Production Support Engineer – Cryptography / HSM

New Era Technology · New York, New York · Engineering

Posted 2026-09-15

Apply for this role →

Job Summary

New Era Technology is seeking an experienced Production Support Engineer to support enterprise cryptographic platforms and services. This role will provide operational support, engineering, and platform stewardship for critical security infrastructure used to protect sensitive data, keys, credentials, and authentication workflows across the enterprise.

The selected candidate will support enterprise cryptography operations, platform administration, key lifecycle management, application onboarding, high availability/disaster recovery (HA/DR), automation, incident response, and audit readiness.

The ideal candidate will have hands-on experience with Oracle Key Vault, Thales Hardware Security Modules (HSMs), Thales Cipher Trust, or similar key management, encryption, and cryptographic control platforms.

Required Experience

5–10+ years of experience in production support, infrastructure security, cybersecurity engineering, IAM, PKI, or enterprise cryptographic services.

Key Responsibilities

Provide production support for enterprise cryptography platforms, ensuring high availability, operational stability, and timely incident response.

Administer and support Oracle Key Vault, Thales HSMs, Thales Cipher Trust, and comparable key management/encryption platforms.

Perform installation, configuration, upgrades, patching, backup/recovery, and lifecycle maintenance of cryptographic platforms and appliances.

Manage cryptographic key lifecycle processes, including secure generation, storage, rotation, escrow/backup, archival, revocation, and decommissioning.

Support high availability and disaster recovery capabilities for critical authentication and cryptographic infrastructure.

Partner with application, infrastructure, IAM, and security engineering teams to integrate applications with cryptographic services using KMIP, PKCS#11, JCE, CNG/KSP, APIs, and related protocols.

Troubleshoot production incidents involving encryption, certificate/key management, platform connectivity, authentication dependencies, and HSM availability.

Lead or contribute to root cause analysis, problem management, and continuous improvement for recurring issues.

Develop and maintain operational procedures, support documentation, runbooks, and controls evidence.

Support audit, risk, and compliance activities and adherence to FIPS 140-2/3, PCI DSS, NIST, ISO 27001, and related enterprise controls.

Automate routine operational tasks using Python, Shell, Bash, or PowerShell.

Participate in on-call support rotation and planned maintenance activities for critical security services.

Required Technical Skills

Candidates should have strong hands-on experience in most of the following areas:

Oracle Key Vault

Thales Luna, pay Shield, or general Thales HSM platforms

Thales Cipher Trust Manager / Cipher Trust encryption or key management services

Enterprise key management, HSM, or data protection technologies

Key management and encryption principles

PKI and certificate management

Cryptographic algorithms and protocols such as AES, RSA, ECC, TLS/SSL, SSH, and X.509

Linux and/or Windows server administration in an enterprise environment

Troubleshooting across network, operating system, middleware, authentication, and application layers

HA/DR architecture and operational resiliency

Change, incident, and problem management processes

Scripting and automation using Python, Shell, Bash, or PowerShell

Education

Bachelor’s degree in computer science, Information Security, Engineering, or a related field, or equivalent practical experience.

Preferred Skills

Experience working in a highly regulated environment, preferably financial services.

Experience supporting privileged access management, web authentication, IAM, or adjacent cybersecurity infrastructure.

Familiarity with cloud key management/HSM services such as AWS CloudHSM, Azure Dedicated HSM, or cloud-native KMS offerings.

Experience integrating cryptographic platforms with enterprise applications, databases, file encryption, tokenization, or secrets-management services.

Prior leadership, mentoring, or technical lead experience.

Work Environment

This is a full-time, 12-month staff augmentation contractor engagement.

On-site support is required 3–4 days per week.

Preferred locations are New York City, NY and Pittsburgh, PA.

Lake Mary, FL and Jersey City, NJ are also acceptable.

The role may require support across different time zones.

Participation in weekend work may be required for Change Management activities.

Participation in an on-call support rotation is required.

Qualifications and Competencies

The successful candidate should demonstrate:

Excellent attention to detail.

Strong organizational skills.

Excellent analytical skills.

Excellent documentation skills.

Demonstrated proficiency in Microsoft Office, including Word, Excel, and PowerPoint.

Ability to work collaboratively both in person and virtually using Microsoft Teams or similar tools.

Ability to work as a liaison between business and information security/information technology teams.

Flexibility to accommodate working across different time zones.

Excellent interpersonal communication skills with strong spoken and written English.

Business-outcomes mindset.

Strong balance of strategic thinking and attention to detail.

Self-starter with the ability to take initiative.

Strong understanding of key management and encryption principles.

Strong understanding of PKI and certificate management.

Strong understanding of cryptographic algorithms and protocols such as AES, RSA, ECC, TLS/SSL, SSH, and X.509.

Experience troubleshooting across network, operating system, middleware, authentication, and application layers.

Familiarity with HA/DR architecture, operational resiliency, and change/incident/problem management processes.

Strong verbal and written communication skills, with the ability to work across engineering, operations, security, risk, and audit teams.

Candidate Profile

The ideal candidate will have hands-on experience supporting enterprise cryptography platforms and services, including technologies such as Oracle Key Vault, Thales Hardware Security Modules (HSMs), Thales Cipher Trust, or similar key management, encryption, and cryptographic control platforms.

Engagement Objectives

Maintain strong operational stability and support coverage for critical enterprise cryptographic and authentication services.

Improve platform resiliency, automation, and onboarding efficiency.

Reduce operational risk through strong controls, documentation, and lifecycle governance.

Serve as a trusted technical partner for application teams, engineering teams, and control functions.

*** This is an onsite role, candidates should locate in commutable distance from any of these locations New York City, NY or Pittsburgh, PA preferred; Lake Mary, FL and Jersey City, NJ. ***

#L1-NP1

Apply for this role →

← Back to all jobs