×
Register Here to Apply for Jobs or Post Jobs. X

HSM Security Engineer

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: Innova
Full Time position
Listed on 2026-09-05
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
A client of Innova Solutions is immediately hiring for an HSM Security Engineer.

Position type:
Contract
Duration: 12 to 18 months

Location:

5 days onsite in Addison, TX.

As an HSM Security Engineer, you will:

Top

Skills:
  • 5+ years of experience in HSM.
  • 3+ years of experience in Thales product such as Luna and/or Cipher Trust Manager (CTM).
  • 3+ years of experience in key Management products - Thales pay Shield, Safe Net HSM, Azure Key Vault (AKV), AWS KMS.
Description:

Mid-level Senior Security Engineer is responsible for security design, implementing and maintain vendor security applications primarily related to crypto/security functions and modules.
These requirements will then be used to make you determine and recommend the technical and operational feasibility of the solutions in the crypto space.
You will be required to maintain and enhance hosted crypto solutions like key management, payment, and general purpose HSMs which are integrated with end user applications so that they are compliant to the banks, as well as industry standards of key security.
You would work to develop prototypes of the system design and work with database, operations, technical support, and other various technocrats throughout the proof of concept and implementation cycle.
You will use your knowledge and abilities as senior technical resources to provide your expertise to the team(s).
You would also be responsible for administering and managing cryptographic keys, including key life cycle management, centrally managing keys with granular key management and proper access controls per our security standards and policy guidance.

Required Experience

Design, implement, and support enterprise cryptographic services and key management platforms, including Thales Cipher Trust Manager, Luna Network HSM, pay Shield 10K/10K+, Cloud HSM, and Cloud KMS solutions.

Enforce cryptographic architectures aligned with industry standards and frameworks including OASIS KMIP 2.x, PCI DSS, PCI HSM, NIST SP 800-57, NIST SP 800-131A, FIPS 140-3, GDPR, EMVCo, Global Platform, and ANSI standards.

Establish and maintain enterprise-wide data protection controls, including data classification, encryption policies, key governance, secrets management, tokenization, and compliance monitoring.

Hands-on experience administering and automating Linux and Windows environments using modern Infrastructure-as-Code and automation frameworks such as Power Shell, Python, and Git Ops methodologies. Ansible and Terraform are nice to have.

Strong understanding of cryptographic APIs and integration frameworks including REST APIs, PKCS#11, KMIP, JCE/JCA, Microsoft CNG, MSCAPI, OpenSSL, and cloud-native security SDKs.

Design and operate cloud-native and containerized platforms using Kubernetes, Open Shift, Podman, Docker, Helm, and CI/CD pipelines.

Experience implementing and testing APIs using modern development and integration tools such as Postman, Insomnia, Swagger/OpenAPI, and API Gateway platforms.

Implement enterprise observability and operational monitoring using Splunk Enterprise, Dynatrace. Other tools like Prometheus, Grafana, Elastic Stack, and SNMPv3 monitoring solutions are nice to have.

Utilize Agile, Scrum, Kanban, Dev Sec Ops , Jira, Azure Dev Ops, and SDLC best practices to support secure and efficient platform delivery.

Perform lifecycle management, configuration management, firmware upgrades, vulnerability remediation, patch management, and compliance validation for cryptographic infrastructure.

Support enterprise adoption of Zero Trust security principles, machine identity management, certificate automation, and Post-Quantum Cryptography (PQC) readiness programs.

Experience with encryption and key management solutions including:
Thales Luna Network HSM

Thales pay Shield 10K

Cipher Trust Manager

Experience implementing enterprise Key Lifecycle Management (KLM), cryptographic policy enforcement, and automated certificate management across on-premises and cloud environments.

Ability to partner with application owners, architects, cloud teams, and security stakeholders to define and implement cryptographic controls, key management strategies, and HSM/KMS service requirements.

Knowledge of database encryption technologies, including:
Microsoft SQL Server TDE and EKM

Oracle TDE

PostgreSQL encryption

KMIP and PKCS#11-based key management integrations

Experience with enterprise secrets management and workload identity solutions for Kubernetes and cloud-native applications.

Familiarity with Post-Quantum Cryptography (PQC), crypto-agility initiatives, and quantum-safe migration strategies.

Qualified candidates should APPLY NOW for immediate consideration!
This position is only open to applicants who can be engaged on a W-2 basis.
Please hit APPLY to provide the required information, and we will be back in touch as soon as possible.
We are currently interviewing to fill this and other similar positions. If this role is not a fit for you, we do offer a referral bonus program for referrals that we successfully…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary