Image hero
Job offer

Expert in key management infrastructures (PKI) - CDI - Monaco

Posted on 16 Oct 2024
Job in Permanent
Remote Remote

We are looking for an expert in key management infrastructures (PKI) for one of our clients based in Monaco.

Missions

To implement the Principality's National Trust Infrastructure, we are looking for an expert specialising in key management infrastructures (PKI). This person will join a team of 3 people already in place and must be able to cover at least two of the four points set out in the following paragraph:

Participate in maintaining the qualification of trust services operated by the Monegasque State services.

In detail, the mission includes the following actions:

  • Monitoring changes in the applicable regulations (eIDAS, RGS-P and ETSI standards, mainly 319 401, [319 411-1, 319 411-2, 319 412] and [319 421, 319 422]),
  • Ensuring that the CCM's document repository is kept up to date and consistent, in particular the certification policies and the certification practice statements,
  • Proposing changes to the document repository in line with regulatory changes, the technical base or the organisation set up within the framework of the CCM, in conjunction with the Certification Authority [CA] managers.
  • Ensuring and monitoring the publication of the elements required for the proper operation of the CCM (CP, CPD, registration forms, CRL, ARL, CA chain, etc.).
  • Preparing the agendas of the Trust Services Monitoring Committee (C2SC)
  • Prepare and validate C2SC minutes
  • Preparing and organising qualification renewal audits and internal audits in conjunction with the Government's CISO and the DSN, each in their respective areas of responsibility,
  • Participate in the preparation of security audits relating to the CCM,
  • Drawing up and monitoring action plans for correcting non-compliances (audits and controls) in liaison with the stakeholders concerned (Registration Authority (RA) managers, online window managers, technical operators, etc.).
  • Ensuring the archiving of CCM traces as required by the standards,
  • Preparing and monitoring applications for qualification of trust services,
  • Supporting the CCM Registration Authorities,

Participating in the operational monitoring of the CCM.

In detail, the mission includes the following actions:

  • Defining and monitoring the implementation of quality, performance and supervision indicators in conjunction with the CERT-MC,
  • Planning, organising (including drafting scripts and minutes) and conducting key ceremonies as and when required,
  • Ensuring that the Lists of Revoked Authorities are drawn up and published in conjunction with the CERT-MC in strict compliance with the deadlines set,
  • Ensuring the management of CCM secrets (drawing up allocation, withdrawal or transfer forms, monitoring and annual inventory),
  • Ensuring that the infrastructure is maintained in operational condition, in conjunction with Certinomis (weekly monitoring of tickets [JIRA], monitoring of progressive maintenance of infrastructure equipment),
  • Participate in the monthly Operations Monitoring Committees (CoSui),
  • Leading and monitoring the monthly Security Monitoring Committees (CoSec),
  • Monitor the implementation of monitoring committee actions,
  • Assisting the functional and technical operation of the ICN and its components, in particular by monitoring the resolution of production and security incidents,
  • Monitor the life cycle of the HSM units (updates, configuration, follow-up sheets),
  • Sharing audit information with the Government's CISO to enable him to consolidate risk analyses,
  • Monitoring the front offices (exchanges with the AEs and service providers, management of requirements, particularly in terms of consumables, etc.),
  • Monitoring the distribution of trusted roles in the CCM and ensuring their segregation in accordance with the matrix provided for this purpose,
  • Ensuring that logs are continuously available on the supervision server, that they are complete and that any anomalies are reported using the JIRA tool,
  • Monitor the compliance of the logs with the service provider chosen for this purpose, who is involved in the analysis of the logs,
  • Monitor the implementation of legal archiving,
  • Participate in the implementation and execution of the CCM's internal control system (organisation, documentation, processes),
  • Carrying out an annual assessment of the CCM's security level.

Participate in the ICN's MCO/MCS operations and its development.

