Security Engineer
Role details
Job location
Tech stack
Job description
Mid-level Security Engineer is responsible for security design, implement and maintain vendor security applications primarily related to crypto/security functions and modules. You would be part of the highly visible Global Information Security (GIS) team where you will gain an in-depth understanding of the business partner's requirements for the applications/systems. These requirements will then be used to make you determine and recommend the technical and operational feasibility of the solutions in the crypto space. You will be required to maintain and enhance hosted crypto solutions like key management, payment, and general purpose HSMs which are integrated with end user applications so that they are compliant to the banks, as well as industry standards of key security. You would work to develop prototypes of the system design and work with database, operations, technical support, and other various technocrats throughout the proof of concept and implementation cycle. You will use your knowledge and abilities as technical resource to provide your expertise to the team(s). You would also be responsible for administering and managing cryptographic keys, including key life cycle management, centrally manage keys with granular key management and proper access controls per our security standards and policy guidance.
Requirements
Implement Best practices per the Oasis KMIP 2 standards, EMVCo, Global Platform, Multos, ANSI, FIPS140-2, NIST SP 800-57, PCI DSS and GDPR. Crypto compliances per industry standards including Data classification, policies, and data standards, Content filtering. Must have hands on experience with Windows/ Linux plateform as you would being working on OpenShift and other Ansible solutions. RESTful services, cloud native applications, PKCS#11, JCE, .NET, MCCAPI, MS CNG Hands on experience with scalable systems using Kubernetes and OpenShift or Container orchestration technologies. Ability to implement REST API consoles example Postman, Insomnia. Full-stack monitoring using log ingress solutions with Splunk and SNMP v3.0 Data security platform engineering Agile methodologies especially kanban for productivity and efficiency. Configuration, patching and lifecycle management of cryptographic devices. Strategize cloud migration and implementation of cloud HSM and cloud KMS using AKV, AWS, Google Cloud Platform etc... Skills pki, Thales, security, CipherTrust, Linux, Automation Top Skills Details pki,Thales,security Additional Skills & Qualifications Desired (Good to have) experience: HSM and key Management products - Thales payShield, SafeNet HSM, Azure Key Vault (AKV), AWS KMS. Key life cycle management and policy enforcement across environments. Understand and implement enterprise cryptography standards per industry. Specialize in crypto products like Thales CipherTrust Manager, Hardware Security Modules and Payshield 10x. Work closely with stakeholders to define crypto requirement for KMS and HSM needs. Database encryption with Microsoft SQL TDE, Oracle TDE with PKCS11 and KMIP compliant products. Experience Level Intermediate Level
Benefits & conditions
This is a Contract position based out of Addison, TX. Pay and Benefits The pay range for this position is $65.00 - $75.00/hr. Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: Medical, dental & vision Critical Illness, Accident, and Hospital 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available Life Insurance (Voluntary Life & AD&D for the employee and dependents) Short and long-term disability Health Spending Account (HSA) Transportation benefits Employee Assistance Program Time Off/Leave (PTO, Vacation or Sick Leave) Workplace Type This is a fully onsite position in Addison,TX.