Product Security Lead (Code Signing / PKI) ~ We at Raise are hiring a Product Security Lead (Code Signing / PKI) for one of our top clients. Windows, Linux & CI/CD Signing Workflows Implement and support Windows and Linux code-signing workflows using Microsoft SignTool, OpenSSL, and associated platform tooling. Integrate signing capabilities into enterprise CI/CD, build, release, and artifact-management pipelines.
Automate secure signing processes while preserving key protection, access controls, traceability, compliance, and audit requirements. Own certificate and key lifecycle processes, including issuance, secure storage, rotation, renewal, revocation, retirement, and recovery planning. Establish and maintain governance, access, approval, monitoring, and audit controls for signing assets and cryptographic material.
Coordinate certificate renewals and key rotations to minimize disruption to development, manufacturing, and release activities. Maintain accurate standards, inventories, procedures, operational records, and audit evidence. Support secure firmware and embedded-system signing processes throughout product development and release lifecycles.
Enable and maintain Secure Boot signing implementations and associated trust relationships. Support device identity implementations, including iDevID certificates and related provisioning processes. Secure SDLC & Software Supply-Chain Security Embed code-signing requirements and controls within secure development and product release processes.
Strengthen software supply-chain integrity through authenticated artifacts, controlled signing services, and auditable chain-of-custody practices. Collaborate with engineering, DevOps, release, security, compliance, and manufacturing stakeholders to resolve risks and operational gaps.
Priority Technical Requirements
Candidates must demonstrate direct hands‑on ownership of code-signing infrastructure, HSM‑backed signing services, AppViewX PKI+, embedded‑security controls, or enterprise PKI operations.
Security‑adjacent experience without direct implementation and operational ownership is not sufficient for this role. Issuance, secure storage, rotation, renewal, revocation, retirement, governance, compliance, and audit support.
Linux and Windows signing workflows using OpenSSL, Microsoft SignTool, and CI/CD pipeline integrations.
Embedded product security: Firmware and embedded‑system signing, Secure Boot implementations, device identities such as iDevID, and production release controls. Software supply‑chain integrity: Secure SDLC, manufacturing and software chain‑of‑custody processes, and production‑grade code‑signing operations.
Technical Qualifications
Robust experience with OpenSSL, Microsoft SignTool, Windows and Linux signing workflows, and CI/CD integrations.
Experience securing firmware, embedded systems, Secure Boot implementations, device identities such as iDevID, and software releases with audited chain‑of‑custody controls. Strong understanding of Secure SDLC, software supply‑chain security, manufacturing controls, and production code‑signing operations.
Experience supporting enterprise product development, embedded technology, or manufacturing environments. Ability to translate security and audit requirements into practical engineering controls and operating procedures. Hands‑on technical owner: Security and control focused: Works effectively with engineering, DevOps, release, security, compliance, and manufacturing teams.
We can help! We strive to build teams that reflect the diversity of the communities we work in. We encourage all qualified applicants to apply, including people from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with visible/nonvisible disabilities.
In order to submit candidates for roles, our clients will sometimes require personal information to confirm the identity of applicants and their legal status to work. Raise will never ask you for personal or banking information unless you have been selected for a job.
📌 Product Security Lead (Code Signing / PKI) (Toronto)
🏢 Raise
📍 Toronto