Implementation Engineer — Cryptographic Strategy & Post-Quantum

Remote
Full Time
Experienced

Implementation Engineer — Cryptographic Strategy & Post-Quantum Readiness

Location: Remote, India
Experience: 5–10+ years
Reporting to: Senior Security Engineer / Cryptographic Strategy Lead

We are seeking a hands-on Implementation Engineer to help turn enterprise cryptographic strategy and Post-Quantum Readiness (PQR) goals into practical, scalable services. This role will focus on enabling self-service certificate capabilities through DigiCert, automating certificate lifecycle management, and establishing a Cryptographic Bill of Materials (CBOM) across the enterprise.

The ideal candidate is an experienced engineer who can work directly with platform, application, infrastructure, cloud, and security teams to deliver automation, improve cryptographic visibility, reduce certificate-related operational risk, and build crypto-agile foundations for future PQC migration.

Responsibilities

  • Implement enterprise cryptographic strategy through practical platforms, services, automation, and engineering standards.

  • Enable and expand DigiCert self-service capabilities for application and infrastructure teams, including secure certificate request, approval, issuance, renewal, revocation, and reporting workflows.

  • Design, build, and support automated certificate lifecycle management across enterprise environments.

  • Integrate certificate automation with CI/CD pipelines, cloud platforms, infrastructure-as-code, secrets-management tools, load balancers, APIs, and application platforms.

  • Establish and maintain a Cryptographic Bill of Materials (CBOM) that documents cryptographic assets, certificates, algorithms, keys, protocols, libraries, dependencies, ownership, business criticality, and lifecycle status.

  • Support cryptographic discovery and inventory efforts across applications, endpoints, networks, cloud services, PKI, and third-party technologies.

  • Help identify and remediate certificate expiration risk, weak or legacy cryptographic configurations, hard-coded cryptographic dependencies, and gaps in crypto-agility.

  • Develop reusable implementation patterns, runbooks, technical documentation, dashboards, and operational controls for certificate and cryptographic services.

  • Partner with senior engineers and architects on PQR and PQC initiatives, including readiness assessments, migration planning, hybrid cryptography pilots, and technology evaluations.

  • Track implementation progress, technical dependencies, risks, and remediation status; escalate blockers to the senior lead as needed.

  • Provide hands-on technical support and guidance to application and infrastructure teams adopting enterprise cryptographic services.

Required qualifications

  • 5–10 years of hands-on experience in security engineering, platform engineering, DevSecOps, cloud engineering, infrastructure engineering, or application engineering.

  • Practical experience with PKI, X.509 certificates, TLS/SSL, certificate authorities, certificate lifecycle management, and key-management concepts.

  • Experience administering, integrating, or automating enterprise certificate-management platforms; DigiCert experience is strongly preferred.

  • Experience building automation with Python, PowerShell, Bash, Java, Go, or similar languages.

  • Familiarity with REST APIs, CI/CD pipelines, Git-based workflows, Terraform, Ansible, containers, and/or Kubernetes.

  • Experience working in AWS, Azure, and/or Google Cloud, including cloud certificate, key-management, secrets, identity, and network-security services.

  • Understanding of applied cryptography, including encryption, hashing, digital signatures, key exchange, PKI, protocols, and cryptographic libraries.

  • Ability to troubleshoot certificate, TLS, trust-store, key, and cryptographic configuration issues in production environments.

  • Strong communication and documentation skills, with the ability to work effectively in a remote, cross-functional global team.

Preferred qualifications

  • Experience implementing certificate self-service portals, certificate automation, ACME/SCEP/EST workflows, or certificate lifecycle integrations.

  • Experience creating or maintaining a CBOM, cryptographic inventory, software bill of materials, configuration-management database, or asset-discovery program.

  • Familiarity with Post-Quantum Cryptography, Post-Quantum Readiness, crypto-agility, and emerging standards such as ML-KEM and ML-DSA.

  • Experience with HSMs, cloud KMS services, secrets-management platforms, code signing, mTLS, API security, or enterprise PKI modernization.

  • Experience in a large, regulated, or highly distributed enterprise environment.

Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*