsible for leading the planning, definition, maintenance, and governance of BICES architectural baselines, service coherency, technical designs, standards, and solutions to ensure coherent, secure, and interoperable enterprise capabilities. The Branch drives the development of CIS solutions, based on requirements and modernisation aspects with a view to provide focus of the solution through architectures, develop designs taking specific system requirements into account (e.g. cyber security, operational), support transition of solutions into the system and provide service ownership.
Under the direction of the Head EEA Branch, the PKI Engineer operates and maintains the BICES Enterprise Public Key Infrastructure (BEPKI) and is the service owner of the BEPKI. BEPKI comprises the organisational and technical aspects including roles, policies, hardware, software, and procedures used to manage the lifecycle of a medium-assurance asymmetric credential provider. The PKI Engineer advises integration of authentication, integrity, non-repudiation and confidentiality aspects to existing and upcoming operational services on BICES.
The incumbent installs, configures, maintains, monitors, and supports BEPKI systems, including certification authority, registration authority, hardware security module, directory, certificate-status, time-stamping, and database services. S/He maintains the associated policies, procedures, accreditation evidence, logs, backups, and performance information.
The incumbent provides second-level technical support, investigates faults, supports service modifications and integration, and coordinates with vendors and external certification authority teams. S/He supports BICES exercises and missions and trains registration authority personnel in the correct operation of BEPKI services.
Operational travel may be required in accordance with the BG Deployment Policy and national requirements.
2. QUALIFICATIONS AND EXPERIENCE
Essential
University degree in Computer Science, Computer Engineering, Systems Engineering, Mathematics or related discipline;
At least 3 years post-related experience;
Experience in operation and configuration of Information Security and Cryptography, such as PKI based symmetric and asymmetric encryption, hash functions, digital signatures, digital certificates, PKI system development, design and day-to-day management in complex IT environments with multiple domains;
Experience in management of certified/accredited PKI CA (deployment, installation, configuration and maintenance) solutions;
Experience in deployment, installation, configuration and maintenance of digital certificates, auto-enrolment services, and HSM;
Experience in the management of PKI RAs;
Experience in CIS certification and accreditation in complex IT environments;
Experience in certificate-based Multi-Factor Authentication (MFA) tokens and its integration in Windows, Linux systems for user access;
Knowledge of the principles of computer and communications security, networking, and vulnerabilities of modern operating systems and applications;
Experience in drafting security policies, including PKI related policies for complex IT environments;
Demonstrated experience of analysing and interpreting system, security and application logs in order to diagnose faults and spot abnormal behaviours of the BICES PKI CA and related services;
Extensive experience in SSL, TLS, and OpenSSL.
Level V (Advanced) proficiency in the English language.
Desirable
Knowledge of and experience in the NATO security policy and the related directives;
Practical experience for Multi-Factor Authentication with use of PKI based user hardware tokens;
Practical experience in VMware and holding system administration certificates;
Knowledge of NATO PKI certificate policy and certification practice statement;
Prior experience of working in an international environment comprising both military and civilian elements;
Experience with on-premises PKI platforms such as Entrust Certificate Authority and/or Red Hat Certificate System;
Extensive experience in operating systems backup and restore;
Practical experience in scripting (PowerShell).
French Level II (Basic).
3. MAIN ACCOUNTABILITIES
Expertise Development
Maintain the technical expertise required for the reliable and secure operation of BEPKI services. Keep current with the PKI platforms, cryptographic mechanisms, operating systems, directory services, hardware security modules, and protocols used within BEPKI. Apply established practices to resolve technical issues and support approved service improvements. Provide practical PKI guidance and training to registration authority personnel.
Knowledge Management
Maintain authoritative BEPKI operating knowledge to support consistent administration and service continuity. Draft and update security policies, standard operating procedures, certificate policy, and certification practice statement documentation. Record technical solutions, configuration guidance, and lessons identified from service incidents, testing, exercises, and audits. Make approved information available to personnel who operate or support BEPKI services. Support the integration of PKI enablers in user services in support of authentication, integrity, non-repudiation and confidentiality.
Information Management
Maintain complete and accurate BEPKI service information to support secure operations, assurance, and audit requirements. Monitor certification authority logs, system alarms, errors, and user activity, and investigate anomalous behaviour. Maintain configuration records, accreditation documentation, audit evidence, and service-performance information. Report qualitative and quantitative service performance through agreed key performance indicators.
Organisational Efficiencies
Improve the reliability and efficiency of BEPKI operations through disciplined maintenance, automation, and problem resolution. Perform regular backups, restoration tests, upgrades, database maintenance, and other recurring administration. Analyse equipment, software, and configuration problems and propose sustainable technical solutions within the established service design. Use scripting and available administration tools to improve repeatability of operational measures and reduce avoidable operational overhead.
Planning and Execution
Operate and maintain BEPKI components in accordance with approved security, configuration, and service requirements. Install and configure certification authority, hardware security module, directory, online certificate status protocol, time-stamping, database, and related services. Prepare and execute test scenarios for backups, restoration, upgrades, configuration changes and service enhancements. Prepare BEPKI systems and evidence for vulnerability assessments, compliance audits, accreditation activities, exercises, and missions.
Project Management
Support approved BEPKI modifications and capability changes by providing technical input, estimates, test results, and implementation evidence. Coordinate assigned technical activities with vendors and other contributors, identify dependencies and risks, and report progress to the Head of Branch. Support the design and integration of new BEPKI components and third-party products while maintaining configuration control and service continuity. Contribute PKI expertise to relevant BGX programme and project activities.
