Production Support Engineer – Cryptography / HSM
Job Summary
New Era Technology is seeking an experienced Production Support Engineer to support enterprise cryptographic platforms and services. This role will provide operational support, engineering, and platform stewardship for critical security infrastructure used to protect sensitive data, keys, credentials, and authentication workflows across the enterprise.
The selected candidate will support enterprise cryptography operations, platform administration, key lifecycle management, application onboarding, high availability/disaster recovery (HA/DR), automation, incident response, and audit readiness.
The ideal candidate will have hands-on experience with Oracle Key Vault, Thales Hardware Security Modules (HSMs), Thales Cipher Trust, or similar key management, encryption, and cryptographic control platforms.
Required Experience
5–10+ years of experience in production support, infrastructure security, cybersecurity engineering, IAM, PKI, or enterprise cryptographic services.
Key Responsibilities
Provide production support for enterprise cryptography platforms, ensuring high availability, operational stability, and timely incident response.
Administer and support Oracle Key Vault, Thales HSMs, Thales Cipher Trust, and comparable key management/encryption platforms.
Perform installation, configuration, upgrades, patching, backup/recovery, and lifecycle maintenance of cryptographic platforms and appliances.
Manage cryptographic key lifecycle processes, including secure generation, storage, rotation, escrow/backup, archival, revocation, and decommissioning.
Support high availability and disaster recovery capabilities for critical authentication and cryptographic infrastructure.
Partner with application, infrastructure, IAM, and security engineering teams to integrate applications with cryptographic services using KMIP, PKCS#11, JCE, CNG/KSP, APIs, and related protocols.
Troubleshoot production incidents involving encryption, certificate/key management, platform connectivity, authentication dependencies, and HSM availability.
Lead or contribute to root cause analysis, problem management, and continuous improvement for recurring issues.
Develop and maintain operational procedures, support documentation, runbooks, and controls evidence.
Support audit, risk, and compliance activities and adherence to FIPS 140-2/3, PCI DSS, NIST, ISO 27001, and related enterprise controls.
Automate routine operational tasks using Python, Shell, Bash, or PowerShell.
Participate in on-call support rotation and planned maintenance activities for critical security services.
Required Technical Skills
Candidates should have strong hands-on experience in most of the following areas:
Oracle Key Vault
Thales Luna, pay Shield, or general Thales HSM platforms
Thales Cipher Trust Manager / Cipher Trust encryption or key management services
Enterprise key management, HSM, or data protection technologies
Key management and encryption principles
PKI and certificate management
Cryptographic algorithms and protocols such as AES, RSA, ECC, TLS/SSL, SSH, and X.509
Linux and/or Windows server administration in an enterprise environment
Troubleshooting across network, operating system, middleware, authentication, and application layers
HA/DR architecture and operational resiliency
Change, incident, and problem management processes
Scripting and automation using Python, Shell, Bash, or PowerShell
Education
Bachelor’s degree in computer science, Information Security, Engineering, or a related field, or equivalent practical experience.
Preferred Skills
Experience working in a highly regulated environment, preferably financial services.
Experience supporting privileged access management, web authentication, IAM, or adjacent cybersecurity infrastructure.
Familiarity with cloud key management/HSM services such as AWS CloudHSM, Azure Dedicated HSM, or cloud-native KMS offerings.
Experience integrating cryptographic platforms with enterprise applications, databases, file encryption, tokenization, or secrets-management services.
Prior leadership, mentoring, or technical lead experience.
Work Environment
This is a full-time, 12-month staff augmentation contractor engagement.
On-site support is required 3–4 days per week.
Preferred locations are New York City, NY and Pittsburgh, PA.
Lake Mary, FL and Jersey City, NJ are also acceptable.
The role may require support across different time zones.
Participation in weekend work may be required for Change Management activities.
Participation in an on-call support rotation is required.
Qualifications and Competencies
The successful candidate should demonstrate:
Excellent attention to detail.
Strong organizational skills.
Excellent analytical skills.
Excellent documentation skills.
Demonstrated proficiency in Microsoft Office, including Word, Excel, and PowerPoint.
Ability to work collaboratively both in person and virtually using Microsoft Teams or similar tools.
Ability to work as a liaison between business and information security/information technology teams.
Flexibility to accommodate working across different time zones.
Excellent interpersonal communication skills with strong spoken and written English.
Business-outcomes mindset.
Strong balance of strategic thinking and attention to detail.
Self-starter with the ability to take initiative.
Strong understanding of key management and encryption principles.
Strong understanding of PKI and certificate management.
Strong understanding of cryptographic algorithms and protocols such as AES, RSA, ECC, TLS/SSL, SSH, and X.509.
Experience troubleshooting across network, operating system, middleware, authentication, and application layers.
Familiarity with HA/DR architecture, operational resiliency, and change/incident/problem management processes.
Strong verbal and written communication skills, with the ability to work across engineering, operations, security, risk, and audit teams.
Candidate Profile
The ideal candidate will have hands-on experience supporting enterprise cryptography platforms and services, including technologies such as Oracle Key Vault, Thales Hardware Security Modules (HSMs), Thales Cipher Trust, or similar key management, encryption, and cryptographic control platforms.
Engagement Objectives
Maintain strong operational stability and support coverage for critical enterprise cryptographic and authentication services.
Improve platform resiliency, automation, and onboarding efficiency.
Reduce operational risk through strong controls, documentation, and lifecycle governance.
Serve as a trusted technical partner for application teams, engineering teams, and control functions.
*** This is an onsite role, candidates should locate in commutable distance from any of these locations New York City, NY or Pittsburgh, PA preferred; Lake Mary, FL and Jersey City, NJ. ***
#L1-NP1