Specialty Software Engineer 3 / Cryptography & Confidential Computing EngineerClient: Financial Services / Digital Assets PlatformLocation: CA (assumed hybrid or aligned with enterprise hubs)Contract Length: 12moPay Rate: $70 - $75Top Requirements:7+ years of systems-level engineering with strong Go and Rust expertiseDeep experience with applied cryptography, specifically MPC and threshold signature schemesHands-on experience with Confidential Computing (TEE technologies like AMD SEV-SNP, Intel SGX/TDX)Plusses:Experience with attestation frameworks (RATS, Key Broker Services)Experience with Kubernetes and confidential containers (CoCo)Experience with WebAuthn/FIDO2 or identity integrationsExperience in digital asset custody, fintech, or high-security environmentsFamiliarity with CNCF Trustee or similar frameworksJob Summary:In this contingent resource assignment, you may: Consult on or participate in moderately complex initiatives and deliverables within Specialty Software Engineering and contribute to large-scale planning related to Specialty Software Engineering deliverables. Review and analyze moderately complex challenges requiring in-depth evaluation of variable factors. Contribute to the resolution of moderately complex issues while leveraging strong understanding of policies, procedures, and compliance requirements.
Collaborate with client personnel in Specialty Software Engineering.Day-to-Day Responsibilities:Cryptography & MPC Engineering:Design and implement threshold cryptography and MPC protocols (e.g., DKLS23, GG20)Build high-performance ECDSA key generation and signing systemsEnsure cryptographic operations are secure, scalable, and auditableConfidential Computing & Secure Enclaves:Develop services running inside Trusted Execution Environments (AMD SEV-SNP, Intel TDX/SGX)Implement confidential container solutions for secure executionWrite memory-safe code (Rust/Go) ensuring zero exposure of sensitive key materialAttestation & Security Architecture:Design and implement RATS-based attestation workflowsIntegrate Key Broker Services (KBS) and attestation servicesEnsure hardware/software integrity verification before key usageInfrastructure & Platform Engineering:Build secure systems where cloud infrastructure is treated as untrustedDesign defense-in-depth architectures across distributed environmentsSupport orchestration and deployment using modern container platformsSecure Key Management & Recovery:Design "cold ceremony" workflows using offline hardware tokens (KEKs)Support disaster recovery and long-term secure storage mechanismsIntegrate hardware-based security controls into platform architecturePolicy & Business Logic Integration:Bind business approvals (e.g., WebAuthn assertions) directly to cryptographic signing flowsEliminate gaps between approval and execution through cryptographic controlsEnsure compliance and enforceability within transaction workflows