> Markdown version of [/jobs/ext/2209327-cryptographic-security-engineer](https://www.wearedevelopers.com/jobs/ext/2209327-cryptographic-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cryptographic Security Engineer - **Company:** CITIZENS INC - **Location:** Westwood, MA, United States - **Experience:** Experienced - **Salary:** $80,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Bash Shell, Cloud Computing, Configuration Management Databases, Cyber Security, Hardware Security Module, Python (Programming Language), Key Management, Public Key Infrastructure, X.509, Windows PowerShell, Systems Integration, Scripting, Software Troubleshooting, Api Design, Restful APIs, Security Orchestration, Automation & Response, Servicenow - **Published:** August 24, 2026 - **Apply:** https://dejobs.org/x/x/C6A2AD10CB8143669A971E708AD6E9E9/job/ ## About the Role * 3+ years of experience in Information Security, PKI, Cryptography, Infrastructure Security, or Security Engineering. * Experience implementing, supporting, or administering enterprise certificate management solutions. * Working knowledge of: * TLS and X.509 certificates * PKI concepts and certificate lifecycle management * Cryptographic key management * Hardware Security Modules (HSMs) ## Description The Cryptographic Engineer is a hands-on technical role responsible for supporting, implementing, and improving the organization's cryptographic platforms with a strong emphasis on operational stability, automation, and risk reduction. This role operates at the intersection of Cryptography, PKI, Certificate Lifecycle Management, Cloud Key Management, and Security Automation. The engineer will help maintain and enhance cryptographic services while contributing to strategic initiatives such as certificate lifecycle automation, cloud encryption adoption, and post-quantum cryptography readiness. Responsibilities Cryptographic Engineering & Operations * Support and enhance enterprise cryptographic platforms including: * Public Key Infrastructure (PKI) * TLS and certificate lifecycle management * Cloud key management services (AWS KMS, Azure Key Vault) * Hardware Security Modules (HSMs) * Apply cryptographic best practices related to: * Cryptographic algorithms and protocols * Key management and protection * Certificate trust models and lifecycle controls * Perform and support day-to-day cryptographic operations including: * Certificate issuance, renewal, revocation, and validation * Key rotation and lifecycle management activities * Monitoring and responding to certificate and encryption-related incidents * Troubleshooting cryptographic service disruptions and operational issues * Hands-on experience with one or more of the following: * Venafi (TLS Protect / Trust Protection Platform) or equivalent certificate management solutions * Thales CipherTrust, Luna HSM, or similar key management technologies * ServiceNow workflows, CMDB, or operational processes * Experience with scripting or automation using: * Python * PowerShell * Bash or similar languages * Familiarity with REST APIs and system integrations. * Strong troubleshooting, analytical, and problem-solving skills. * Assist with API-based integrations to improve certificate and key management processes. Post-Quantum Cryptography & Emerging Technologies * Participate in the organization's post-quantum cryptography (PQC) readiness initiatives by: * Assisting with cryptographic inventory efforts * Identifying quantum-vulnerable algorithms and systems * Supporting crypto-agility assessments * Evaluating emerging cryptographic technologies and standards * Stay current with industry developments including NIST guidance, PQC standards, and evolving cryptographic best practices. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)