Lead Info Security EngineerThe Encryption & Key Management (EKM) Team within Cyber Security Org owns the Public Key Infrastructure (PKI), and is responsible for certificate lifecycle management, distribution, and key management. The deployed solutions have various integrations from provisioning certs & keys to protect data at rest and in-transit, to signing code binaries, identifying users and devices, etc. The Lead Security Engineer is expected to provide engineering support required to build and maintain internal and external PKI systems, libraries, and automation. They are expected to be self-starter, have a strong work ethic, leverage analytical and critical thinking and be resourceful in working as part of a global team.
The role requires interfacing with other business units so the candidate must have strong verbal and written communication skills.Key Responsibilities and Duties:Participates in key ceremoniesProvides engineering support for critical EKM systems and services including on premise and cloud-based PKI/CLM servers, HSMs, and KMS.Ensures the execution of enterprise EKM standards and best practices while onboarding new uses cases and configuring existing systems.Reports identified gaps in encryption/CLM implementation and mis/unclassified data discovered through testing, peer discussions and evaluation procedures.Partners with application teams to design, develop, and implement encryption system integrations with the goal of protecting company/client data based on data classification.Documents system configurations and new operational procedures.Top Skills Required for this Role:Public Key Infrastructure (PKI)Encryption & Key Management (EKM)Scripting language (Python, PowerShell, Golang, Ruby, Bash, Perl, etc.)Additional Information:Team Size - 3 No Direct reports.Required skills:5+ years of experience working as a Security Engineer3+ years of experience with public key infrastructure (PKI)3+ years of experience with at least one scripting language (Python, PowerShell, Golang, Ruby, Bash, Perl, etc.)Experience working with Certificate Lifecycle Management, Hardware Secure Module, and Key Management ServicesExperience with X.509, RSA and general certificate management processesPreferred Skills:BA or BS degree in Computer Science, Cyber Security, or other related information technology field of studySecurity certifications such as CISSP, CCSP, CRISC, AWS Security, SANS, etc.Experience supporting either Venafi, KeyFactor, or AppViewXExperience working with code signing solutionsExperience with Active Directory Certificate ServicesExperience working in multi-Cloud environmentsExperience with databases, and SQL queries (DBMS preferred)