HSM & PKI Security Engineer
Core
Operate, secure, and support enterprise Hardware Security Module (HSM) and Public Key Infrastructure (PKI) environments, managing cryptographic keys and certificate lifecycles.
Role type
HSM & PKI Security Engineer
Builds
Secure cryptographic key management and certificate services for enterprise applications, databases, and security platforms.
Domain
Cybersecurity, Cryptography, PKI
Required skills
HSM administration, PKI management, cryptographic key protection, certificate lifecycle management, TLS/SSL, X.509, RSA, ECC, AES, high availability, backup and recovery, disaster recovery, Microsoft AD CS, troubleshooting
Preferred skills
Microsoft PKI/AD CS expertise, government cybersecurity environment experience, vendor-specific HSM training
Technologies
Thales Luna HSM, Microsoft Certificate Authority, AD CS, DigiCert, PED/MFA
Responsibilities
Administer Thales Luna HSM infrastructure and partitions; manage cryptographic keys per security policies; support HSM backup, recovery, and cloning; integrate HSM with enterprise applications; manage public certificate issuance, renewal, and revocation; troubleshoot PKI and HSM incidents; maintain documentation and runbooks; support audit and compliance requirements.
Seniority
Mid-Senior, hands-on IC