> Markdown version of [/jobs/ext/3432564-hsm-security-engineer](https://www.wearedevelopers.com/jobs/ext/3432564-hsm-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # HSM Security Engineer - **Company:** American CyberSystems - **Location:** Addison, TX, United States - **Experience:** Expert - **Salary:** $166,400.0 - $176,800.0 - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Agile Methodology, JIRA, Microsoft Azure, Cipher, Cloud Computing, Cloud Computing Security, Cloud Engineering, Configuration Management, Databases, Database Encryption, Linux, Elasticsearch, Federal Information Processing Standards (FIPS), Firmware, Identity and Access Management, Python (Programming Language), Key Management, PostgreSQL, Microsoft SQL Server, OpenShift, OpenSSL, Oracle (Applications), PCI Data Security Standards, Windows PowerShell, Scrum Methodology, Systems Development Life Cycle, Ansible, Prometheus, Zero Trust Network Access, Swagger, Tokenization, Software Vulnerability Management, Openapi, SSL Certificate Management, Cloud Platform System, Data Classification, Postman, Spring Cloud, Grafana, Git Flow, Kubernetes, Patch Management, Integration Frameworks, Api Gateway, Restful APIs, Terraform, Splunk, Dynatrace, Devsecops, Docker - **Published:** September 7, 2026 - **Apply:** https://www.disabledperson.com/jobs/74950192-hsm-security-engineer ## About the Role * 5+ years of experience in HSM. * 3+ years of experience in Thales product such as Luna and/or Cipher Trust Manager (CTM). * 3+ years of experience in key Management products - Thales payShield, SafeNet HSM, Azure Key Vault (AKV), AWS KMS., * Experience implementing enterprise Key Lifecycle Management (KLM), cryptographic policy enforcement, and automated certificate management across on-premises and cloud environments. * Ability to partner with application owners, architects, cloud teams, and security stakeholders to define and implement cryptographic controls, key management strategies, and HSM/KMS service requirements. * Knowledge of database encryption technologies, including: * Microsoft SQL Server TDE and EKM * Oracle TDE * PostgreSQL encryption * KMIP and PKCS#11-based key management integrations * Experience with enterprise secrets management and workload identity solutions for Kubernetes and cloud-native applications. * Familiarity with Post-Quantum Cryptography (PQC), crypto-agility initiatives, and quantum-safe migration strategies. ## Description Mid-level Senior Security Engineer is responsible for security design, implementing and maintain vendor security applications primarily related to crypto/security functions and modules. These requirements will then be used to make you determine and recommend the technical and operational feasibility of the solutions in the crypto space. You will be required to maintain and enhance hosted crypto solutions like key management, payment, and general purpose HSMs which are integrated with end user applications so that they are compliant to the banks, as well as industry standards of key security. You would work to develop prototypes of the system design and work with database, operations, technical support, and other various technocrats throughout the proof of concept and implementation cycle. You will use your knowledge and abilities as senior technical resources to provide your expertise to the team(s). You would also be responsible for administering and managing cryptographic keys, including key life cycle management, centrally managing keys with granular key management and proper access controls per our security standards and policy guidance. Required Experience * Design, implement, and support enterprise cryptographic services and key management platforms, including Thales CipherTrust Manager, Luna Network HSM, payShield 10K/10K+, Cloud HSM, and Cloud KMS solutions. * Enforce cryptographic architectures aligned with industry standards and frameworks including OASIS KMIP 2.x, PCI DSS, PCI HSM, NIST SP 800-57, NIST SP 800-131A, FIPS 140-3, GDPR, EMVCo, GlobalPlatform, and ANSI standards. * Establish and maintain enterprise-wide data protection controls, including data classification, encryption policies, key governance, secrets management, tokenization, and compliance monitoring. * Hands-on experience administering and automating Linux and Windows environments using modern Infrastructure-as-Code and automation frameworks such as PowerShell, Python, and GitOps methodologies. Ansible and Terraform are nice to have. * Strong understanding of cryptographic APIs and integration frameworks including REST APIs, PKCS#11, KMIP, JCE/JCA, Microsoft CNG, MSCAPI, OpenSSL, and cloud-native security SDKs. * Design and operate cloud-native and containerized platforms using Kubernetes, OpenShift, Podman, Docker, Helm, and CI/CD pipelines. * Experience implementing and testing APIs using modern development and integration tools such as Postman, Insomnia, Swagger/OpenAPI, and API Gateway platforms. * Implement enterprise observability and operational monitoring using Splunk Enterprise, Dynatrace. Other tools like Prometheus, Grafana, Elastic Stack, and SNMPv3 monitoring solutions are nice to have. * Utilize Agile, Scrum, Kanban, DevSecOps, Jira, Azure DevOps, and SDLC best practices to support secure and efficient platform delivery. * Perform lifecycle management, configuration management, firmware upgrades, vulnerability remediation, patch management, and compliance validation for cryptographic infrastructure. * Support enterprise adoption of Zero Trust security principles, machine identity management, certificate automation, and Post-Quantum Cryptography (PQC) readiness programs.