HSM & PKI Security Engineer
Core
Operate, secure, and support enterprise Hardware Security Module (HSM) and Public Key Infrastructure (PKI) environments, managing cryptographic keys and certificate lifecycles.
Role type
HSM & PKI Security Engineer
Builds
Secure cryptographic key management and certificate services for enterprise applications, databases, and security platforms.
Domain
Cybersecurity, Cryptography, PKI
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
HSM administration, PKI management, cryptographic key protection, certificate lifecycle management, TLS/SSL, X.509, RSA, ECC, AES, high availability, backup and recovery, disaster recovery, Microsoft AD CS, troubleshooting
Preferred skills
Microsoft PKI/AD CS expertise, government cybersecurity environment experience, vendor-specific HSM training
Technologies
Thales Luna HSM, Microsoft Certificate Authority, AD CS, DigiCert, PED/MFA
Responsibilities
Administer Thales Luna HSM infrastructure and partitions; manage cryptographic keys per security policies; support HSM backup, recovery, and cloning; integrate HSM with enterprise applications; manage public certificate issuance, renewal, and revocation; troubleshoot PKI and HSM incidents; maintain documentation and runbooks; support audit and compliance requirements.
Seniority
Mid-Senior, hands-on IC