Stakeholder Management
Provide responsive PKI support and coordination to sustain trusted certificate services across BICES. Deliver second-level technical support and work with BEPKI vendors to diagnose and resolve service issues. Manage the top-level BICES registration authority and provide technical guidance to other registration authorities. Coordinate with national root certification authority operation teams, BEPKI entities, BGX staff, and other personnel engaged in related activities.
4. INTERRELATIONSHIPS
The incumbent reports to the Branch Head and receives technical guidance from the Principal Engineers for Security, Systems and Network. S/He coordinates with staff across PEM, IES, OSS, and the ISR Cell in support of BEPKI operations, changes, exercises, missions, assurance, and service continuity. The incumbent maintains working relationships with BEPKI entities, registration authorities, national root certification authority operation teams, vendors, and personnel engaged in related or similar activities.
Direct reports: 0
Indirect reports: 0
5. COMPETENCIES
Achievement
Works to meet expected performance standards and deliver outputs within agreed timelines. Completes PKI maintenance, testing, documentation, and incident-resolution activities within agreed service, security, and operational requirements.
Analytical Thinking
Breaks down problems and information to identify relationships, patterns and logical conclusions. Analyses system, security, and application logs, configuration data, alarms, and test results to diagnose PKI faults and identify appropriate corrective action.
Clarity and Accuracy
Communicates information in a clear and precise manner and checks work carefully for accuracy. Maintains accurate certificate policies, procedures, configuration records, accreditation evidence, and technical reports, recognising that errors may affect trust services across BICES.
Customer Service Orientation
Responds constructively to the needs and requests of internal and external users in support of service quality and mission needs. Provides timely second-level support, practical guidance, and training to BEPKI users and registration authorities while setting clear expectations for issue resolution.
Initiative
Takes action within own area of responsibility to address issues and improve results without waiting to be told. Investigates emerging service, equipment, and configuration problems, proposes corrective measures, and improves recurring administration through approved tools and automation.
Teamwork
Works cooperatively with others to achieve shared goals and supports a positive and collaborative team environment. Coordinates constructively with BGX staff, vendors, national certification authority teams, and registration authority personnel during maintenance, testing, exercises, audits, and incident resolution.
6. CONTRACT
Contract to be offered to the successful applicant (if non-seconded): Definite Duration contract of three years.
Contract clause applicable:
This post is a limited duration project post. The first 6 months of the contract will be considered as probationary period. If the successful candidate is seconded from the national administration of one of NATO's member States, a three-year definite duration contract will be offered.
Serving staff will be offered a contract in accordance with the NATO Civilian Personnel Regulations.
7. USEFUL INFORMATION REGARDING APPLICATION AND RECRUITMENT PROCESS
Please note that we can only accept applications from nationals of NATO member countries. Applications must be submitted using e-recruitment system, as applicable:
For NATO civilian staff members only: please apply via the internal recruitment portal (link);
For all other applications: www.nato.int/recruitment
Before you apply to any position, we encourage you to click here and watch our video providing 6 tips to prepare you for your application and recruitment process.
Do you have questions on the application process in the system and not sure how to proceed? Click here for a video containing the information you need to successfully submit your application on time.
When submitting your application, please ensure that your Taleo Candidate Profile is updated and that your CV is correctly uploaded in the Taleo attachments section.
More information about the recruitment process and conditions of employment, can be found at our website (http://www.nato.int/cps/en/natolive/recruit-hq-e.htm)
Appointment will be subject to receipt of a security clearance (provided by the national Authorities of the selected candidate), approval of the candidate’s medical file by the NATO Medical Adviser, verification of your study(ies) and work experience, and the successful completion of the accreditation and notification process by the relevant authorities.
NATO will not accept any phase of the recruitment and selection prepared, in whole or in part, by means of reference documents without proper quotes (plagiarism), or any tools available on internet, including but not limited to translation facilities, or generative artificial-intelligence (AI) tools. NATO reserves the right to screen applications to identify the use of such tools. All applications prepared, in whole or in part, by means of such tools will be rejected without further consideration, and NATO reserves the right to take further steps in such cases as appropriate.
8. ADDITIONAL INFORMATION
NATO is committed to diversity and inclusion, and strives to provide equal access to employment, advancement and retention, independent of gender, age, nationality, ethnic origin, religion or belief, cultural background, sexual orientation, and disability. NATO welcomes applications of nationals from all member Nations, and strongly encourages women to apply.
NATO is committed to fostering an inclusive and accessible working environment, where all candidates living with disabilities can fully participate in the recruitment and selection process. If you require reasonable accommodation, please inform us during your selection process.
Candidates will be required to provide documented medical evidence to support their request for accommodation.
Building Integrity is a key element of NATO’s core tasks. As an employer, NATO values commitment to the principles of integrity, transparency and accountability in accordance with international norms and practices established for the defence and related security sector. Selected candidates are expected to be role models of integrity, and to promote good governance through ongoing efforts in their work.
Applicants who are not successful in this competition may be offered an appointment to another post of a similar nature, albeit at the same or a lower grade, provided they meet the necessary requirements.
The nature of this position may require the staff member at times to be called upon to travel for work and/or to work outside normal office hours.
For information about the NATO Single Salary Scale (Grading, Allowances, etc.) please visit our website. Detailed data is available under the Salary and Benefits tab.
NATO does not charge any application, processing, training, interviewing, testing or other fee in connection with the application or recruitment process. For more info please click here.