HSM & PKI Security Engineer
Summary
Operate and secure enterprise HSM and PKI environments, administering Thales Luna HSMs, managing cryptographic keys, certificates, and Microsoft AD CS. Handles backup/recovery, TLS/SSL troubleshooting, and HSM integrations with enterprise apps.
Location: Dammam, Saudi Arabia Employment Type: Full-Time | Onsite Project Duration: Long-term project assignment About the Role We are seeking an experienced HSM & PKI Security Engineer to operate, secure, and support enterprise Hardware Security Module and Public Key Infrastructure environments.
The engineer will be responsible for HSM administration, cryptographic key protection, high availability, backup and recovery, PKI integrations, certificate lifecycle activities, and coordination with the HSM OEM.
Key Responsibilities Administer and operate Thales Luna HSM infrastructure.
Manage HSM partitions, security domains, roles, access controls, and high-availability configurations.
Support HSM backup, recovery, cloning, and disaster recovery procedures.
Manage PED/MFA and secure administrative access to HSM infrastructure.
Support integration of HSM with enterprise applications, databases, servers, and security platforms.
Protect and manage cryptographic keys in accordance with security policies.
Support Microsoft Certificate Authority and AD CS environments.
Support public certificate lifecycle management, including issuance, renewal, installation, and revocation.
Coordinate with DigiCert or other public Certificate Authority providers.
Troubleshoot certificate, PKI, TLS/SSL, and HSM-related incidents.
Perform health checks, maintenance, testing, and technical validation.
Coordinate technical activities with OEM/vendor engineers.
Maintain HSM/PKI documentation, configuration records, procedures, and recovery runbooks.
Support audit, compliance, and security assessment requirements.
Required Qualifications & Experience Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering , or related discipline.
5+ years of experience in HSM, PKI, cryptography, certificate management, or enterprise security.
Strong knowledge of PKI, X.
509 certificates, TLS/SSL, RSA, ECC, AES , and cryptographic key management.
Hands-on experience with enterprise HSM technologies.
Experience with Microsoft AD CS / Certificate Services is highly desirable.
Experience supporting enterprise or government cybersecurity environments is preferred.
Must be available full-time onsite in Dammam .
Required Certification CompTIA Security+ or equivalent recognized security certification .
Preferred Certifications & Training Thales Luna HSM official training/certification.
Microsoft PKI / AD CS certification or advanced PKI training.
Vendor-specific HSM administration certification.
Relevant cryptography or PKI professional certification.
Core Competencies HSM | PKI | Cryptography | AD CS | Certificate Management | TLS/SSL | Key Protection | High Availability | Backup & Recovery | Troubleshooting Candidates should clearly indicate their HSM, PKI, certificate-management platforms, and vendor training/certifications on their CV.
The engineer will be responsible for HSM administration, cryptographic key protection, high availability, backup and recovery, PKI integrations, certificate lifecycle activities, and coordination with the HSM OEM.
Key Responsibilities Administer and operate Thales Luna HSM infrastructure.
Manage HSM partitions, security domains, roles, access controls, and high-availability configurations.
Support HSM backup, recovery, cloning, and disaster recovery procedures.
Manage PED/MFA and secure administrative access to HSM infrastructure.
Support integration of HSM with enterprise applications, databases, servers, and security platforms.
Protect and manage cryptographic keys in accordance with security policies.
Support Microsoft Certificate Authority and AD CS environments.
Support public certificate lifecycle management, including issuance, renewal, installation, and revocation.
Coordinate with DigiCert or other public Certificate Authority providers.
Troubleshoot certificate, PKI, TLS/SSL, and HSM-related incidents.
Perform health checks, maintenance, testing, and technical validation.
Coordinate technical activities with OEM/vendor engineers.
Maintain HSM/PKI documentation, configuration records, procedures, and recovery runbooks.
Support audit, compliance, and security assessment requirements.
Required Qualifications & Experience Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering , or related discipline.
5+ years of experience in HSM, PKI, cryptography, certificate management, or enterprise security.
Strong knowledge of PKI, X.
509 certificates, TLS/SSL, RSA, ECC, AES , and cryptographic key management.
Hands-on experience with enterprise HSM technologies.
Experience with Microsoft AD CS / Certificate Services is highly desirable.
Experience supporting enterprise or government cybersecurity environments is preferred.
Must be available full-time onsite in Dammam .
Required Certification CompTIA Security+ or equivalent recognized security certification .
Preferred Certifications & Training Thales Luna HSM official training/certification.
Microsoft PKI / AD CS certification or advanced PKI training.
Vendor-specific HSM administration certification.
Relevant cryptography or PKI professional certification.
Core Competencies HSM | PKI | Cryptography | AD CS | Certificate Management | TLS/SSL | Key Protection | High Availability | Backup & Recovery | Troubleshooting Candidates should clearly indicate their HSM, PKI, certificate-management platforms, and vendor training/certifications on their CV.