In detail, the mission includes the following actions:

  • Implementing quality, performance and supervision indicators,
  • Analysing alerts from the SIEM and NAGIOS systems, as well as anti-DDoS, antivirus and CyberWatch reports, and carrying out any necessary investigations or operations,
  • Take charge of the functional (EJBCA) and technical operation of the ICN and its components,
  • Create incident and support tickets,
  • Participate in the diagnosis and resolution of technical incidents,
  • Helping to draw up proposals for changes to the architecture of the CCM,
  • Annually implementing and proposing changes to the CCM's Disaster Recovery Plan,
  • Participating in technical, technological and methodological choices in connection with the CCM,
  • Propose and implement technical and organisational changes as required,
  • Contributing to the operational management of the Certification Authorities,
  • Participating in the preparation of public procurement contracts in conjunction with the CCM.

Monitor issues relating to trust services.

In detail, the mission includes the following actions:

  • Monitoring issues relating to cryptology and their implementation (algorithms, components, etc.) in liaison with the service provider chosen for this purpose and, where appropriate, the French National Information Systems Security Agency [ANSSI]),
  • Developing the Monegasque TSL (Trusted Services List) as required and helping to keep it up to date.

Profile

  • Hold a national diploma attesting to 5 years' higher education, or a diploma recognised as equivalent by a competent authority in the country where the diploma was obtained, and provide evidence of at least 4 years' professional experience in the field of information technology (computing, networking, telecommunications or cybersecurity);
  • Hold a national diploma attesting 4 years of higher education, or a diploma recognised as equivalent by a competent authority in the country where the diploma was obtained, and provide proof of at least 5 years' professional experience in the field of information technology (computing, networks, telecommunications or cybersecurity);
  • Hold a national diploma attesting to 3 years' higher education, or a diploma recognised as equivalent by a competent authority in the country where the qualification was obtained, and provide evidence of at least 7 years' professional experience in the field of information technology (computing, networking, telecommunications or cybersecurity);
  • hold a national diploma attesting to 2 years of higher education, or a diploma recognised as equivalent by a competent authority in the country in which the qualification was obtained, and provide proof of 10 years' professional experience in the field of information technology (computing, networks, telecommunications or cybersecurity).
  • Be of French or Monegasque nationality.

Know how

  • Master the rules for using cryptography,
  • Master the life cycle of electronic certificates,
  • Skills in operating system security and network and protocol security,
  • Know how to interpret event logs (systems or applications) and network flows,
  • Have a good command of the usual office automation tools, in particular Microsoft Excel and Word,
  • Ability to communicate and explain technical information to a non-technical audience,
  • Ability to write letters and clear, concise summaries,
  • Ability to report both orally and in writing.
  • Knowledge of how an HSM appliance works, of SIEM-type event log correlation tools and methods and of one or more system, network or security supervision solutions, as well as the ability to automate recurring tasks, would be a plus.
  • Knowledge of trust services regulations and associated standards, particularly ETSI, would also be a plus.

Know be

  • Fluency in French and English (read, written and spoken),
  • Be of good character,
  • Ability to work across the organisation,
  • Have a sense of responsibility and the ability to work as part of a team,
  • Ability to withstand pressure, particularly during incidents or crises,
  • A sense of public service,
  • Demonstrate rigour, method and organisation,
  • Demonstrate loyalty and dynamism,
  • Be proactive,
  • Be curious and keen to acquire new knowledge and skills,
  • Excellent analytical skills and a real ability to adapt,
  • Ability to work independently,
  • Have a sense of ethics and absolute respect for confidentiality,
  • Demonstrate reserve and professional discretion,
  • Be sensitive to the Principality's ecological values and willing to participate in an eco-responsible approach.

More informations

  • PERMANENT CONTRACT
  • Other contractual conditions possible, please contact us
  • Availability: immediate
  • Possibility of teleworking up to 2 days a week
  • Gross annual salary depending on profile and experience.

Similar job offer

Discover our others job offers
See all our job offers
Expert in key management infrastructures (PKI) - CDI - Monaco
Inforca
Monaco
Permanent
Remote : Remote