IT Security Encryption Engineer
الوصف الوظيفي
Position Overview
We are seeking a highly skilled IT Security Encryption Engineer to oversee the operational integrity, administration, and continuous enhancement of our enterprise encryption infrastructure. This critical role will encompass the management, maintenance, and optimization of encryption services, including Public Key Infrastructure (PKI), Hardware Security Modules (HSM), digital certificates, cryptographic key management, and advanced encryption technologies that safeguard our organization’s most vital IT services. The ideal candidate will play a pivotal role in ensuring the confidentiality, integrity, and availability of sensitive data across our systems while maintaining compliance with industry standards and regulatory requirements.
Core Responsibilities
- Enterprise Encryption Services Management: Oversee the deployment, administration, and lifecycle management of enterprise-wide encryption solutions, including PKI, HSM, and digital certificates, to protect critical IT infrastructure and data assets.
- PKI and HSM Operations: Maintain and optimize on-premises PKI environments, such as Microsoft Active Directory Certificate Services (ADCS), and manage Hardware Security Modules (HSMs) from leading vendors like Thales Luna, Entrust nShield, or Utimaco to ensure robust cryptographic key protection and secure certificate issuance.
- Certificate Lifecycle Management: Implement and enforce best practices for certificate lifecycle management, including issuance, renewal, revocation, and monitoring, to mitigate risks associated with expired or compromised certificates.
- TLS/SSL and X.509 Certificate Administration: Configure, deploy, and monitor TLS/SSL certificates and X.509 standards to secure web communications, APIs, and internal services, ensuring adherence to security policies and compliance frameworks.
- Cryptographic Key Management: Develop and enforce key management policies, including generation, storage, rotation, and destruction, to maintain the highest levels of cryptographic security and prevent unauthorized access.
- Database Encryption (TDE): Implement and manage Transparent Data Encryption (TDE) solutions to protect sensitive data at rest within databases, ensuring compliance with data protection regulations and internal security policies.
- Disaster Recovery and Business Continuity: Design, implement, and test PKI/HSM disaster recovery plans to ensure rapid restoration of encryption services in the event of a failure or security incident, minimizing downtime and operational impact.
- Automation and Scripting: Leverage PowerShell and other scripting tools to automate repetitive encryption-related tasks, streamline workflows, and enhance operational efficiency while reducing human error.
- Security Hardening and Compliance: Conduct regular security assessments, vulnerability scans, and compliance audits to identify and remediate risks, ensuring alignment with industry standards such as NIST, ISO 27001, and internal security frameworks.
- Identity Integration: Collaborate with Identity and Access Management (IAM) and Privileged Access Management (PAM) teams to integrate encryption solutions with authentication and authorization systems, enhancing overall security posture.
Required Skills and Qualifications
- Technical Proficiency: Hands-on experience with enterprise PKI solutions, particularly Microsoft ADCS, HSMs (Thales Luna, Entrust nShield, Utimaco), certificate lifecycle management, TLS/SSL, X.509 standards, and cryptographic key management.
- Database Encryption: Familiarity with Transparent Data Encryption (TDE) and other database encryption methodologies to secure sensitive data at rest.
- Automation and Scripting: Strong proficiency in PowerShell and scripting languages to automate encryption-related processes and improve operational efficiency.
- Security and Compliance: Deep understanding of security hardening techniques, compliance requirements (e.g., NIST, ISO 27001), and risk management frameworks to ensure robust protection of organizational assets.
- Identity Integration: Experience integrating encryption solutions with IAM/PAM systems to enhance authentication and authorization security.
- Disaster Recovery: Ability to design and implement PKI/HSM disaster recovery strategies to ensure business continuity and rapid service restoration.
- Problem-Solving and Collaboration: Strong analytical and troubleshooting skills to resolve complex encryption-related issues, coupled with the ability to work effectively with cross-functional teams to drive security initiatives.
Preferred Certifications and Tools
While not mandatory, candidates with the following certifications or tool experience will be highly regarded:
- Certifications: CISSP, CISM, CompTIA Security+, or vendor-specific certifications (e.g., Thales, Entrust, Utimaco).
- Tools: Venafi, Keyfactor, or other enterprise certificate management platforms.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.