Application close date:
Applications will be accepted on an ongoing basis until the requisition is closed.
Job DescriptionAs part of a hardworking team of engineers and specialists, you will design, implement, automate, and operate the Public Key Infrastructure (PKI), certificate management, Hardware Security Module (HSM), and cryptographic key-management infrastructure supporting TeraWave custom silicon, devices, and systems.
You will be responsible for securely managing certificates and cryptographic key material throughout their lifecycle and will work closely with security, silicon, firmware, software, manufacturing, and infrastructure teams to deploy scalable and reliable security infrastructure across development, manufacturing, and production environments.
Special Mentions- Relocation provided
- Travel expected up to 20% of the time
- Interviews will include a technical assessment
Responsibilities include but are not limited to:- Design, implement, administer, and maintain PKI and certificate-management infrastructure supporting TeraWave devices and infrastructure.
- Automate and oversee the issuance, renewal, revocation, rotation, and replacement of digital certificates.
- Configure hardware security interfaces, token management, and cryptographic service integrations for applications and HSMs.
- Install, configure, administer, and maintain enterprise-class Hardware Security Module (HSM) appliances in accordance with vendor best practices, approved operating procedures, and applicable industry standards.
- Monitor HSM health, performance, and availability and identify, troubleshoot, and resolve hardware, firmware, software, and client-side issues.
- Perform HSM firmware updates, software patches, supporting client software upgrades, and configuration changes.
- Maintain HSM configuration documentation, baseline records, audit information, and change logs in accordance with configuration-management processes.
- Manage the full lifecycle of cryptographic key material, including generation, distribution, rotation, backup, escrow, restoration, revocation, and secure destruction.
- Maintain appropriate chain-of-custody documentation and controls for cryptographic key operations.
- Plan, execute, and participate in secure key ceremonies.
- Develop automation and tooling for PKI, certificate-management, HSM, and cryptographic key-management operations.
- Work with software, firmware, silicon, manufacturing, security, and infrastructure teams to integrate certificate and key-management capabilities into TeraWave systems.
- Evaluate third-party PKI, HSM, certificate-management, and key-management solutions and contribute to technical build-versus-buy decisions and vendor selection.
- Support deployment and operation of cryptographic infrastructure across development, manufacturing, and production environments.
Minimum Qualifications- Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, or a related technical discipline.
- 5+ years of relevant experience in PKI, cryptographic infrastructure, security infrastructure, or related engineering.
- Demonstrated experience designing, implementing, or administering enterprise Public Key Infrastructure (PKI).
- Strong knowledge of X.509 certificates, certificate authorities, trust chains, cryptographic algorithms, key management, certificate revocation, and certificate lifecycle management.
- Strong understanding of cryptography, including encryption, digital signatures, hashing, key exchange, and secure communications.
- Experience managing cryptographic key material and understanding key-generation, distribution, storage, rotation, backup, recovery, and destruction processes.
- Experience working with Hardware Security Modules (HSMs) or similar cryptographic hardware.
- Strong troubleshooting, documentation, and operational skills for security-critical infrastructure.
- Ability to work collaboratively across security, software, firmware, silicon, infrastructure, and manufacturing teams.
- Must be a U.S. citizen or national, U.S. permanent resident (current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Preferred Qualifications- Experience automating HSM, PKI, certificate-management, or key-management operations using Python or another scripting language.
- Experience using PKCS#11 APIs from Python, Java, C/C++, or similar languages.
- Experience configuring and administering enterprise-class HSM appliances.
- Experience designing or operating Root CA and Issuing/Leaf CA infrastructure.
- Experience conducting secure key ceremonies and maintaining chain-of-custody controls.
- Experience with PKI and cryptographic infrastructure supporting embedded devices, custom silicon, or manufacturing environments.
- Experience integrating HSMs with applications, services, and automated infrastructure.
- Experience evaluating and integrating commercial PKI, HSM, certificate-management, or key-management platforms.
Base Pay Range for:
CA applicants is $230,398.00 - $322,556.85WA applicants is $230,398.00 - $322,556.85
Other site ranges may differBenefits- Benefits include: Medical, dental, vision, basic and supplemental life insurance, paid parental leave, short and long-term disability, 401(k) with a company match of up to 5%, and an Education Support Program.
- Stock Options for all regular employees (working at least 20 hours/week)
- Paid Time Off: Up to four (4) weeks per year based on weekly scheduled hours, and up to 14 company-paid holidays.
- Dependent on role type and job level, employees may be eligible for benefits and bonuses based on the company's intent to reward individual contributions and enable them to share in the company's results, or other factors at the company's sole discretion. Bonus amounts and eligibility are not guaranteed and subject to change and cancellation. Please check with your recruiter for more details.