HSM And PKI Security Engineer

Summary

Onsite HSM & PKI Security Engineer administering Thales Luna HSM infrastructure, cryptographic key protection, Microsoft AD CS, and enterprise certificate lifecycle management. Core stack: PKI, X.509, TLS/SSL, RSA, ECC, AES, DigiCert.

Location

Dammam, Saudi Arabia

Employment type

Full-time | Onsite

Project duration

Long-term project assignment

About the role

We are seeking an experienced HSM & PKI security engineer to operate, secure, and support enterprise hardware security module and public key infrastructure environments.

The engineer will be responsible for HSM administration, cryptographic key protection, high availability, backup and recovery, PKI integrations, certificate lifecycle activities, and coordination with the HSM OEM.

Key responsibilities

  • Administer and operate Thales Luna HSM infrastructure.
  • Manage HSM partitions, security domains, roles, access controls, and high-availability configurations.
  • Support HSM backup, recovery, cloning, and disaster recovery procedures.
  • Manage PED/MFA and secure administrative access to HSM infrastructure.
  • Support integration of HSM with enterprise applications, databases, servers, and security platforms.
  • Protect and manage cryptographic keys in accordance with security policies.
  • Support Microsoft Certificate Authority and AD CS environments.
  • Support public certificate lifecycle management, including issuance, renewal, installation, and revocation.
  • Coordinate with DigiCert or other public Certificate Authority providers.
  • Troubleshoot certificate, PKI, TLS/SSL, and HSM-related incidents.
  • Perform health checks, maintenance, testing, and technical validation.
  • Coordinate technical activities with OEM/vendor engineers.
  • Maintain HSM/PKI documentation, configuration records, procedures, and recovery runbooks.
  • Support audit, compliance, and security assessment requirements.

Requirements

Required qualifications & experience

  • Bachelor's degree in cybersecurity, computer science, information technology, computer engineering, or related discipline.
  • 5+ years of experience in HSM, PKI, cryptography, certificate management, or enterprise security.
  • Strong knowledge of PKI, X.509 certificates, TLS/SSL, RSA, ECC, AES, and cryptographic key management.
  • Hands-on experience with enterprise HSM technologies.
  • Experience with Microsoft AD CS / Certificate Services is highly desirable.
  • Experience supporting enterprise or government cybersecurity environments is preferred.
  • Must be available full-time onsite in Dammam.

Required certification

CompTIA Security+ or equivalent recognized security certification.

Preferred certifications & training

  • Thales Luna HSM official training/certification.
  • Microsoft PKI / AD CS certification or advanced PKI training.
  • Vendor-specific HSM administration certification.
  • Relevant cryptography or PKI professional certification.

Core competencies

HSM | PKI | Cryptography | AD CS | Certificate Management | TLS/SSL | Key Protection | High Availability | Backup & Recovery | Troubleshooting

Candidates should clearly indicate their HSM, PKI, certificate-management platforms, and vendor training/certifications on their CV.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available