Company Description
Vattenfall is one of Europe’s largest producers and retailers of electricity and heat. Our main markets are Sweden, Germany, the Netherlands, Denmark, and the UK. The Vattenfall Group has approximately 20,000 employees. We have been electrifying industries, powering homes and transforming life through innovation for more than 100 years. We now want to make fossil free living possible within one generation and we are driving the transition to a sustainable energy system.
Job Description
Would you like to be a part of our team as we move towards a fossil free generation?
For the Vattenfall IT we are now looking for an experienced and ambitious Data Security Engineer who will enjoy a fast-developing international working environment.
Our environment
Because of fast growing security developments and threats, we want to enhance our security organization by increasing operational security in our delivery units. To realize this ambition, we set up a technically oriented Security Operations Team (SecOps) focusing on implementing security related improvements for the whole IT landscape.
The SecOps department is an international team of IT engineering colleagues representing different competence areas. We follow security trends, identify vulnerabilities and security findings and above all, focus on implementing improvements. One of the key competences within SecOps services is data encryption and key management. In order to provide high quality services within Vattenfall‘s IT landscape we continue development of this area. As a result we keep our team growing and we’re looking for a new colleague who will help us in this journey.
Your Job as Data Security Engineer
We are looking for a talented and experienced Data Security Engineer as an expert in the areas of encryption and key management. In this new position, you will work on improving our key management infrastructure consisting of HSMs and an enterprise key management system. Your tasks involve designing, implementing, and managing cryptographic key management services, applying encryption technologies, and working on key management processes. You will work with various teams to ensure that encryption standards and processes are maintained, and that cryptographic keys are securely managed and protected throughout their lifecycle.
Your key activities will be:
- Define and implement encryption and key management processes to ensure the security of data in transit and at rest
- Develop and maintain cryptographic key management policies and procedures
- Collaborate with cross-functional teams to integrate cryptographic systems into applications, platforms, and infrastructure
- Operate, manage and improve the existing cryptographic key management core infrastructure
- Define and maintain Hardware Security Module (HSM) security policies and procedures
- Monitor and troubleshoot issues related to cryptographic systems and key management processes
- Develop, test and maintain disaster recovery plans for cryptographic systems and key management processes
- Stay informed about recent developments on new cryptographic technologies and assess their applicability to the organization
- Provide technical guidance and training to other team members on cryptographic systems and key management processes
- Participate in audits and compliance assessments related to cryptographic systems and key management processes
You will also contribute in:
- Participation in SecOps daily activities, projects, initiatives
- Implementation of security improvements and mitigations
- Helping to define security baselines and initiate changes
- Support the line organization with execution and broaden IT Security knowledge
Qualifications
Our ideal candidate
Will you become our Cryptography expert and help us become fossil free in one generation?
And do you enjoy creating efficient and lean encryption and key management solutions? Then this is your job! Furthermore you bring:
- Proven experience in designing, implementing, operating, and managing on-premise and/or cloud-based IT systems (appliances, e.g. HSM, Azure key Vault, VPN, FW) and related IT services
- Familiarity with HSM (e.g. Hardware Security Modules, TPM, TEE, smartcards) technologies and their integration.
- Strong understanding of cryptographic concepts, standards and tools (encryption, digital signatures, authentication, X.509/PKI) and related protocols (e.g., SSL/TLS, KMIP, PKCS#11)
- Knowledge of security best practices and compliance standards (e.g., FIPS 140-2, GDPR, HIPAA).
- Excellent problem-solving and very good analytical and conceptual