Cryptography & Data Security Platform Engineer (HSM Engineer)

Indotronix Avani Group
Charlotte, NC, United States
2 days ago
Apply on candidateportal.ceipal.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Cloud Computing Cloud Engineering Configuration Management Cyber Security Data Security Linux Elasticsearch Federal Information Processing Standards (FIPS) Firmware Monitoring of Systems Identity and Access Management Python (Programming Language)
+20 more
Key Management OpenShift OpenSSL PCI Data Security Standards Public Key Infrastructure Windows PowerShell Prometheus Zero Trust Network Access Runbook Tokenization Scripting Google Cloud Data Classification Grafana Software Troubleshooting Containerization Kubernetes Splunk Dynatrace Docker

Job description

Job Summary: Senior Cryptography & Data Security Platform Engineer (HSM Engineer), Join a high-impact Global Information Security team as a Senior Cryptography & Data Security Platform Engineer (HSM Engineer). Play a key role in designing, implementing, and supporting enterprise cryptographic services and data security platforms for a leading organization. Collaborate with top-tier architects, cloud engineers, application owners, and security stakeholders to drive cutting-edge security solutions and ensure enterprise data protection across on-premises and cloud environments., Design, deploy, maintain, and support cryptographic services and key management platforms: Thales CipherTrust Manager, Luna Network HSM, payShield 10K/10K+, Cloud HSM, and Cloud KMS.

  • Administer cryptographic keys through full lifecycle management: generation, activation, rotation, backup, recovery, archival, retirement, and compliance validation.
  • Translate business and application requirements into secure, scalable, and auditable cryptographic solutions.
  • Establish and enforce enterprise-wide data protection controls: encryption policies, key governance, secrets management, tokenization, and compliance monitoring.
  • Integrate cryptographic APIs and frameworks: REST APIs, PKCS#11, KMIP, JCE/JCA, Microsoft CNG, OpenSSL, and cloud-native SDKs.
  • Engineer and automate Linux and Windows environments using PowerShell, Python, and Infrastructure-as-Code (Ansible, Terraform preferred).
  • Build, operate, and monitor cloud-native and containerized platforms: Kubernetes, OpenShift, Docker, Helm, CI/CD pipelines.
  • Perform configuration management, firmware upgrades, vulnerability remediation, patch management, and operational readiness validation for cryptographic infrastructure.
  • Partner with cross-functional teams to support Zero Trust, machine identity management, crypto-agility, and post-quantum cryptography initiatives.
  • Maintain robust documentation, runbooks, diagrams, and audit-ready evidence packages.

Requirements

Extensive hands-on experience with enterprise cryptographic services and key management platforms (Thales CipherTrust Manager, Luna Network HSM, payShield 10K/10K+, Cloud HSM, Cloud KMS).

  • Strong PKI HSM engineering expertise and PowerShell (or similar scripting) proficiency.
  • Deep knowledge of cryptographic standards: OASIS KMIP 2.x, PCI DSS, PCI HSM, NIST SP 800-57, NIST SP 800-131A, FIPS 140-3, GDPR, EMVCo, GlobalPlatform, ANSI.
  • Proven ability to implement and maintain enterprise data protection controls: key governance, encryption policies, secrets management, tokenization, data classification alignment, compliance monitoring.
  • Experience with cryptographic API integration: REST, PKCS#11, KMIP, JCE/JCA, Microsoft CNG, OpenSSL, cloud-native SDKs.
  • Skilled in administering and automating Linux and Windows environments (PowerShell, Python, Infrastructure-as-Code).
  • Experience with cloud-native/container platforms (Kubernetes, OpenShift, Docker, Helm, CI/CD pipelines).
  • Familiarity with enterprise monitoring tools (Splunk Enterprise, Dynatrace; Prometheus, Grafana, Elastic Stack, SNMPv3 preferred).
  • Strong troubleshooting, documentation, and collaboration skills.

Preferred Skills

  • Experience with Azure Key Vault, AWS KMS, Google Cloud KMS, or enterprise cloud KMS platforms.
  • Knowledge of payment cryptography, PIN/key block concepts, EMVCo/PCI/ANSI payment security.
  • Familiarity with post-quantum cryptography and crypto-agility initiatives.
  • Experience building automation workflows, reusable implementation patterns, and operational runbooks.
  • Hands-on with secrets management and workload identity solutions for Kubernetes and cloud-native environments., Top Requirements: * Strong PKI HSM Engineer experience * PowerShell or similar scripting experience

Benefits & conditions

Work at the forefront of cryptographic engineering and enterprise data security.

  • Collaborate with leading experts in a dynamic, high-visibility information security team.
  • Access to professional development and training on the latest cryptographic technologies.
  • Competitive compensation and benefits package.
  • Opportunity for career advancement in a mission-critical, regulated environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on candidateportal.ceipal.com
Prepare application

Good distractions

Loading talks and stories from around this role…