Key Management & Cryptographic Security Engineer

Cubic Transportation Systems

Hyderabad

On-site

INR 1,200,000 - 2,400,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Cubic Transportation Systems is seeking a Key Management & Cryptographic Security Engineer to oversee cryptographic key lifecycles, certificates, and HSMs across multiple locations. The role includes participating in key ceremonies, audits, and secure provisioning, with strong coordination across regional teams.

Ideal candidates combine practical cryptography experience with hands-on HSM administration, PKI, and secure device provisioning capabilities, and are comfortable working with

Qualifications

  • Demonstrated experience with cryptographic key management and lifecycle
  • Experience securing cryptographic materials and sensitive data
  • Experience with HSMs and secure provisioning environments
  • Knowledge of TLS and mutual TLS configurations
  • Familiarity with NIST-based security guidance

Responsibilities

  • Manage lifecycle of cryptographic keys, certificates, and keys across global locations
  • Support key ceremonies, HSMs, SAMs, and device provisioning processes
  • Maintain accurate key inventories and configurations across systems
  • Investigate encryption, certificate, and HSM issues with dev/test teams
  • Define cryptographic requirements for fare-collection solutions
  • Ensure security policy compliance and incident support

Skills

Cryptographic key management
HSM management
PKI & certificates
Secure device provisioning
Key injection
TLS / mutual TLS
NIST guidance
Security incident handling

Education

Bachelor's degree in cybersecurity / computer science

Tools

HSM platforms

Job description

We are seeking a Key Management & Cryptographic Security Engineer to manage and support our global Key Management and Encryption Security Services environment.

The role is responsible for the secure lifecycle management of cryptographic keys, certificates, keysets, HSMs, SAMs, and secure provisioning environments across multiple locations. The engineer will support key ceremonies, regional Key Injection Facilities, audits, system changes, and production incidents.

The ideal candidate will combine practical cryptography and HSM experience with strong configuration management, documentation, troubleshooting, and stakeholder coordination skills. Experience in fare collection, payments, smartcards, or secure embedded systems is preferred.

