Description
Job Title: HSM Engineer
Duration: 6–12 Month Contract‑to‑Hire
Location: Chandler, AZ – 5 Days Onsite
Required Pay Scale: $75-80/hr W2 (NO C2C)
***Due to client requirements this role is only open to USC or GC candidates***
Job Description:
HSM Engineer role will be responsible for designing, deploying, configuring, and maintaining Hardware Security Modules used to protect sensitive cryptographic keys and perform secure cryptographic operations. This role ensures the security, availability, and compliance of cryptographic infrastructure in alignment with industry standards, security policies, and regulatory requirements.
Key Responsibilities
- HSM Administration & Operations
- Deploy, configure, and manage HSM devices (, Thales, Entrust, Futurex, Utimaco)
- Maintain and update HSM inventory to ensure up-to-date tracking.
- Submit Firewall request to allow network traffic between HSM and client systems
- Manage HSM partitioning, remote HSM administration and auditing functions.
- Conduct firmware and software upgrades while maintaining operational continuity.
- Ensure HSM configurations meet compliance standards (PCI-DSS, PIN, HIPAA, GDPR, ISO 27001, etc.).
- Monitor for unauthorized access or anomalies in cryptographic operations.
- Participate in internal and external security audits.
- Work with development and infrastructure teams to integrate cryptographic services into business applications.
- Troubleshoot HSM integration issues with applications, APIs, and security services.
- Implement automated monitoring and alerting for HSM performance and health.
- Respond to cryptographic security incidents and investigate root causes.
- Provide on-call support for HSM-related issues and outages
Required Qualifications
• Bachelor’s degree in computer science, Information Security, or related field (or equivalent experience).
• 3–5 years of experience in HSM administration and/or cryptographic operations
• Hands-on experience with HSM vendors such as Thales, Entrust, Futurex, Utimaco, or SafeNet.
• Strong understanding of PKI, digital certificates, TLS/SSL, and key management practices.
• Familiarity with security standards: FIPS 140-2/140-3, NIST SP 800 series, PCI-DSS.
• Experience with scripting languages (Python, PowerShell, Bash) for automation.
Preferred Qualifications
• Cloud HSM experience (AWS CloudHSM, Azure Key Vault Managed HSM, GCP Cloud HSM).
• Certification such as CISSP, CISM, CCSP, or vendor-specific HSM certification.
• Experience with hardware cryptography in payment systems, banking, or government environments.
• Knowledge of secure application development and API security.
Soft Skills
• Strong problem-solving and analytical skills.
• Ability to work under pressure in high-security environments.
• Excellent communication and documentation skills.
• Ability to collaborate with cross-functional teams.
Working Conditions
• May require occasional travel for HSM installation or maintenance.
• On-call rotation for 24/7 HSM support.
About Matlen Silver
Experience Matters. Let your experience be driven by our experience. For more than 40 years, Matlen Silver has delivered solutions for complex talent and technology needs to Fortune 500 companies and industry leaders. Led by hard work, honesty, and a trusted team of experts, we can say that Matlen Silver technology has created a solutions experience and legacy of success that is the difference in the way the world works.
Matlen Silver is an Equal Opportunity Employer and considers all applicants for all positions without regard to race, color, religion, gender, national origin, age, sexual orientation, veteran status, the presence of a non-job-related medical condition or disability, or any other legally protected status.
If you are a person with a disability needing assistance with the application or at any point in the hiring process, please contact us at email and/or phone at: // 908-393-8600