CKMS & HSM IT Security Engineer

hace 6 días


Madrid, Madrid, España BNP Paribas A tiempo completo

GROUP BNP PARIBAS
BNP Paribas Group is the top bank in the European Union and a major international banking establishment. It has close to 185,000 employees in 65 countries. In Spain we are more than 5,100 employees within 13 business lines.

Spain IT Production
Spain IT Production organization consists of CIB ITO & ITG IT Platforms and is responsible for providing IT Production services to our Clients in EMEA, ensuring a Digital Market evolution, in a secured and performant environment, and with a reliable quality. IT Production organisation includes Infrastructure services, Telecom & Workspace, Production Security and Application Production domains and associated transversal services (CTO Office, Control Tower, PMO and IT Continuity). In Spain, IT Production relies on a Platform with over 400 experts that provide full-stack support services ensuring a secure, stable, standardized, and efficient production.

About The Job
MISSION

BNP Paribas is a major player in the European banking sector. As such, BNP Paribas must protect its assets from cyber-attacks. The bank is also subject to strong rules from regulators or its customers.

The major challenges of current computing require greater security of data and banking applications. In a growing context of developing mobility solutions and Cloud services adoption, the mission is to integrate the Production Security teams in charge of setting up services to secure access to information system assets.

The mission is part of the IT Group Production Security – Defense teams. This team is specialized in security and data protection issues. The primary responsibility of the teams is to provide security services within the overall requirements framework while ensuring the operational readiness and Level 3 support of these services within an international scope.

Scope: Key Management Services (KMS), Hardware Security Modules (HSM), Encryption, PKI, cryptographic services, smart cards, strong authentication solutions, electronic signature, etc.

Mission & Role summary

Within the Crypto Services expertise team, the mission will be to ensure the operational maintenance of the Group's cryptographic security services (HSM, KMS, BYOK, KYOK, KMS, etc.) and to participate in the evolution of digital trust services (encryption, key management, electronic signature solutions, etc.).

It is expected that you operate in a cloud context (Office 365, IBM and others) to meet new uses and security needs (authentication, encryption, signature). In this context, you will contribute to the study, qualification and subsequent implementation of new security solutions. A technical background, security and project management is therefore needed.

You will contribute to the on-call duty rotation provided to ensure the high availability of services provided by the Crypto Services expert team.

Responsibilities
As part of this job, your missions will be to:

Technical Essentials

  • Provide technical expertise around cryptography: HSM, KMS, data encryption, cryptographic key life cycle, BYOK, KYOK, algorithms,
  • Participate in the design of architectures, building (Build) and evolution of KMS / HSM solutions,
  • Work with the IT Risk Management teams and transcribing risk and security requirements from an operational perspective,
  • Advise and support the business lines on the security aspects of various projects,
  • Write technical, operational procedures (e.g. key ceremony, installation of MSM, change of defective MSM, etc.),
  • Investigate, qualify and implement new security solutions
  • Qualify version runs of existing solutions,
  • Participate in cryptographic implementation projects and cryptographic key management,
  • Participate in ongoing cryptographic services management activities,
  • Contribute to the study of innovative solutions around cryptography,
  • Integrate solutions for the protection of the Bank's data as set out in the Cloud solutions,
  • Perform a security technology watch (authentication means, cryptographic algorithms, vulnerabilities, etc.),

Maintenance In Operational And Security Condition

  • Carry out on-call duty (one week per month),
  • Providing Level 3 support for services,
  • Analyses and processes engineering requests and incident tickets,
  • Carry out operations in unworked hours,
  • Maintenance and development of services,
  • Industrialise and automate operating processes,

Requirements

  • Studies

Master's degree or equivalent

  • Experience

Minimum 2-to-4-year Experience With HSM, CKMS, PKI
Experience in IT Production environments

Experience as SPOC for technical escalations

  • Languages

High Level of English (written / spoken).

French speaking will be appreciated.

Skills

  • Technical

Cryptography - Expert

HSM - Expert

Security - Expert

Infrastructure - Mastery

Architecture - Mastery

Programming Languages (Shell, Python, etc.) - Mastery

Production - Expert

OS UNIX / Windows - Mastery

Base de données (Postgres, MongoDB…) - Pratique

Active Directory - Mastery

Administration - Mastery

IAM - Mastery

Network - Mastery

  • Transversal & Behavioral

Teamwork

Organizational skills and timeliness

Priority management and adjustment to constraints

Good writing quality

Sense of initiative

Autonomous, rigorous and methodical.

Benefits

  • Training programs, career plans and internal mobility opportunities, national and international thanks to our presence in different countries.
  • Diversity and Inclusion Committee that ensures an inclusive work environment. In recent years, several employee communities have been created to organize diversity and inclusion awareness actions (PRIDE, We Generations and MixCity).
  • Corporate volunteering program (1 Million Hours 2 Help) in which employees can dedicate time out of their working hours to volunteer activities.
  • Flexible compensation plan.
  • Hybrid telecommuting model (50%).
  • 32 vacation days.

