You bring strong experience in PKI security, security architecture and hands-on engineering. You design secure solutions for Root CA, issuing CAs, HSMs, scripts and supporting infrastructure, manage sensitive offline PKI assets and improve automation, documentation and recovery procedures. You advise on risks, controls and compliance, support audits and ceremonies, and troubleshoot complex Linux, scripting, HSM and certificate-chain issues. You combine architectural judgement with operational discipline, clear communication and ownership of high-risk security processes.
Requirements
- HBO/WO-level education or thinking level in IT, security, computer science or similar.
- At least 5 years of experience in IT security, PKI, security architecture or infrastructure engineering.
- Proven knowledge of PKI, Root CA, issuing CAs, digital certificates, trust chains and certificate lifecycle.
- Hands-on experience with HSMs, key material protection, access control and segregation of duties.
- Practical experience with Linux, preferably Debian-based systems, Python and scripting is required.
- Knowledge of cryptography and protocols such as RSA, ECC, AES, SHA, TLS/SSL, HTTPS, S/MIME and code signing.
- Experience with automation, security tooling, CI/CD pipelines, runbooks, audit evidence or recovery procedures.
- Fluent English; Dutch and CISSP, PKI, security or encryption certification are a plus.
Important: this role is only open to candidates currently residing in the Netherlands. If you do not currently live in the Netherlands, your application will not be considered.