A major Belgian financial institution is expanding its Key, Certificate, and Key Management squad within Production Security. This senior KCSM OPS Engineer role focuses on the operational security of cryptographic keys, digital certificates, and application secrets, using HSMs, PKI, and HashiCorp Vault. The team supports electronic transactions, authentication services, and cloud-hosted applications across the organisation.
The mission
The key certificate and key management squad consists of around 15 security specialists in Belgium and operates within a broader System Security Cluster. It manages internal, group, and public certificates, application secrets, and HSM platforms including Adyton, nCipher, and mainframe TKE. The work protects high-availability services while supporting compliance with NIST cryptographic standards, PSD2, PCI-DSS, and applicable group policies.
As an HSM operations engineer, you will combine production support with security expertise and project delivery. Your scope covers lifecycle management, incident resolution, HSM Lifecycle Management, key ceremonies, and improvements linked to Extended Key Usage, post-quantum cryptography, and crypto agility. You will work with IT architects, application owners, COE Security, and Group Security to turn regulatory and business requirements into workable technical solutions.
Your responsibilities
- Govern the lifecycle of cryptographic keys, digital certificates, and application secrets, including rotation, revocation, access control, and secure storage.
- Maintain Adyton, nCipher, and mainframe TKE HSM infrastructures to preserve availability, security, and operational compliance.
- Resolve incidents affecting authentication, encryption, certificate services, or secret management, coordinating with application and infrastructure teams.
- Advise as a Crypto Design Authority on algorithms, NIST standards, PCI-DSS, PSD2, EKU readiness, and practical cryptographic controls.
- Lead or contribute to initiatives covering post-quantum cryptography, crypto agility, HSM support, key ceremonies, and integration with Certis and Horizon.
- Improve operational procedures, documentation, reporting, and stakeholder communication using tools such as ServiceNow, Rally, and Microsoft Office.
Your profile
Essential skills
- Bring at least 5 years of relevant experience in IT security, security operations, or cryptographic infrastructure.
- Demonstrate technical mastery of HSMs, particularly Adyton, nCipher, or mainframe TKE, in high-availability environments.
- Manage PKI, cryptographic keys, digital certificates, and application secrets throughout their operational lifecycle.
- Use HashiCorp Vault for secure application secret storage, access management, and rotation processes.
- Apply NIST cryptographic standards and translate security, regulatory, and business requirements into feasible IT solutions.
- Work analytically with architects, application owners, and security stakeholders while maintaining production stability and cost awareness.
- Use Microsoft Office, including Word, Excel, and PowerPoint, for documentation, analysis, and presentations.
Preferred skills
- Experience with Crypto Design Authority responsibilities, PCI-DSS, PSD2, Extended Key Usage, or crypto agility.
- Knowledge of Post-Quantum Cryptography, HSM Lifecycle Management, and HSM Key Ceremonies.
- Scripting capability in Python or Bash, and familiarity with Certis, Horizon, Portunus, ServiceNow, or Rally.
- Experience adopting Agile Methodology in operational security or infrastructure projects.
Languages
- English: C1, fluent spoken and written.
- French: C1, fluent spoken.
- Dutch: an advantage, with no minimum CEFR level specified.