Job Description :
We are seeking a skilled Encryption / Crypto Engineer to design and implement secure cryptographic frameworks across multi-cloud environments. This role requires deep expertise in cryptography, key management, and infrastructure-as-code, with a strong emphasis on compliance, audit, and service validation.
Key Responsibilities :
- Cryptographic Architecture & Implementation : Design and deploy secure KMS, CAs, and encryption modules across AWS, Azure, or GCP. Implement cryptographic principles for data protection, tokenization, and secure key lifecycle management.
- Infrastructure Automation & Module Development : - Develop reusable GitHub and Terraform modules for provisioning keys, certificates, and cryptographic services. Integrate modules with CI / CD pipelines and cloud-native security tooling.
- Policy & Compliance Enablement : - Collaborate on SCPs, compliance certifications (ISO, SOC2, PCI-DSS), and audit frameworks. Create documentation, playbooks, and validation checklists for internal and external audits.
- Custom App Development & Validation : - Build and deploy custom applications for encryption, secure data workflows, and key rotation. Conduct validation and audit of cryptographic services and infrastructure modules.
Required Qualifications :
8 - 12 years of experience in Cloud Cryptography / Encryption Engineering.Strong understanding of key exchange protocols, cryptographic assets, PKI, and HSMs.Hands-on experience with Terraform, GitHub, and cloud-native KMS (AWS KMS, Azure Key Vault, GCP Cloud KMS).Proven ability to create audit-ready documentation, playbooks, and service validation reports.Familiarity with zero-trust architectures, secure enclaves, and CSP services.Preferred Skills :
Experience with DevSecOps pipelines and secrets management tools (HashiCorp Vault, AWS Secrets Manager).Knowledge of compliance frameworks (NIST, FIPS, GDPR) and cryptographic certifications.Ability to translate technical requirements into platform-optimized content for internal stakeholders.(ref : hirist.tech)