Hiring.Camp

Crypto - Thales for Key Management & Entrust for HSM

Base Camp IT Recruiting

·

Today

Location
HK
Type
Full-time
Department
IT
Closing date
Today
Source
Vincere

Description

Cryptography Security Engineer (HSM & Key Management)

1-Year Contract (Renewable)
Financial Services Industry
Location: Hong Kong, Quarry Bay

About the Role

We are seeking a Cryptography Security Engineer to support and maintain enterprise encryption platforms that safeguard critical systems and sensitive data. This role involves managing Hardware Security Modules (HSMs), encryption key management solutions, and ensuring cryptographic services remain secure, reliable, and compliant with industry standards.

You will work closely with infrastructure, security, application, and operations teams to support business-critical encryption services within a highly regulated environment.

Key Responsibilities

  • Administer and maintain Hardware Security Modules (HSMs) supporting enterprise and payment-related encryption services.

  • Manage encryption keys throughout their lifecycle, including generation, rotation, backup, recovery, and retirement.

  • Perform installation, configuration, upgrades, and maintenance of cryptographic platforms and security infrastructure.

  • Troubleshoot and resolve incidents related to encryption services, HSMs, certificates, and key management systems.

  • Participate in change, release, and maintenance activities, including after-hours and weekend support when required.

  • Ensure cryptographic environments comply with internal security policies, regulatory requirements, and industry best practices.

  • Collaborate with cross-functional teams to integrate encryption services into business applications and IT infrastructure.

  • Support incident, problem, change, and release management processes to maintain service availability.

  • Prepare and maintain technical documentation, operational procedures, and system configurations.

  • Continuously improve operational processes through automation and process optimization where applicable.

Requirements

  • Experience managing Hardware Security Modules (HSMs) within enterprise or financial services environments.

  • Hands-on experience with enterprise key management solutions, preferably Thales CipherTrust or similar platforms.

  • Strong understanding of cryptographic concepts, encryption technologies, and key management principles.

  • Knowledge of IT infrastructure, including Windows/Linux servers, networking, virtualization, and cloud platforms.

  • Familiarity with security frameworks, regulatory requirements, and operational controls.

  • Experience working within IT Service Management (ITSM) environments covering incident, problem, change, and release management.

  • Ability to prioritize multiple tasks while supporting business-critical systems.

  • Strong communication and stakeholder management skills.

  • Experience using collaboration and documentation tools such as JIRA, Confluence, Microsoft Teams, and SharePoint is an advantage.

  • Exposure to scripting or system administration (PowerShell, Bash, Python, or similar) is a plus.

Preferred Qualifications

  • Professional certifications such as CISSP, CISM, CISA, PCI QSA, ITIL, or equivalent.

  • Experience supporting enterprise security, cloud security, or financial services environments.

  • Knowledge of PKI, certificates, and secure key lifecycle management will be advantageous.

Skills

PythonLinuxJiraConfluenceITILCISSP