Epicareer Might not Working Properly
Learn More

Engineering Lead-Key Management

Salary undisclosed

Checking job availability...

Original
Simplified

Engineering Lead Key Management with expertise in cryptographic key and certificate management to design, develop, and maintain automation solutions that enhance the security, efficiency, and scalability of our enterprise cryptographic infrastructure. This role will focus on integrating key management systems (KMS), public key infrastructure (PKI), and hardware security modules (HSMs) with enterprise applications, cloud environments, IoT and DevSecOps workflows.

The Ideal candidate has experience with the secure automation, scripting, API development, and integrating cryptographic solutions within financial or highly regulated environments.

This role can be performed in a hybrid model, where you can balance work from home and office to match your needs and role requirements.

What you will be responsible for

  • Lead a team of developers and engineers in designing and implementing cryptographic automation and integrations solutions.
  • Provide technical direction and mentorship, ensuring best practices in secure coding, automation, and cryptographic integrations.
  • Collaborate with senior stakeholders, including security architects, compliance teams, and DevSecOps leads to define and drive key management strategies.
  • Design and implement integrations between cryptographic key and certificate management systems and enterprise applications, cloud platforms, and security tools.
  • Develop and maintain APIs, microservices, and automation scripts to streamline cryptographic operations.
  • Enable seamless integration with multi-cloud key management services (AWS KMS, Azure Key Vault, OCI KMS)
  • Collaborate with security architects, application teams, and DevSecOps engineers to embed encryption and certificate management into CI/CD pipelines.
  • Automate key lifecycle processes such as key generation, rotation, distribution, revocation and decommissioning.
  • Implement certificate automation solutions (ACME protocol, automated issuance/renewal via API-driven PKI).
  • Build monitoring and alerting mechanisms to detect cryptographic anomalies and improve operational efficiency.
  • Ensure automation and integrations align with cryptographic policies, compliance and regulations (PCI DSS, GDPR, FIPS 140-2/3), and security best practices.
  • Work closely with risk and compliance teams to provide audit trails and access control mechanisms for key and certificate operations.
  • Assist in vulnerability management and patching of cryptographic components and automation workflows.
  • Troubleshoot integration and automation issues, ensuring high availability and reliability of cryptographic services.
  • Stay up to date on emerging encryption technologies, cloud security trends, and automation frameworks.
  • Provide technical documentation and training for internal teams on cryptographic integration best practices.

Education & Preferred Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field. Advanced degree or certifications (e.g., CISSP, CISM) preferred or equivalent work experience.
  • Strong proficiency in Python, PowerShell, Bash, or Java for automation and integrations.
  • Experience with RESTful APIs, JSON, XML, and WebSockets to integrate key management solutions
  • Hands-on Experience with key management systems (HashiCorp Vault, ASW KMS, Azure Key Vault, OCI KMS).
  • Familiarity with X.509 certificates, PKI automation, TLS/SSL, ACME protocol, and certificate lifecycle management.
  • Experience with Kubernetes, Terraform, Ansible, Chef, and CI/CD automation.
  • Understanding of cryptographic algorithms (AES, RSA, ECC), hardware security modules (HSMs), and secure key storage practices.
  • Experience working in financial institutions or other highly regulated industries.
  • Knowledge of blockchain technology and its cryptographic principles is a plus.
  • Certifications such as CISSP, CISM, AWS Security Specialty, HashiCorp Certified Vault Associate or CCSK.
  • Familiarity with security frameworks such as NIST 800-57, ISO 27001 or PCI DSS.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job

Engineering Lead Key Management with expertise in cryptographic key and certificate management to design, develop, and maintain automation solutions that enhance the security, efficiency, and scalability of our enterprise cryptographic infrastructure. This role will focus on integrating key management systems (KMS), public key infrastructure (PKI), and hardware security modules (HSMs) with enterprise applications, cloud environments, IoT and DevSecOps workflows.

The Ideal candidate has experience with the secure automation, scripting, API development, and integrating cryptographic solutions within financial or highly regulated environments.

This role can be performed in a hybrid model, where you can balance work from home and office to match your needs and role requirements.

What you will be responsible for

  • Lead a team of developers and engineers in designing and implementing cryptographic automation and integrations solutions.
  • Provide technical direction and mentorship, ensuring best practices in secure coding, automation, and cryptographic integrations.
  • Collaborate with senior stakeholders, including security architects, compliance teams, and DevSecOps leads to define and drive key management strategies.
  • Design and implement integrations between cryptographic key and certificate management systems and enterprise applications, cloud platforms, and security tools.
  • Develop and maintain APIs, microservices, and automation scripts to streamline cryptographic operations.
  • Enable seamless integration with multi-cloud key management services (AWS KMS, Azure Key Vault, OCI KMS)
  • Collaborate with security architects, application teams, and DevSecOps engineers to embed encryption and certificate management into CI/CD pipelines.
  • Automate key lifecycle processes such as key generation, rotation, distribution, revocation and decommissioning.
  • Implement certificate automation solutions (ACME protocol, automated issuance/renewal via API-driven PKI).
  • Build monitoring and alerting mechanisms to detect cryptographic anomalies and improve operational efficiency.
  • Ensure automation and integrations align with cryptographic policies, compliance and regulations (PCI DSS, GDPR, FIPS 140-2/3), and security best practices.
  • Work closely with risk and compliance teams to provide audit trails and access control mechanisms for key and certificate operations.
  • Assist in vulnerability management and patching of cryptographic components and automation workflows.
  • Troubleshoot integration and automation issues, ensuring high availability and reliability of cryptographic services.
  • Stay up to date on emerging encryption technologies, cloud security trends, and automation frameworks.
  • Provide technical documentation and training for internal teams on cryptographic integration best practices.

Education & Preferred Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field. Advanced degree or certifications (e.g., CISSP, CISM) preferred or equivalent work experience.
  • Strong proficiency in Python, PowerShell, Bash, or Java for automation and integrations.
  • Experience with RESTful APIs, JSON, XML, and WebSockets to integrate key management solutions
  • Hands-on Experience with key management systems (HashiCorp Vault, ASW KMS, Azure Key Vault, OCI KMS).
  • Familiarity with X.509 certificates, PKI automation, TLS/SSL, ACME protocol, and certificate lifecycle management.
  • Experience with Kubernetes, Terraform, Ansible, Chef, and CI/CD automation.
  • Understanding of cryptographic algorithms (AES, RSA, ECC), hardware security modules (HSMs), and secure key storage practices.
  • Experience working in financial institutions or other highly regulated industries.
  • Knowledge of blockchain technology and its cryptographic principles is a plus.
  • Certifications such as CISSP, CISM, AWS Security Specialty, HashiCorp Certified Vault Associate or CCSK.
  • Familiarity with security frameworks such as NIST 800-57, ISO 27001 or PCI DSS.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job