Key Responsibilities
  • Manage the lifecycle of cryptographic keys, certificates, and keysets, including generation, distribution, activation, rotation, renewal, revocation, backup, recovery, and secure destruction.
  • Manage and support Hardware Security Modules (HSMs) and associated cryptographic services.
  • Maintain accurate key inventories and configurations across global locations, systems, devices, and environments.
  • Participate in controlled key ceremonies, security audits, and secure provisioning activities.
  • Support regional Key Injection Facilities and associated HSM, SAM, and device-provisioning processes.
  • Assess the end-to-end impact of key, certificate, device, and cryptographic configuration changes.
  • Create and maintain technical designs, operating procedures, configuration records, runbooks, and audit evidence.
  • Work with development and testing teams to investigate and resolve encryption, certificate, secure-messaging, key-injection, and HSM-related issues.
  • Define cryptographic and security requirements for fare-collection solutions.
  • Support production incidents, root-cause analysis, change management, and service improvements.
  • Ensure cryptographic material and sensitive information are handled in accordance with approved security policies and procedures.
Required Skills and Experience
  • Practical experience with one or more of the following:
  • Cryptographic key management
  • Hardware Security Module development, administration, or management
  • PKI and certificate management
  • Secure device provisioning or key injection
  • Good understanding of symmetric cryptographic keys and algorithms, including:
  • AES
  • DES and Triple DES
  • DUKPT
  • Key derivation and key diversification
  • Hashing and encryption modes
  • Key wrapping and key exchange
  • Good understanding of asymmetric cryptography, including:
  • PKI
  • Public and private key pairs
  • Digital certificates and certificate chains
  • Digital signatures
  • Certificate Authorities and trust stores
  • Certificate renewal and revocation
  • Understanding of secure communication protocols, including TLS and mutual TLS.
  • Knowledge of cryptographic key-management lifecycles and applicable NIST guidance.
  • Experience managing security-sensitive configurations across multiple systems or environments.
  • Strong troubleshooting and end-to-end systems-analysis skills.
  • Excellent attention to detail, documentation, and communication skills.
  • Ability to define and follow controlled security procedures precisely.
  • Experience working with geographically distributed teams and business stakeholders.
  • Ability to participate in global support activities, planned key ceremonies, and critical incident escalation when required.
Preferred Skills
  • Experience in HSM product development, integration, administration, or operational management.
  • Experience with HSM platforms used in payment, banking, transit, or enterprise cryptographic environments.
  • Knowledge of HSM functions such as:
  • Key generation and import
  • Key blocks and key wrapping
  • Key translation
  • PIN and payment cryptography
  • Signing and verification
  • Secure backup and recovery
  • HSM clustering, resilience, and monitoring
  • Experience with HSMs, SAMs, Key Injection Facilities, or secure provisioning environments.
  • Knowledge of payment key-management concepts such as DUKPT, Base Derivation Keys, Initial Key Serial Numbers, Key Encryption Keys, and Terminal Master Keys.
  • Knowledge of secure embedded systems and mobile-platform security.
  • Experience with contactless smartcards, particularly NXP MIFARE DESFire, or similar technologies.
  • Experience in fare collection, transportation, payments, banking, financial services, or another security-sensitive industry.
  • Knowledge of PCI PTS POI, PCI P2PE, PCI Mobile Payments on COTS, ISO/IEC 27000, or similar standards.
  • Experience with UMB components and S-KMS.
  • Familiarity with development, integration, laboratory, pre-production, and production environments.
  • Scripting or automation experience for validation, monitoring, reporting, or controlled operational activities.
Key Personal Attributes
  • Highly detail-oriented, methodical, and security-conscious.
  • Understands that a single incorrect key value, digit, version, or configuration can cause significant security or service impact.
  • Strong configuration and change-management discipline.
  • Able to understand the wider system impact of an individual key, certificate, HSM, or device change.
  • Excellent written and verbal communication skills.
  • Comfortable coordinating with engineering teams, suppliers, service personnel, auditors, and management.
  • Able to create clear procedures that can be safely followed by other engineers.
  • Calm and systematic when resolving complex or high-impact incidents.
  • Willing to stop and escape an activity when security, authorization, or procedural requirements are not met.
Qualifications
  • Degree in cybersecurity, computer science, electronics, engineering, or a related discipline, or equivalent professional experience.
  • Relevant experience in cryptographic security, HSM development or administration, key management, PKI, payment security, embedded security, or secure provisioning.
  • Security or technology certifications such as CISSP, CCSP, Security+, ISO 27001, PCI, or vendor-specific HSM/KMS certifications are beneficial but not mandatory.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Key Management and Cryptographic Security Engineer
Key Management and Cryptographic Security Engineer

Pixelcode Technologies India • Hyderabad

On-site
INR 1,800,000 - 2,600,000
Senior Security Engineer – PKI & Platform Security
Senior Security Engineer – PKI & Platform Security

1JS Global • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Senior Analyst - IAM PKI
Senior Analyst - IAM PKI

PepsiCo • Hyderabad

On-site
INR 2,400,000 - 4,200,000
Lead Software Engineer - Java, Spring, Springboot, Kafka, Cryptography, Session Key Derivation, HSM
Lead Software Engineer - Java, Spring, Springboot, Kafka, Cryptography, Session Key Derivation, HSM

Mastercard • Maharashtra

On-site
INR 1,800,000 - 3,000,000
HSM Architect
HSM Architect

Greytip Software Private Limited • Bengaluru

On-site
INR 1,200,000 - 2,400,000
Crypto, PKI, CMS, KMS, HSM Analyst
Crypto, PKI, CMS, KMS, HSM Analyst

Orbus International • Pune District

On-site
INR 2,500,000 - 4,000,000
Pki Security Analyst
Pki Security Analyst

Cloudxtreme • Kolkata District, Hyderabad, Bengaluru

On-site
INR 1,500,000 - 2,100,000
Systems Engineer III
Systems Engineer III

Aditi Consulting • Chennai District

On-site
INR 1,200,000 - 1,800,000
Associate Cybersecurity Analyst
Associate Cybersecurity Analyst

PowerToFly • Bengaluru

On-site
INR 1,200,000 - 1,800,000
PKI, HSM & Certificate Services Sr. Engineer
PKI, HSM & Certificate Services Sr. Engineer

3mcompany • Bengaluru

Hybrid
INR 3,000,000 - 4,200,000