Sr System Security Engineer – PKI, Certificate & Key Management
Summary
Senior specialist designing and implementing enterprise PKI, certificate lifecycle management, HSM, and key management solutions. Day-to-day work spans CA hierarchies, CLM platforms (Venafi/Keyfactor/Entrust), HSM integration, AWS KMS/CloudHSM, and cryptography automation via Python, PowerShell, Bash, and REST APIs.
Location: Central Singapore
Employment Type: 12-Month Contract, Renewable
Seniority: Mid-Level / Senior
Job Summary
We are looking for an experienced System Security Engineer with strong hands-on expertise in the design and implementation of enterprise PKI, Certificate Lifecycle Management (CLM), Key Management and HSM security solutions.
This is a specialist cryptography/security engineering position and is not a general SOC, vulnerability management or cybersecurity operations role.
Key Responsibilities
- Design, implement and operationalise enterprise PKI, Certificate Lifecycle Management and Key Management solutions.
- Design and manage CA hierarchies, including Root and Subordinate CAs.
- Implement certificate lifecycle processes covering discovery, issuance, enrolment, renewal, revocation and expiry management.
- Design and integrate CLM platforms such as CyberArk Venafi, Keyfactor, Entrust or equivalent with enterprise Certificate Authorities.
- Design, deploy and integrate HSM and enterprise Key Management solutions such as Entrust nShield, Thales CipherTrust/Luna HSM or equivalent.
- Support HSM operations including key generation, rotation, key ceremonies and secure key protection.
- Integrate certificate and key-management platforms with enterprise applications and security systems using REST APIs and automation.
- Design and support cloud cryptographic solutions using AWS KMS, ACM, Secrets Manager and CloudHSM.
- Support cryptographic asset discovery and maintain certificate/key inventories or Cryptographic Bill of Materials (CBOM).
- Apply cryptographic standards and best practices including X.509, PKCS, FIPS and NIST.
- Support cryptographic modernization and Post-Quantum Cryptography (PQC)/crypto-agility initiatives.
- Work closely with security architects, application owners, infrastructure teams and technology vendors throughout solution design and implementation.
- Troubleshoot complex PKI, certificate, HSM and key-management issues.
Requirements
- Degree in Computer Science, Information Technology, Cybersecurity or related discipline.
- Minimum 5 years of IT/security experience, including at least 2 years of hands-on PKI, Certificate Management, HSM or Enterprise Key Management experience.
- Strong experience designing and implementing, rather than only supporting, enterprise certificate and key-management solutions.
- Strong knowledge of X.509, TLS/mTLS, CA hierarchy, certificate issuance/renewal/revocation and PKI architecture.
- Hands-on experience with CyberArk Venafi / Keyfactor / Entrust / AppViewX or similar CLM platforms.
- Hands-on experience with Entrust nShield / Thales CipherTrust / Thales Luna / AWS CloudHSM or similar HSM/KMS technologies.
- Knowledge of AWS KMS, ACM, Secrets Manager and CloudHSM is highly desirable.
- Experience with Python, PowerShell, Bash and/or REST APIs for automation is advantageous.
- Knowledge of FIPS, NIST, PKCS, crypto-agility and PQC is advantageous.
- Strong stakeholder and vendor management skills.
- Experience within banking, financial services or other highly regulated enterprise environments is preferred.
Interested candidates are kindly requested to email their CV with their experience to [email protected]
We look forward to your application!