6 months +Contract-San Francisco CA
Remote role
Pay $100 on w-2
Key Management Engineer
Role Overview : We are seeking a skilled Key Management Engineer to join our team, with expertise in the architecture and tools for both symmetric and asymmetric key management, including Public Key Infrastructure (PKI). This role requires experience managing cryptographic keys for applications, databases, infrastructure, including storage subsystems, and working with cloud-based tools and solutions. A solid understanding of infrastructure utilizing cryptographic keys, experience with Hardware Security Modules (HSMs), basic development skills in Java and Python, and strong documentation and execution abilities are essential.
Key Responsibilities :
- Design and implement architectures for symmetric and asymmetric key management solutions with a focus on PKI.
- Manage and maintain cryptographic key infrastructure services, including key lifecycle management processes from creation to retirement.
- Deploy and secure cryptographic keys for applications, databases, infrastructure, and storage subsystems, ensuring adherence to security standards and best practices.
- Utilize and configure tools and products for key management, including those used in cloud environments such as AWS KMS, Azure Key Vault, and Google Cloud Key Management Service.
- Integrate key management solutions into existing infrastructure, collaborating with cross-functional teams to ensure comprehensive security measures.
- Configure, deploy, and manage Hardware Security Modules (HSMs) for secure key storage and operations, utilizing products like Thales, Gemalto, or SafeNet.
- Develop scripts and applications using Java and Python to automate key management tasks and processes.
- Document key management procedures, policies, and architecture designs to enhance operational efficiency and facilitate effective knowledge transfer.
- Conduct regular assessments and audits of cryptographic systems to ensure compliance with industry best practices and standards.
- Provide training and guidance to technical teams on key management best practices and security protocols.
Qualifications :
Proven experience in designing and implementing key management solutions, with emphasis on symmetric and asymmetric cryptography, including PKI.Experience in key lifecycle management processes, involving key creation, distribution, rotation, and revocation.Ability to deploy and secure cryptographic keys effectively for applications, databases, infrastructure, and storage subsystems.Strong understanding of key management infrastructure and protocols, including HSM configurations and operations.Experience with cloud-based key management tools like AWS KMS, Azure Key Vault, and Google Cloud Key Management Service.Basic development skills in Java and Python with the ability to script and automate routine processes.Hands-on experience with key management tools and products such as Thales HSM, Gemalto HSM, SafeNet, Microsoft Active Directory Certificate Services, OpenSSL, etc.Excellent documentation skills, able to produce clear and comprehensive technical documents and user guides.Strong analytical and problem-solving skills to troubleshoot complex issues.Demonstrated experience working in environments requiring strict security and compliance standards, familiar with frameworks like NIST, ISO 27001, and CIS.Technical Skills :
Familiarity with network security concepts and secure communication protocols.Understanding of cloud security concepts and practices.Knowledge of network security concepts and secure communication protocols.Experience with security standards and frameworks (e.g., NIST, ISO 27001).Preferred Qualifications :
Bachelor's degree in Computer Science, Information Security, or a related field.Experience with security operations tools and best practices.Application Process : Interested candidates should submit their resume along with a cover letter detailing relevant experience and qualifications. This role represents an excellent opportunity to contribute substantially to the security infrastructure