HSM Security Engineer

Innova SolutionsAddison, TX
Onsite

About The Position

A client of Innova Solutions is immediately hiring for an HSM Security Engineer. This is a contract position expected to last 12 to 18 months, requiring 5 days onsite in Addison, TX. As an HSM Security Engineer, you will be responsible for security design, implementing and maintaining vendor security applications primarily related to crypto/security functions and modules. These requirements will then be used to determine and recommend the technical and operational feasibility of solutions in the crypto space. You will be required to maintain and enhance hosted crypto solutions like key management, payment, and general purpose HSMs which are integrated with end-user applications so that they are compliant with banks and industry standards of key security. You would work to develop prototypes of the system design and collaborate with database, operations, technical support, and other various technocrats throughout the proof of concept and implementation cycle. You will use your knowledge and abilities as senior technical resources to provide expertise to the team(s). You would also be responsible for administering and managing cryptographic keys, including key life cycle management, centrally managing keys with granular key management and proper access controls per our security standards and policy guidance.

Requirements

  • 5+ years of experience in HSM.
  • 3+ years of experience in Thales product such as Luna and/or Cipher Trust Manager (CTM).
  • 3+ years of experience in key Management products - Thales payShield, SafeNet HSM, Azure Key Vault (AKV), AWS KMS.
  • Design, implement, and support enterprise cryptographic services and key management platforms, including Thales CipherTrust Manager, Luna Network HSM, payShield 10K/10K+, Cloud HSM, and Cloud KMS solutions.
  • Enforce cryptographic architectures aligned with industry standards and frameworks including OASIS KMIP 2.x, PCI DSS, PCI HSM, NIST SP 800-57, NIST SP 800-131A, FIPS 140-3, GDPR, EMVCo, GlobalPlatform, and ANSI standards.
  • Establish and maintain enterprise-wide data protection controls, including data classification, encryption policies, key governance, secrets management, tokenization, and compliance monitoring.
  • Hands-on experience administering and automating Linux and Windows environments using modern Infrastructure-as-Code and automation frameworks such as PowerShell, Python, and GitOps methodologies.
  • Strong understanding of cryptographic APIs and integration frameworks including REST APIs, PKCS#11, KMIP, JCE/JCA, Microsoft CNG, MSCAPI, OpenSSL, and cloud-native security SDKs.
  • Design and operate cloud-native and containerized platforms using Kubernetes, OpenShift, Podman, Docker, Helm, and CI/CD pipelines.
  • Experience implementing and testing APIs using modern development and integration tools such as Postman, Insomnia, Swagger/OpenAPI, and API Gateway platforms.
  • Implement enterprise observability and operational monitoring using Splunk Enterprise, Dynatrace.
  • Utilize Agile, Scrum, Kanban, DevSecOps, Jira, Azure DevOps, and SDLC best practices to support secure and efficient platform delivery.
  • Perform lifecycle management, configuration management, firmware upgrades, vulnerability remediation, patch management, and compliance validation for cryptographic infrastructure.
  • Support enterprise adoption of Zero Trust security principles, machine identity management, certificate automation, and Post-Quantum Cryptography (PQC) readiness programs.
  • Experience with encryption and key management solutions including: Thales Luna Network HSM, Thales payShield 10K, CipherTrust Manager.
  • Experience implementing enterprise Key Lifecycle Management (KLM), cryptographic policy enforcement, and automated certificate management across on-premises and cloud environments.
  • Ability to partner with application owners, architects, cloud teams, and security stakeholders to define and implement cryptographic controls, key management strategies, and HSM/KMS service requirements.
  • Knowledge of database encryption technologies, including: Microsoft SQL Server TDE and EKM, Oracle TDE, PostgreSQL encryption, KMIP and PKCS#11-based key management integrations.
  • Experience with enterprise secrets management and workload identity solutions for Kubernetes and cloud-native applications.
  • Familiarity with Post-Quantum Cryptography (PQC), crypto-agility initiatives, and quantum-safe migration strategies.
  • Must be able to be engaged on a W-2 basis.

Nice To Haves

  • Ansible and Terraform
  • Other tools like Prometheus, Grafana, Elastic Stack, and SNMPv3 monitoring solutions

Responsibilities

  • Design, implement, and support enterprise cryptographic services and key management platforms, including Thales CipherTrust Manager, Luna Network HSM, payShield 10K/10K+, Cloud HSM, and Cloud KMS solutions.
  • Enforce cryptographic architectures aligned with industry standards and frameworks including OASIS KMIP 2.x, PCI DSS, PCI HSM, NIST SP 800-57, NIST SP 800-131A, FIPS 140-3, GDPR, EMVCo, GlobalPlatform, and ANSI standards.
  • Establish and maintain enterprise-wide data protection controls, including data classification, encryption policies, key governance, secrets management, tokenization, and compliance monitoring.
  • Administer and automate Linux and Windows environments using modern Infrastructure-as-Code and automation frameworks such as PowerShell, Python, and GitOps methodologies.
  • Design and operate cloud-native and containerized platforms using Kubernetes, OpenShift, Podman, Docker, Helm, and CI/CD pipelines.
  • Implement and test APIs using modern development and integration tools such as Postman, Insomnia, Swagger/OpenAPI, and API Gateway platforms.
  • Implement enterprise observability and operational monitoring using Splunk Enterprise, Dynatrace.
  • Utilize Agile, Scrum, Kanban, DevSecOps, Jira, Azure DevOps, and SDLC best practices to support secure and efficient platform delivery.
  • Perform lifecycle management, configuration management, firmware upgrades, vulnerability remediation, patch management, and compliance validation for cryptographic infrastructure.
  • Support enterprise adoption of Zero Trust security principles, machine identity management, certificate automation, and Post-Quantum Cryptography (PQC) readiness programs.
  • Implement enterprise Key Lifecycle Management (KLM), cryptographic policy enforcement, and automated certificate management across on-premises and cloud environments.
  • Partner with application owners, architects, cloud teams, and security stakeholders to define and implement cryptographic controls, key management strategies, and HSM/KMS service requirements.

Benefits

  • Medical & pharmacy coverage
  • Dental/vision insurance
  • 401(k)
  • Health saving account (HSA)
  • Flexible spending account (FSA)
  • Life Insurance
  • Pet Insurance
  • Short term and Long term Disability
  • Accident & Critical illness coverage
  • Pre-paid legal & ID theft protection
  • Sick time
  • Other types of paid leaves (as required by law)
  • Employee Assistance Program (EAP)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service