> Markdown version of [/jobs/ext/3588606-cryptography-data-security-platform-engineer-hsm-engineer](https://www.wearedevelopers.com/jobs/ext/3588606-cryptography-data-security-platform-engineer-hsm-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cryptography & Data Security Platform Engineer (HSM Engineer) - **Company:** Indotronix Avani Group - **Location:** Charlotte, NC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cloud Engineering, Configuration Management, Cyber Security, Data Security, Linux, Elasticsearch, Federal Information Processing Standards (FIPS), Firmware, Monitoring of Systems, Identity and Access Management, Python (Programming Language), Key Management, OpenShift, OpenSSL, PCI Data Security Standards, Public Key Infrastructure, Windows PowerShell, Prometheus, Zero Trust Network Access, Runbook, Tokenization, Scripting, Google Cloud, Data Classification, Grafana, Software Troubleshooting, Containerization, Kubernetes, Splunk, Dynatrace, Docker - **Published:** October 5, 2026 - **Apply:** https://candidateportal.ceipal.com/job-details/hgJZLZ545u6t3xydGM62DaYVyVaB2icg_ivq_CCKCU0 ## About the Role Extensive hands-on experience with enterprise cryptographic services and key management platforms (Thales CipherTrust Manager, Luna Network HSM, payShield 10K/10K+, Cloud HSM, Cloud KMS). - Strong PKI HSM engineering expertise and PowerShell (or similar scripting) proficiency. - Deep knowledge of cryptographic standards: OASIS KMIP 2.x, PCI DSS, PCI HSM, NIST SP 800-57, NIST SP 800-131A, FIPS 140-3, GDPR, EMVCo, GlobalPlatform, ANSI. - Proven ability to implement and maintain enterprise data protection controls: key governance, encryption policies, secrets management, tokenization, data classification alignment, compliance monitoring. - Experience with cryptographic API integration: REST, PKCS#11, KMIP, JCE/JCA, Microsoft CNG, OpenSSL, cloud-native SDKs. - Skilled in administering and automating Linux and Windows environments (PowerShell, Python, Infrastructure-as-Code). - Experience with cloud-native/container platforms (Kubernetes, OpenShift, Docker, Helm, CI/CD pipelines). - Familiarity with enterprise monitoring tools (Splunk Enterprise, Dynatrace; Prometheus, Grafana, Elastic Stack, SNMPv3 preferred). - Strong troubleshooting, documentation, and collaboration skills. Preferred Skills - Experience with Azure Key Vault, AWS KMS, Google Cloud KMS, or enterprise cloud KMS platforms. - Knowledge of payment cryptography, PIN/key block concepts, EMVCo/PCI/ANSI payment security. - Familiarity with post-quantum cryptography and crypto-agility initiatives. - Experience building automation workflows, reusable implementation patterns, and operational runbooks. - Hands-on with secrets management and workload identity solutions for Kubernetes and cloud-native environments., Top Requirements: * Strong PKI HSM Engineer experience * PowerShell or similar scripting experience ## Description Job Summary: Senior Cryptography & Data Security Platform Engineer (HSM Engineer), Join a high-impact Global Information Security team as a Senior Cryptography & Data Security Platform Engineer (HSM Engineer). Play a key role in designing, implementing, and supporting enterprise cryptographic services and data security platforms for a leading organization. Collaborate with top-tier architects, cloud engineers, application owners, and security stakeholders to drive cutting-edge security solutions and ensure enterprise data protection across on-premises and cloud environments., Design, deploy, maintain, and support cryptographic services and key management platforms: Thales CipherTrust Manager, Luna Network HSM, payShield 10K/10K+, Cloud HSM, and Cloud KMS. - Administer cryptographic keys through full lifecycle management: generation, activation, rotation, backup, recovery, archival, retirement, and compliance validation. - Translate business and application requirements into secure, scalable, and auditable cryptographic solutions. - Establish and enforce enterprise-wide data protection controls: encryption policies, key governance, secrets management, tokenization, and compliance monitoring. - Integrate cryptographic APIs and frameworks: REST APIs, PKCS#11, KMIP, JCE/JCA, Microsoft CNG, OpenSSL, and cloud-native SDKs. - Engineer and automate Linux and Windows environments using PowerShell, Python, and Infrastructure-as-Code (Ansible, Terraform preferred). - Build, operate, and monitor cloud-native and containerized platforms: Kubernetes, OpenShift, Docker, Helm, CI/CD pipelines. - Perform configuration management, firmware upgrades, vulnerability remediation, patch management, and operational readiness validation for cryptographic infrastructure. - Partner with cross-functional teams to support Zero Trust, machine identity management, crypto-agility, and post-quantum cryptography initiatives. - Maintain robust documentation, runbooks, diagrams, and audit-ready evidence packages.