KCSM OPS Engineer (SRQ158174
Listed on 2026-08-10
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Location: Town of Belgium
Join our Key, Certificate, and Key Management squad within the Production Security BE tribe! We’re a team of about 15 experts based in Belgium, specializing in the lifecycle management of cryptographic keys, certificates (internal/group/public), and application secrets (via Hashicorp Vault).
Our mission? To secure electronic transactions, authentications, and cloud-hosted applications while ensuring full compliance with EU/Group regulations (e.g. PSD2, PCI) and industry standards.
As part of the broader System Security Cluster, we operate and support Hardware Security Modules (HSMs) like Adyton and nCipher, enabling a trustworthy environment for both internal and external customers. Innovation drives us; we’re the go-to partners for stakeholders, delivering cost-efficient, reliable security solutions that keep the bank and its clients safe.
1. Operations- Manage the lifecycle of cryptographic keys, digital certificates, and application secrets (e.g., rotation, revocation, access control).
- Monitor and maintain HSM infrastructures (Adyton, nCipher, mainframe TKE) to ensure high availability and compliance.
- Troubleshoot incidents and collaborate with teams to resolve security gaps in authentication, encryption, or secret storage.
- Act as a Crypto Design Authority (Advise on cryptographic standards, algorithms, and best practices (e.g., NIST, PCI-DSS, PSD2)).
- Lead or contribute to strategic projects, including:
- Post-Quantum Cryptography (Assess risks, contribute to the migration of quantum resistant solutions)
- EKU Readiness (Prepare systems for Extended Key Usage (EKU) compliance)
- HSM Lifecycle Management (LCM) (Operate HSM support and configuration)
- Crypto Agility:
Improve certificate and key lifecycle mgmt. processes - Platform Integration:
Align with Group tools (Certis, Horizon) - Partner with COE Security, Group Security and other stakeholders like IT architects, IT application owners to translate regulatory and business requirements into technical solutions.
- French Fluent spoken
- English Fluent spoken and written
Expectation: 50% on site & 50% homeworking
Experience and skills- At least 5 years of relevant experience
- Deep IT security expertise
- Your foundation is technical mastery of HSMs (Adyton/nCipher), PKI, Hashicorp Vault, and cryptographic standards (NIST), paired with sharp operational oversight of high-availability infrastructures.
- Technical experience Microsoft Office (Word, Excel and Powerpoint)
- Scripting (Python, Bash, ?), preferable Service Now, Rally, Portunus, Adyton, nCipher, Hashi Corp Vault
- Bridging tech and business:
You turn abstract security requirements (e.g., from COE experience / Security) into feasible IT solutions, balancing cost efficiency, compliance, and developer practicality. - Agile in action:
In a fast-evolving landscape (e.g., crypto-agility, IoT onboarding automation), you anticipate change, prioritize flexibly, and contribute to iterative enhancements; without compromising production stability. - Collaboration and results drive you:
You work closely with stakeholders (IT architects, application owners, COE & Group Security) to deliver tangible security solutions that meet both business needs and regulatory demands; without losing sight of operational realities. - Client-centric by design:
Whether supporting internal teams or external partners, you translate complex cryptographic requirements (e.g., PSD2, PCI-DSS) into practical, user-friendly implementations that ensure trust and compliance. - Proactive and analytical:
Beyond spotting risks (e.g. in post-quantum cryptography or EKU readiness), you proactively enhance processes (e.g. improving key and certificate rotation protocols).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).