16 Sep
|
S.i. Systems
|
Ontario
16 Sep
S.i. Systems
Ontario
Cybersecurity Analyst to support cryptographic operations using HashiCorp Vault, PKI, and TLS/SSL certificate management - 2927 Duration: Until 30 Sep 2027 (possibility of extension)
Location: Markham - Hybrid (3 days a week)
Role Overview The Cryptography Analyst is responsible for delivering business-as-usual (BAU) cryptographic operations across key and secrets management, TLS/SSL certificate lifecycle, PKI services, and post-quantum cryptography (PQC) readiness. This role ensures secure, compliant, and resilient cryptographic services supporting enterprise platforms and applications.
Top Required Skills: Cryptography and Hashi Vault experience
Information security incident handling
Required Skills & Experience Technical Skills HashiCorp Vault (administration and operations)
Hardware Security Modules (Thales LUNA preferred)
TLS/SSL certificate management and PKI Aviva: Internal
Automation (APIs, scripting, CI/CD integration)
Monitoring tools (Dynatrace, Rapid7, Power BI) Core Competencies
Solid understanding of cryptographic principles and lifecycle
Knowledge of RBAC, least privilege, and access control
Experience with compliance and audit frameworks
Problem-solving and troubleshooting skills
Ability to operate in a 24/7 BAU environment
Nice-to-Have Experience with Kubernetes and cert-manager
Exposure to Post-Quantum Cryptography (PQC)
Experience in regulated industries (e.g., insurance, financial services)
Key Responsibilities Cryptography Services & Operations
Provide operational support for: o HashiCorp Vault–based secrets and key management o HSM-integrated root of trust operations o TLS/SSL certificate lifecycle using platforms such as Sectigo o Cryptographic monitoring, reporting, and governance o PQC readiness, risk management, and enablement
HashiCorp Vault & