IT Security Specialist III
Role details
Job location
Tech stack
Job description
Mid-level Senior Security Engineer is responsible for security design, implement and maintain vendor security applications primarily related to crypto/security functions and modules. You would be part of the highly visible Global Information Security (GIS) team where you will gain an in-depth understanding of the business partner's requirements for the applications/systems. These requirements will then be used to make you determine and recommend the technical and operational feasibility of the solutions in the crypto space. You will be required to maintain and enhance hosted crypto solutions like key management, payment, and general purpose HSMs which are integrated with end user applications so that they are compliant to the banks, as well as industry standards of key security. You would work to develop prototypes of the system design and work with database, operations, technical support, and other various technocrats throughout the proof of concept and implementation cycle. You will use your knowledge and abilities as senior technical resource to provide your expertise to the team(s). You would also be responsible for administering and managing cryptographic keys, including key life cycle management, centrally manage keys with granular key management and proper access controls per our security standards and policy guidance.
Requirements
- 5+ years of experience in HSM and key Management products - Thales payShield, SafeNet HSM, Azure Key Vault (AKV), AWS KMS.
- Key life cycle management and policy enforcement across environments., * Implement Best practices per the Oasis KMIP 2 standards, EMVCo, Global Platform, Multos, ANSI, FIPS140-2, NIST SP 800-57, PCI DSS and GDPR. Crypto compliances per industry standards including Data classification, policies, and data standards, Content filtering.
- Must have hands on experience with Windows/ Linux plateform as you would being working on OpenShift and other Ansible solutions.
- RESTful services, cloud native applications, PKCS#11, JCE, .NET, MCCAPI, MS CNG
- Hands on experience with scalable systems using Kubernetes and OpenShift or Container orchestration technologies.
- Ability to implement REST API consoles example Postman, Insomnia.
- Full-stack monitoring using log ingress solutions with Splunk and SNMP v3.0
- Data security platform engineering
- Agile methodologies especially kanban for productivity and efficiency.
- Configuration, patching and lifecycle management of cryptographic devices.
- Strategize cloud migration and implementation of cloud HSM and cloud KMS using AKV, AWS, GCP etc
Desired (Good to have) experience:
- HSM and key Management products - Thales payShield, SafeNet HSM, Azure Key Vault (AKV), AWS KMS.
- Key life cycle management and policy enforcement across environments.
- Understand and implement enterprise cryptography standards per industry. Specialize in crypto products like Thales CipherTrust Manager, Hardware Security Modules and Payshield 10x.
- Work closely with stakeholders to define crypto requirement for KMS and HSM needs.
- Database encryption with Microsoft SQL TDE, Oracle TDE with PKCS11 and KMIP compliant products.
Benefits & conditions
Pay Range*: $71 - $76 per hour *Pay range offered to a successful candidate will be based on several factors, including the candidate's education, work experience, work location, specific job duties, certifications, etc.
Benefits: Innova Solutions offers benefits( based on eligibility) that include the following: Medical & pharmacy coverage, Dental/vision insurance, 401(k), Health saving account (HSA) and Flexible spending account (FSA), Life Insurance, Pet Insurance, Short term and Long term Disability, Accident & Critical illness coverage, Pre-paid legal & ID theft protection, Sick time, and other types of paid leaves (as required by law), Employee Assistance Program (EAP).