About this role
Job Description Cybersecurity Analyst / Cryptography Analyst
Looking for an opportunity to work on meaningful projects and cutting-edge technologies? Join a high-performing team in the insurance sector for our client and contribute to initiatives that strengthen security, support digital transformation, and drive operational excellence in a fast-paced and collaborative environment.
What is in it for you:
? Salaried: $30.50 per hour.
? 12-month contract with the potential for permanent employment.
? Full-time position: 37.50 hours per week.
? Occasional overtime may be required to support project requirements.
? Hybrid model: 3 days per week on-site, subject to change.
Responsibilities:
Vault & Secrets Management
? Provide operational support for HashiCorp Vault-based secrets and key management.
? Administer and support HashiCorp Vault environments across production and non-production environments.
? Manage the lifecycle of secrets, keys, tokens, leases, and service accounts.
? Maintain authentication mechanisms, role-based access control, and access control lists aligned with least privilege principles.
? Perform tenant onboarding and offboarding activities.
? Troubleshoot and optimize Vault performance.
? Support integrations with AWS KMS and external secret platforms.
? Manage Vault upgrades, testing, and currency roadmaps.
Cryptography & HSM Operations
? Support HSM-integrated root of trust operations.
? Support Vault-HSM integration, including Thales LUNA HSM environments.
? Manage auto-unseal functionality, key rotation activities, and secure key handling practices.
? Coordinate firmware upgrades and disaster recovery processes.
? Support post-quantum cryptography readiness, assessments, transition strategies, risk identification, and mitigation.
? Maintain inventories of cryptographic keys, secrets, certificates, and algorithms.
? Identify deprecated or weak cryptographic implementations.
Certificate & PKI Management
? Manage TLS/SSL certificate lifecycle activities, including creation, renewal, revocation, replacement, installation validation, and incident troubleshooting.
? Ensure certificate lifecycle service level agreement adherence.
? Maintain certificate inventory and ownership records.
? Support PKI documentation, compliance activities, audits, and governance requirements.
? Design, implement, and operate certificate lifecycle automation solutions.
? Implement automation using ACME protocols, Vault PKI engine, Kubernetes cert-manager, and cloud-native tools.
? Maintain certificate inventory, automation status records, and monitoring systems for renewal failures and expiry risks.
? Enforce certificate standards, security best practices, least privilege principles, and segregation of duties.
Monitoring, Compliance & Security
? Perform cryptographic monitoring, reporting, governance, and risk management activities.
? Conduct proactive monitoring and health checks.
? Deliver KPIs and service metrics related to Vault operations, PKI, certificate automation, cryptographic risks, and post-quantum cryptography readiness.
? Utilize moni