Opes Cybersecurity logo
Opes CybersecurityPosted 1 month ago

Senior Security Engineer / Architect – Key Management Services (KMS)

On-siteCanberra, Australian Capital Territory, Australia

Full TimeSenior Level

Job Summary

Lead the architecture, design, and implementation of enterprise-grade Key Management Services (KMS) solutions, focusing exclusively on cryptographic key lifecycle management. Develop secure integration patterns between KMS platforms and enterprise applications, databases, and cloud services while designing Hardware Security Module (HSM) backed cryptographic services. Architect Public Key Infrastructure (PKI) solutions, including Certificate Authorities and trust models, and produce high-quality architecture documentation for security design reviews. Identify technical risks and provide mitigation strategies throughout project delivery. This 12-month contract in Canberra requires an ASAP start and TSPV clearance.

Required Qualifications

  • 8+ years' experience in cyber security engineering, security architecture, cryptographic engineering or a related discipline
  • Demonstrated experience designing and implementing enterprise Key Management Services (KMS) solutions
  • AWS KMS
  • Azure Key Vault
  • Google Cloud KMS
  • HashiCorp Vault (or equivalent secrets management/KMS platforms)
  • Strong understanding of cryptographic key lifecycle management, including key generation, storage, distribution, rotation, archival and destruction
  • Experience designing and integrating cryptographic services into enterprise applications, infrastructure and cloud environments
  • Strong understanding of symmetric and asymmetric cryptography, encryption, digital signatures, authentication and trust services
  • Experience developing security architecture documentation, solution designs and implementation artefacts
  • Experience working within regulated or high-assurance environments (e.g. Defence, Government, Critical Infrastructure or Financial Services)
  • Hands-on experience designing and implementing Hardware Security Module (HSM) backed cryptographic services
  • Thales
  • Entrust
  • Utimaco
  • Luna HSM
  • Equivalent enterprise HSM platforms
  • TSPV required
  • NV2 holders will be considered, with uplift to TSPV mandatory
  • Canberra based (on-site)
  • 12-month contract
  • ASAP Start

Desired Qualifications

  • Experience designing and implementing Public Key Infrastructure (PKI) solutions
  • Microsoft Active Directory Certificate Services (AD CS)
  • Certificate Authority (CA) design and management
  • Certificate lifecycle management
  • Digital certificate provisioning and trust models
  • Experience with one or more of the following technologies and practices: Secrets management platforms
  • Experience with one or more of the following technologies and practices: Certificate lifecycle management platforms
  • Experience with one or more of the following technologies and practices: Code signing infrastructure
  • Experience with one or more of the following technologies and practices: TLS and Mutual TLS (mTLS) implementations
  • Experience with one or more of the following technologies and practices: Cryptographic API integration
  • Experience with one or more of the following technologies and practices: Secure DevSecOps pipelines
  • Experience with one or more of the following technologies and practices: Zero Trust architecture
  • Experience with one or more of the following technologies and practices: Container security and Kubernetes secrets management
  • Experience with one or more of the following technologies and practices: Identity and Access Management (IAM) integration
  • Experience with one or more of the following technologies and practices: High Availability (HA) and Disaster Recovery (DR) design for cryptographic services

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce