Application close date:
Applications will be accepted on an ongoing basis until the requisition is closed.
Job Description
As part of a hardworking team of engineers and specialists, you will design, implement, automate, and operate the Public Key Infrastructure (PKI), certificate management, Hardware Security Module (HSM), and cryptographic key-management infrastructure supporting TeraWave custom silicon, devices, and systems.
You will be responsible for securely managing certificates and cryptographic key material throughout their lifecycle and will work closely with security, silicon, firmware, software, manufacturing, and infrastructure teams to deploy scalable and reliable security infrastructure across development, manufacturing, and production environments.
Special Mentions
- Relocation provided
- Travel expected up to 20% of the time
- Interviews will include a technical assessment
Responsibilities include but are not limited to:
- Design, implement, administer, and maintain PKI and certificate-management infrastructure supporting TeraWave devices and infrastructure.
- Automate and oversee the issuance, renewal, revocation, rotation, and replacement of digital certificates.
- Configure hardware security interfaces, token management, and cryptographic service integrations for applications and HSMs.
- Install, configure, administer, and maintain enterprise-class Hardware Security Module (HSM) appliances in accordance with vendor best practices, approved operating procedures, and applicable industry standards.
- Monitor HSM health, performance, and availability and identify, troubleshoot, and resolve hardware, firmware, software, and client-side issues.
- Perform HSM firmware updates, software patches, supporting client software upgrades, and configuration changes.
- Maintain HSM configuration documentation, baseline records, audit information, and change logs in accordance with configuration-management processes.
- Manage the full lifecycle of cryptographic key material, including generation, distribution, rotation, backup, escrow, restoration, revocation, and secure destruction.
- Maintain appropriate chain-of-custody documentation and controls for cryptographic key operations.
- Plan, execute, and participate in secure key ceremonies.
- Develop automation and tooling for PKI, certificate-management, HSM, and cryptographic key-management operations.
- Work with software, firmware, silicon, manufacturing, security, and infrastructure teams to integrate certificate and key-management capabilities into TeraWave systems.
- Evaluate third-party PKI, HSM, certificate-management, and key-management solutions and contribute to technical build-versus-buy decisions and vendor selection.
- Support deployment and operation of cryptographic infrastructure across development, manufacturing, and production environments.
Minimum Qualifications
- Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, or a related technical discipline.
- 5+ years of relevant experience in PKI, cryptographic infrastructure, security infrastructure, or related engineering.
- Demonstrated experience designing, implementing, or administering enterprise Public Key Infrastructure (PKI).
- Strong knowledge of X.509 certificates, certificate authorities, trust chains, cryptographic algorithms, key management, certificate revocation, and certificate lifecycle management.
- Strong understanding of cryptography, including encryption, digital signatures, hashing, key exchange, and secure communications.
- Experience managing cryptographic key material and understanding key-generation, distribution, storage, rotation, backup, recovery, and destruction processes.
- Experience working with Hardware Security Modules (HSMs) or similar cryptographic hardware.
- Strong troubleshooting, documentation, and operational skills for security-critical infrastructure.
- Ability to work collaboratively across security, software, firmware, silicon, infrastructure, and manufacturing teams.
- Must be a U.S. citizen or national, U.S. permanent resident (current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Preferred Qualifications
- Experience automating HSM, PKI, certificate-management, or key-management operations using Python or another scripting language.
- Experience using PKCS#11 APIs from Python, Java, C/C++, or similar languages.
- Experience configuring and administering enterprise-class HSM appliances.
- Experience designing or operating Root CA and Issuing/Leaf CA infrastructure.
- Experience conducting secure key ceremonies and maintaining chain-of-custody controls.
- Experience with PKI and cryptographic infrastructure supporting embedded devices, custom silicon, or manufacturing environments.
- Experience integrating HSMs with applications, services, and automated infrastructure.
- Experience evaluating and integrating commercial PKI, HSM, certificate-management, or key-management platforms.
Base Pay Range for:
CA applicants is $230,398.00 - $322,556.85
WA applicants is $230,398.00 - $322,556.85
Other site ranges may differ
Culture Statement
Don’t meet all desired requirements? Studies have shown that some people are less likely to apply to jobs unless they meet every single desired qualification. At Blue Origin, we are dedicated to building an authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every desired qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.
Export Control Regulations
Applicants for employment at Blue Origin must be a U.S. citizen or national, U.S. permanent resident (i.e. current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Background Check
- Required for all positions: Blue’s Standard Background Check
- Required for Certain Job Profiles: Defense Biometric Identification System (DBIDS) background check if at any time the role requires one to be on a military installation
- Required for Certain Job Profiles: Drivers who operate Commercial Motor Vehicles with a Gross Vehicle Weight (GVW), Gross Vehicle Weight Rating (GVWR) or combination of power unit and trailer that meets or exceeds 10,001 lbs. and/or transports placardable amounts of hazardous materials by ground in any vehicle on a public road while in commerce, may be subject to additional Federal Motor Carrier Safety Regulations including: Driver Qualification Files, Medical Certification (obtained before onboarding), Road Test, Hours of Service, Drug and Alcohol Testing, vehicle inspection requirements, CDL requirements (if applicable) and hazardous materials transportation/shipping training.
- Required for certain Job Profiles: Ability to obtain and maintain Merchant Mariner Credential, which includes pre-employment and random drug testing as well as DOT physical
Benefits
- Benefits include: Medical, dental, vision, basic and supplemental life insurance, paid parental leave, short and long-term disability, 401(k) with a company match of up to 5%, and an Education Support Program.
- Stock Options for all regular employees (working at least 20 hours/week)
- Paid Time Off: Up to four (4) weeks per year based on weekly scheduled hours, and up to 14 company-paid holidays.
- Dependent on role type and job level, employees may be eligible for benefits and bonuses based on the company's intent to reward individual contributions and enable them to share in the company's results, or other factors at the company's sole discretion. Bonus amounts and eligibility are not guaranteed and subject to change and cancellation. Please check with your recruiter for more details.