HTC Global Services

Cybersecurity Key Provisioning Process Engineer

HTC Global Services$95K — $115K *
Manufacturing & Automotive
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in relevant field.
  • Experience with embedded systems and their security.
  • Background in auditing processes and compliance.
  • Demonstrated cybersecurity expertise and knowledge.
  • Proven track record in defining and managing cryptographic key requirements.
  • Experience coordinating cybersecurity across diverse engineering and manufacturing teams.
  • Familiar with PKI/KMS environments and cryptographic provisioning processes.

Responsibilities

  • Define, document, and approve cryptographic key requirements for ECUs and vehicle programs.
  • Coordinate between vehicle program teams and cybersecurity architecture for requirement consistency.
  • Conduct technical audits of suppliers to ensure compliance with cybersecurity standards.
  • Assess and enhance supplier readiness for cryptographic requirements, addressing any gaps found.
  • Establish compliance metrics and manage escalating non-conformances through governance processes.
  • Work with engineering and procurement teams to tailor cryptographic key requirements to specific ECU needs.
  • Manage technical implementation of key requirements within backend PKI and KMS systems.

Benefits

  • Hybrid work model with flexibility.
  • Opportunity to influence vehicle cybersecurity practices.
  • Involvement in cutting-edge automotive technology projects.
  • Collaboration with cross-functional teams to enhance skills.
  • Engagement with suppliers to drive cybersecurity compliance.
Full Job Description
Cybersecurity Key Provisioning Process Engineer

Overview / Summary

We are seeking a Cybersecurity Key Provisioning Process Engineer to support vehicle cybersecurity initiatives. This role sits at the intersection of automotive engineering, cryptographic security architecture, and manufacturing operations, with responsibility for the end-to-end process by which cryptographic key material is defined, provisioned, and secured across Electronic Control Units (ECUs) and vehicle programs.

The ideal candidate is a systems thinker who can translate cryptographic and security requirements into engineering specifications, drive supplier accountability through audits and integration, and support backend Public Key Infrastructure (PKI) and Key Management System (KMS) operations to deliver secure keys at scale.

This is a highly cross-functional role requiring experience in cybersecurity engineering, supplier quality and manufacturing processes, and product key management systems. The role also involves development and governance of security policies and procedures, review of security controls and their effectiveness, monitoring processes for compliance risks and vulnerabilities, and management of third-party security risk programs.

Key Responsibilities
  • Own and facilitate the process for defining, documenting, and approving cryptographic key requirements, including algorithms, key lengths, key hierarchies, usage policies, and rotation/expiry rules, for each ECU type and vehicle program.
  • Serve as the central point of coordination between vehicle program teams, ECU feature owners, and cybersecurity architecture to ensure requirements are complete, consistent, and traceable across program timelines.
  • Conduct technical audits of Tier-1 supplier manufacturing sites and processes to validate conformance with cybersecurity requirements.
  • Assess supplier readiness against cryptographic and secure manufacturing requirements, identify gaps, and drive corrective action plans.
  • Establish and monitor supplier compliance metrics and escalate non-conformances through appropriate governance channels.
  • Partner with cybersecurity architects, ECU/software engineering teams, vehicle program management, procurement, and manufacturing to define cryptographic key requirements tailored to each ECU's function, threat model, and program constraints.
  • Coordinate the technical implementation of approved key requirements within backend PKI and KMS infrastructure with the teams responsible for these systems.
  • Define and manage key lifecycle workflows within the KMS in alignment with program and supplier timelines.
  • Troubleshoot and resolve issues in the key delivery pipeline between backend systems and supplier manufacturing lines.
  • Author technical documentation, specifications, and work instructions covering cryptographic key requirements, provisioning processes, and PKI/KMS interfaces.
  • Cascade approved requirements to relevant internal teams and external suppliers, ensuring proper acknowledgment and implementation.
  • Enforce compliance with documented requirements through audits, design reviews, and program gate reviews.
  • Maintain version control and change management for specifications.

Required Qualifications
  • Bachelor's degree.
  • Experience with embedded systems.
  • Experience in auditing.
  • Cybersecurity experience.
  • Compliance professional experience.
  • Experience defining, documenting, and managing cryptographic key requirements.
  • Experience coordinating cybersecurity requirements across engineering, manufacturing, suppliers, and related teams.
  • Experience conducting technical audits and assessing supplier compliance.
  • Experience with cryptographic key provisioning processes and PKI/KMS environments.

Preferred Qualifications
  • ISO 27001 experience or knowledge.
  • Supply chain operations experience.
  • Familiarity with automotive cybersecurity standards, including ISO/SAE 21434 and UNECE R155/R156.
  • Hands-on experience with commercial or in-house PKI/KMS platforms, such as Thales, Entrust, HashiCorp Vault, AWS KMS, or automotive-specific secure provisioning platforms.
  • Experience with ECU/embedded systems development lifecycle and vehicle program timing.
  • Knowledge of secure manufacturing/provisioning protocols, such as SHE, HSM-based key injection, and secure flashing.
  • Project or process management experience, such as Agile, Six Sigma, or similar.
  • Experience with relevant control frameworks, such as NIST 800-53/800-57, ISO 27001, PCI-HSM, or automotive-specific key management security standards.
  • Experience managing third-party security risk programs.

#LI-Hybrid #LI-CP1

About HTC Global Services

HTC Global Services is a global provider of IT and Business Process Services and Solutions. Founded in 1990, HTC is headquartered in Troy, Michigan with delivery centers across multiple locations in North America, Europe, India, and Malaysia. HTC is an Inc. 500 Hall of Fame company and has been recognized by numerous industry and trade publications as a top provider of services. HTC has a strong client base of Global 2000 customers. HTC has a strong focus on healthcare, retail, financial services, and automotive verticals. HTC has a strong commitment to corporate social responsibility and has been recognized for its contributions to the community.
Learn more about HTC Global Services
Size
17,575 employees
Industry
Founded
1990
NASDAQ

Similar Jobs

More Jobs at HTC Global Services

More Manufacturing & Automotive Jobs

Find similar Cybersecurity Key Provisioning Process Engineer jobs: