Enable job alerts via email!

Data Security Engineer (HSM PKI )

K20s - Kinetic Technologies Private Limited

Los Angeles (CA)

On-site

USD 150,000 - 200,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a talented Data Security Engineer to enhance the security of critical data systems within the banking sector. This role demands a deep technical understanding of Utimaco HSMs, Key Management Systems, and Payment Security protocols. The ideal candidate will have a strong cryptographic background and a proven track record in deploying and managing security solutions. You'll be responsible for ensuring compliance with stringent regulations while optimizing the performance of cryptographic systems. If you are ready to take on a challenging role that directly impacts data security in a high-stakes environment, this opportunity is for you.

Qualifications

  • 5-7 years of experience in data security, focusing on banking and financial services.
  • Strong background in cryptography and compliance with industry standards.

Responsibilities

  • Design and maintain Utimaco HSMs for secure cryptographic key management.
  • Implement encryption strategies for sensitive banking data and ensure compliance.

Skills

Cryptography
Data Security
Key Management Systems (KMS)
HSM Integration
Payment Security
Public Key Infrastructure (PKI)
Compliance Management
Incident Response

Education

Bachelor's degree in Computer Science
Master's degree in Information Security

Tools

Utimaco HSM
Gemalto SafeNet
Thales CipherTrust
AWS KMS

Job description

Banking Experience Mandatory

Availability: Immediate Joiner Preferred

Position Overview

We are looking for a highly skilled Data Security Engineer with deep technical expertise in Utimaco Hardware Security Modules (HSM) or similar vendor, Key Management Systems (KMS), Payment Security, and Public Key Infrastructure (PKI). The ideal candidate will bring at least 5-7 years of hands-on experience in securing critical data systems, with a specific focus on the banking and financial services sectors. This role requires someone with a strong cryptographic background and a solid cyber security foundation and a proven track record in deploying, managing, and optimizing security solutions for sensitive data.

Key Responsibilities
  • HSM Integration & Management: Design, deploy, configure, and maintain Utimaco HSMs for cryptographic key storage and processing. Ensure secure generation, storage, and usage of cryptographic keys in line with banking compliance frameworks.
  • Key Management Systems (KMS): Architect and operationalize Key Management Systems to support key lifecycle management, including key generation, distribution, rotation, and destruction. Implement enterprise-grade encryption practices with emphasis on security, performance, and compliance.
  • Payment Security Implementation: Secure the end-to-end lifecycle of payment transactions through encryption, tokenization, and key management protocols. Develop and enforce standards compliant with PCI DSS, EMV, and ISO 20022. Engage in securing real-time payments, SWIFT transactions, and digital banking services.
  • PKI Deployment & Administration: Oversee Public Key Infrastructure (PKI), including the design and management of certificate authorities (CA), subordinate CAs, and registration authorities (RA). Administer certificate lifecycles, certificate revocation lists (CRLs), and secure digital certificate distribution.
  • Banking Data Encryption: Implement encryption strategies for sensitive banking data both at rest and in transit, ensuring compliance with local and international financial regulatory frameworks, including GDPR, FFIEC, and Basel III. Utilize encryption algorithms such as AES, RSA, and ECC for optimal data protection.
  • Security Hardening: Perform ongoing system hardening, security audits, and risk assessments across HSMs, KMS, PKI, and payment security infrastructure. Identify and mitigate vulnerabilities, ensuring that all cryptographic systems are resilient to attacks.
  • Compliance & Risk Management: Ensure that all cryptographic operations adhere to industry and banking standards, such as ISO 27001, PCI DSS, NIST SP 800-57, FIPS 140-2, and eIDAS. Collaborate with internal audit teams to align practices with risk management and data protection policies.
  • Incident Response & Monitoring: Provide expert-level support during security incidents related to cryptographic systems. Deploy proactive monitoring and logging to detect anomalies or breaches in data encryption systems.
  • Performance Optimization: Fine-tune the performance of cryptographic hardware and software systems to meet the high transaction volumes typical of banking environments. Ensure minimal latency and robust throughput in key management and cryptographic processing.
Technical Requirements
  • HSM Expertise: Proficiency with Utimaco HSM platforms, including CryptoServer Se, CSe-Series, and CSeC-Series, with a focus on configuring key hierarchies, secure key injection, and partitioning for multiple security domains.
  • KMS Proficiency: In-depth knowledge of enterprise KMS systems, such as Gemalto SafeNet, Thales CipherTrust, or AWS KMS, including handling complex key hierarchies and ensuring keys are securely distributed and used across the enterprise.
  • Payment Security Protocols: Expertise in securing payment systems following PCI HSM, EMV, 3-D Secure, SWIFT standards, with direct experience in designing secure payment channels, and using Hardware Security Modules to safeguard cryptographic keys used in payment authorization and tokenization systems.
  • Cryptographic Algorithms: Strong foundational knowledge of cryptographic algorithms, including AES, RSA, ECC, SHA-2, SHA-3, HMAC, and practical experience with both symmetric and asymmetric encryption methodologies.
  • PKI and Certificate Management: Extensive experience with PKI infrastructures, managing X.509 certificates, and familiarity with OCSP, SCEP, and LDAP for certificate validation and revocation.
Qualifications And Experience
  • Education: Bachelor's or Master's degree in Computer Science, Information Security, or related field.
  • Experience: Minimum of 5-7 years of focused experience in HSM, KMS, PKI, and Payment Security solutions, particularly in high-compliance, high-security environments such as banking, financial services, or payment processing.
  • Industry Certifications: Certifications such as CISSP, CISM, CCSP, PCI DSS QSA, or specialized certifications in HSM and KMS technologies (e.g., Utimaco Certified HSM Specialist) are highly preferred.
  • Banking Industry Experience: Strong background in securing banking and financial transaction environments, with a thorough understanding of regulatory requirements such as PCI DSS, PSD2, SWIFT CSP, and Basel III.
Personal Attributes
  • Availability: Must be available for immediate onboarding or with minimal notice period.
  • Analytical Mindset: Capable of evaluating complex cryptographic architectures and identifying gaps and improvement areas in securing data workflows.
  • Team Collaboration: Proven ability to work in cross-functional teams, including IT infrastructure, compliance, and application development teams, to ensure comprehensive data security strategies.
Seniority level

Mid-Senior level

Employment type

Full-time

Job function

Information Technology

Industries

IT Services and IT Consulting

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Security Solutions Engineer (Pre-Sales) - Remote

EVOTEK

Los Angeles

Remote

USD 150,000 - 200,000

Yesterday
Be an early applicant

Security Engineer

The Walt Disney Company

Burbank

Remote

USD 99,000 - 154,000

Yesterday
Be an early applicant

Security Engineer

Disney Interactive Media Group

Burbank

Remote

USD 99,000 - 154,000

3 days ago
Be an early applicant

Security Engineer

Disney Parks and Resorts

Burbank

Remote

USD 99,000 - 154,000

3 days ago
Be an early applicant

Security Solutions Engineer (Pre-Sales) - Remote

EVOTEK

Irvine

Remote

USD 150,000 - 200,000

Today
Be an early applicant

Senior Application Security Engineer (Remote US)

Experian Health

Costa Mesa

Remote

USD 87,000 - 152,000

9 days ago

Senior FIPS 140 Security Engineer- REMOTE

Lensa

Boston

Remote

USD 150,000 - 200,000

Yesterday
Be an early applicant

Information Security Engineer II / IS - Information Security / Full Time

Children's Hospital Los Angeles

Los Angeles

Remote

USD 99,000 - 179,000

30+ days ago

Security Engineer- Data Protection/Desensitization

PNC

Remote

USD 65,000 - 188,000

Today
Be an early applicant