Job Summary
The Senior Cryptography & Data Security Platform Engineer will design, implement, maintain, and support enterprise cryptographic services and data security platforms, with a primary focus on HSMs, key management, cloud KMS, PKI, and data protection controls. The role will partner with application, cloud, database, operations, and security teams to implement secure, scalable, supportable, and auditable cryptographic solutions. The position also supports key lifecycle management, security hardening, vulnerability remediation, monitoring, compliance validation, and cloud-native security initiatives.
Key Responsibilities
• Design, implement, maintain, and support enterprise cryptographic services and key management platforms, including Thales CipherTrust Manager, Luna Network HSM, payShield 10K/10K+, Cloud HSM, and Cloud KMS solutions.
• Administer cryptographic keys across their full lifecycle, including generation, activation, custody, use, rotation, backup, recovery, archival, retirement, access control, and compliance validation.
• Design and maintain enterprise data protection controls, including encryption policies, key governance, secrets management, tokenization, data classification alignment, and compliance monitoring.
• Translate application and business requirements into technical designs, feasibility assessments, implementation approaches, and operational support models for cryptographic services.
• Develop prototypes, proof-of-concepts, automation workflows, and implementation patterns for cryptographic and data security solutions.
• Perform configuration management, firmware upgrades, vulnerability remediation, patch management, security hardening, and operational readiness validation for cryptographic infrastructure.
• Integrate HSM and key management platforms with enterprise applications and platforms using REST APIs, PKCS#11, KMIP, JCE/JCA, Microsoft CNG, MSCAPI, OpenSSL, and cloud-native security SDKs.
• Support cloud-native and containerized security platforms using Kubernetes, OpenShift, Podman, Docker, Helm, and CI/CD pipelines.
• Implement and maintain monitoring and observability using Splunk Enterprise, Dynatrace, SNMPv3, and other approved monitoring technologies.
• Support Zero Trust security principles, machine identity management, certificate automation, crypto-agility, and Post-Quantum Cryptography readiness initiatives.
• Support database encryption integrations, including Microsoft SQL Server TDE and EKM, Oracle TDE, PostgreSQL encryption, KMIP, and PKCS#11-based key management.
• Maintain technical documentation, runbooks, architecture diagrams, control evidence, change records, and operational procedures.
• Partner with application owners, architects, cloud teams, operations, and security stakeholders to define and implement cryptographic controls and key management strategies.
• Support high-availability cryptographic services, backup and recovery validation, disaster recovery exercises, incident response, and production troubleshooting.
Required Qualifications
• Strong hands-on experience as a PKI/HSM Engineer supporting enterprise cryptographic services and key management platforms.
• Experience with HSM technologies such as Thales CipherTrust Manager, Luna Network HSM, payShield, Cloud HSM, or equivalent platforms.
• Strong understanding of cryptographic architectures, PKI, key management, encryption, and security controls.
• Strong experience with PowerShell or similar scripting languages for automation and administration.
• Experience with Python and modern GitOps or Infrastructure-as-Code practices.
• Strong understanding of cryptographic APIs and integration frameworks, including REST APIs, PKCS#11, KMIP, JCE/JCA, Microsoft CNG, MSCAPI, and OpenSSL.
• Experience with cloud KMS and cloud security services across platforms such as Azure, AWS, or Google Cloud.
• Experience with Kubernetes, OpenShift, Podman, Docker, Helm, and CI/CD environments.
• Experience with enterprise monitoring and observability platforms such as Splunk Enterprise and Dynatrace.
• Experience with lifecycle management, configuration management, firmware upgrades, vulnerability remediation, patch management, and compliance validation for cryptographic infrastructure.
• Knowledge of database encryption technologies and key management integrations.
• Understanding of standards and security requirements including OASIS KMIP, NIST SP 800-57, NIST SP 800-131A, FIPS 140-3, PCI DSS, and PCI HSM.
• Strong troubleshooting skills across application, API, network, certificate, database, cloud, key management, and HSM/KMS integration issues.
• Ability to translate cryptographic requirements into secure, scalable, supportable, and auditable engineering solutions.
• Strong written and verbal communication skills and ability to collaborate with technical and security stakeholders.
Preferred Qualifications
• Experience with Ansible and Terraform.
• Experience with Azure Key Vault, AWS KMS, Google Cloud KMS, or equivalent enterprise cloud KMS platforms.
• Experience with Prometheus, Grafana, Elastic Stack, or SNMPv3 monitoring.
• Experience with payment cryptography, payment HSM operations, PIN/key block concepts, key ceremonies, EMVCo, ANSI, and PCI security guidance.
• Experience supporting machine identity management, certificate automation, secure signing, tokenization, and data encryption integrations.
• Familiarity with Post-Quantum Cryptography, crypto-agility initiatives, and quantum-safe migration strategies.
• Experience supporting Agile, Scrum, Kanban, DevSecOps, Jira, Azure DevOps, and SDLC practices.
• Experience supporting regulated cryptographic infrastructure, including audit readiness, evidence collection, access reviews, and compliance activities.
Certifications
• Relevant PKI, HSM, cloud security, cryptography, or information security certifications are preferred.
Top 3 Skills
• Strong PKI/HSM Engineering Experience
• PowerShell or Similar Scripting Experience
• Enterprise Cryptographic Services & Key Management