Diversity and inclusion commitment
BNP Paribas Group in Spain is an equal opportunity employer and proud to provide equal employment opportunity to all job seekers. We are actively committed to ensuring that no individual is discriminated against on the grounds of age, disability, gender reassignment, marriage or civil partnership status, pregnancy and maternity/paternity, race, religion or belief, sex or sexual orientation. Equity and diversity are at the core of our recruitment policy because we believe that they foster creativity and efficiency, which in turn increase performance and productivity. We strive to reflect the society we live in, while keeping with the image of our clients.


  • security Consultant

    hace 2 días


    Madrid, Madrid, España Axiom Software Solutions Limited A tiempo completo

    Thales HSM and Cipher Trust exp. are mandatory. Though it doesn't reflect in the JD shared (which was generic as mentioned by HPE), they have called out these skills in the email as mandatory.- Candidate must have (Thales HSM and CipherTrust as example)o Domain knowledge – key management and rood key securityo Product/vendor knowledge – Thales HSM Luna,...

  • IT Security Engineer

    hace 1 semana


    Madrid, Madrid, España Roche A tiempo completo

    Bei Roche kannst du ganz du selbst sein und wirst für deine einzigartigen Qualitäten geschätzt. Unsere Kultur fördert persönlichen Ausdruck, offenen Dialog und echte Verbindungen. Hier wirst du für das, was du bist, wertgeschätzt, akzeptiert und respektiert. Dies schafft ein Umfeld, in dem du sowohl persönlich als auch beruflich wachsen kannst....

  • IT Security Engineer

    hace 1 semana


    Madrid, Madrid, España Roche A tiempo completo 17.000  - 23.000 

    At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections,  where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure...

  • Security Engineer

    hace 2 días


    Madrid, Madrid, España ESSP SAS A tiempo completo

    ESSP SAS Madrid, Community of Madrid, SpainJoin or sign in to find your next jobJoin to apply for the Security Engineer - (F/M) role at ESSP SASESSP SAS Madrid, Community of Madrid, Spain4 weeks ago Be among the first 25 applicantsJoin to apply for the Security Engineer - (F/M) role at ESSP SASCreated in ****, ESSP is a young and dynamic company, a pan...


  • Madrid, Madrid, España Aubay Spain A tiempo completo

    Localidad : MadridProvincia : MadridNº Vacantes (puestos) : 1FuncionesBuscamos un Security Expert especializado en cifrado para incorporarse al equipo de seguridad global, dando soporte tanto a actividades de proyecto como a la operativa diaria de la plataforma corporativa de Encryption. La persona seleccionada trabajará con tecnologías de referencia como...


  • Madrid, Madrid, España AVEVA A tiempo completo

    AVEVA is creating software trusted by over 90% of leading industrial companies.Job Title: Vice President, IT SecurityLocation: Any AVEVA Group location  Employment Type: Full-time regular The jobWe are seeking a dynamic leader to head Corporate IT Security. This role reports directly to the AVEVA CIO, with a dotted-line reporting relationship to the Group...

  • Security Engineer

    hace 2 días


    Madrid, Madrid, España Happyrobot A tiempo completo

    About HappyRobotHappyRobot is the AI-native operating system for the real economy—a system that closes the circuit between intelligence and action. By combining real-time truth, specialized AI workers, and an orchestrating intelligence, we help enterprises run complex, mission-critical operations with true autonomy.Our AI OS compounds knowledge, optimizes...

  • Security Engineer

    hace 2 semanas


    Madrid, Madrid, España intro A tiempo completo

    Security Security EngineerOnsite - London, Madrid or Malaga (4 days in the office, 1 day remote)Our client's expanding Cyber Security team is seeking a skilled professional to contribute to security enhancements across their diverse product range. In this role, you will collaborate seamlessly with application, platform, and product teams, championing...

  • SAP Security Engineer

    hace 5 horas


    Madrid, Madrid, España Liebherr Group A tiempo completo

    The SAP Security Engineer is responsible for implementing, maintaining and monitoring security controls across SAP systems to protect against unauthorized access, data breaches, and other cyber threats. This role requires hands-on experience with SAP security tools and configurations, as well as a strong understanding of cybersecurity principles and...


  • Madrid, Madrid, España Axiom Software Solutions Limited A tiempo completo

    Position: Netops EngineerLocation: Spain (Remote)Duration: Long Term B2B ContractJob Description:We are seeking a highly skilled NetOps Security Engineer with a strong background in Fortinet and Cisco technologies, combined with hands-on experience in enterprise-grade network security operations. This role is part of a global support team, with a primary...