NATO Public Key Infrastructure (PKI) Engineer

NATO Public Key Infrastructure (PKI) Engineer

North Atlantic Treaty Organization (NATO)

August 24, 2026September 28, 2026BrusselsBelgium
Job Description
Job Posting Organization:
The BICES Group Executive (BGX) is a NATO entity that serves as the executive body of the BICES Group (BG). Established to facilitate the sharing and exchange of intelligence and information among NATO nations and with non-NATO nations and organizations, BGX is led by a Director and comprises several divisions including Intelligence and Enterprise Services (IES), Programmes, Engineering and Maintenance (PEM), and Operations and security" style="border-bottom: 1px dotted #007bff !important;">security-services" style="border-bottom: 1px dotted #007bff !important;">Security Services (OSS). The PEM Division is particularly focused on managing the BICES Programme and overseeing the lifecycle of IT capabilities, ensuring that these capabilities are developed, improved, and maintained effectively. The organization operates with a mission to enhance IT coherence and modernization across NATO's intelligence-sharing framework.

Job Overview:
The NATO Public Key Infrastructure (PKI) Engineer is responsible for the operation and maintenance of the BICES Enterprise Public Key Infrastructure (BEPKI). This role involves managing both the organizational and technical aspects of BEPKI, which includes overseeing policies, hardware, software, and procedures necessary for the lifecycle management of a medium-assurance asymmetric credential provider. The PKI Engineer will advise on the integration of critical security aspects such as authentication, integrity, non-repudiation, and confidentiality into existing and future operational services. The position requires the incumbent to install, configure, maintain, monitor, and support BEPKI systems, which encompass various services including certification authority and registration authority. The role also involves providing second-level technical support, investigating faults, and coordinating with vendors and external certification authority teams. Additionally, the PKI Engineer will support BICES exercises and missions and train personnel in the operation of BEPKI services.

Duties and Responsibilities:
The PKI Engineer's duties include maintaining technical expertise for the reliable operation of BEPKI services, keeping current with PKI platforms and cryptographic mechanisms, and applying established practices to resolve technical issues. The incumbent will draft and update security policies and standard operating procedures, maintain complete and accurate service information, and monitor certification authority logs and user activity to investigate anomalies. The role also involves improving the reliability and efficiency of BEPKI operations through disciplined maintenance and automation, preparing and executing test scenarios for various operational changes, and supporting approved modifications and capability changes by providing technical input and coordination with vendors. Furthermore, the PKI Engineer will manage stakeholder relationships, providing responsive support to sustain trusted certificate services across BICES.

Required Qualifications:
Candidates must possess a university degree in Computer Science, Computer Engineering, Systems Engineering, Mathematics, or a related discipline. Essential qualifications include at least three years of post-related experience, particularly in the operation and configuration of Information Security and Cryptography, including PKI systems. Experience in managing certified/accredited PKI CA solutions, deployment of digital certificates, and familiarity with Multi-Factor Authentication (MFA) tokens is also required. Knowledge of computer and communications security principles, experience in drafting security policies, and proficiency in analyzing system logs are essential. Level V (Advanced) proficiency in English is mandatory, while knowledge of NATO security policies is desirable.

Educational Background:
A university degree in a relevant field such as Computer Science, Computer Engineering, Systems Engineering, or Mathematics is required for this position. This educational background provides the foundational knowledge necessary for understanding complex IT environments and the technical aspects of PKI systems.

Experience:
The position requires a minimum of three years of relevant experience in the field of Information Security and Cryptography, specifically with PKI systems. Candidates should have hands-on experience in managing and configuring PKI solutions, as well as familiarity with complex IT environments that involve multiple domains. Experience in drafting security policies and analyzing system logs is also essential for this role.

Languages:
Proficiency in English at Level V (Advanced) is mandatory for this position. Additionally, knowledge of French at Level II (Basic) is considered desirable, enhancing communication capabilities within the NATO environment.

Additional Notes:
The contract offered for this position is a definite duration contract of three years, with the first six months serving as a probationary period. The successful candidate may be seconded from the national administration of a NATO member state, in which case a three-year contract will be provided. The position is open only to nationals of NATO member countries, and applications must be submitted through the specified e-recruitment system. The appointment is subject to security clearance, medical approval, and verification of qualifications and experience. NATO emphasizes diversity and inclusion in its hiring practices and encourages applications from all member nations, particularly from women and individuals with disabilities.
Apply now
Similar Jobs