Job Description
We are seeking a highly skilled experienced Security Engineer with hands-on
experience in implementing and supporting Encryption, Public Key
Infrastructure (PKI), and Hardware Security Modules (HSM). In this role, you
will be responsible for deploying and maintaining security solutions to
protect customer’s data and systems. Your expertise will be critical in
managing certificate lifecycles, implementing encryption protocols, and
ensuring secure key management practices across various environments. This
position offers an excellent opportunity to play a key role in supporting
encryption systems, PKI frameworks, and HSM technologies while collaborating
with relevant teams to ensure compliance with industry standards and best
practices.
Responsibilities
-
Implement and Support Encryption Systems:
Deploy and configure encryption solutions to secure data both at rest and in
transit. Manage encryption protocols and key management practices.
-
PKI Management:
Oversee the full lifecycle of certificates, including issuance, renewal,
revocation, and troubleshooting PKI-related issues. Ensure seamless
integration of PKI into applications and infrastructure.
-
HSM Management:
Implement and maintain Hardware Security Modules (HSMs) for secure key
generation, storage, and lifecycle management. Provide ongoing support and
troubleshooting for HSM-related issues.
-
Incident Support:
Resolve security incidents related to encryption, PKI, and HSM technologies,
working quickly to mitigate risks and maintain system integrity.
-
Collaboration and Integration:
Work with cross-functional teams to integrate encryption, PKI, and HSM
technologies into our infrastructure and applications.
-
Compliance & Reporting:
Ensure that all encryption and key management solutions adhere to industry
standards and regulatory compliance requirements (e.g., GDPR, HIPAA,
PCI-DSS). Assist in audits and provide documentation as needed.
Requirements
-
Experience:
2-4 years of hands-on experience in implementing and supporting Encryption,
PKI, and HSM technologies in a production environment.
-
Skills:
-
Strong understanding of encryption algorithms (e.g., RSA, AES, ECC) and
cryptographic protocols (SSL/TLS, IPsec, etc.).
-
Experience with PKI management, including certificate lifecycle
management, digital certificates, and SSL/TLS integration.
-
Practical experience with Hardware Security Modules (HSM), including key
management and troubleshooting.
-
Familiarity with encryption libraries and tools (e.g., OpenSSL,
Keyfactor, etc.).
-
Good to have experience with Thales’s products (e.g., Thales
CipherTrust, Thales HSM) is a plus.
-
Problem Solving:
Strong troubleshooting and analytical skills to resolve complex issues in a
timely manner.
-
Compliance:
Understanding of industry standards and regulatory requirements (e.g., NIST,
FIPS, PCI-DSS).
-
Collaboration:
Ability to work well with cross-functional teams, including IT, DevOps, and
security teams.
-
Communication:
Strong written and verbal communication skills with the ability to explain
complex technical concepts to non-technical stakeholders.
Nice to Have
-
Certifications:
Relevant certifications such as CISSP, CISM, or vendor-specific
certifications (e.g., Thales HSM certifications).
-
Cloud Security:
Familiarity with cloud environments and key management solutions (e.g., AWS
KMS, Azure Key Vault).