More jobs:
Senior Product Security Engineer – Cryptography
Job in
Worcester, Worcester County, Massachusetts, 01609, USA
Listed on 2026-07-20
Listing for:
Jobtailor
Full Time
position Listed on 2026-07-20
Job specializations:
-
IT/Tech
Blockchain / Web3, Crypto & DeFi, Cybersecurity
Job Description & How to Apply Below
Responsibilities
- Act as the primary technical owner for auditing Go-based cryptographic implementations within Open Shift and container runtimes (CRI‑O, Podman).
- Identify and resolve cryptographic discrepancies where containerized applications fail to correctly leverage the host's FIPS or PQC providers.
- Act as the primary technical owner responsible for continuing the implementation and integration of Red Hats cryptographic inventory tools (e.g. Crypto Scanner).
- Partner with the Principal Product Security Engineer to define and implement scanner policies for detecting cryptographic assets in our build pipelines.
- Work directly with pipeline and data teams to integrate these tools and produce a sustainable Cryptographic Bill of Materials (CBOM).
- Partner with product teams to integrate Merkle Tree Certificate support within the portfolio’s unified security fabric.
- Serve as the primary go‑to technical consultant for product teams (like Open Shift, Ansible, and Middleware) navigating cryptographic migrations (e.g. PQC, FIPS).
- Consult directly with engineers to help them audit their code, understand their dependencies (e.g. python‑cryptography), and build migration plans that align with the portfolio‑wide policy.
- Enable other teams by creating documentation, best‑practice guides, and office hours to scale your expertise.
- Define the functional requirements for and partner on the integration of new cryptographic tools, such as runtime instrumentation for core libraries.
- Track and manage critical cryptographic dependencies across the portfolio, working with RHEL Security and other teams to resolve blockers and ensure the successful, sequential delivery of modern crypto capabilities.
- Multi‑Language Technical Expertise:
Deep, hands‑on experience in Go and Python is required. - Applied Cryptography and PKI:
Broad knowledge in applied cryptography (PKI, TLS, digital signatures). - Strong understanding of modern cryptographic challenges, including Post‑Quantum Cryptography (PQC).
- Container & Cloud‑Native Security:
Strong understanding of OCI specifications and how container runtimes interact with cryptographic hardware (HSMs) or kernel‑level providers. - Project Ownership:
Proven experience owning and delivering complex, cross‑team technical projects from design to completion. - Collaborative Leadership: A track record of building relationships across teams and acting as a recognized go‑to person.
- Problem Solving:
Strong analytical skills to diagnose complex dependencies and technical blockers in a large‑scale software portfolio. - Bonus
Skills:
Previous experience contributing to or maintaining core cryptographic libraries or security‑focused Go projects. - Familiarity with SPIFFE/SPIRE or Sigstore/Cosign.
- Experience with Merkle Tree implementations or binary‑level runtime analysis.
- Familiarity with FIPS validation processes in virtualized/containerized environments.
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×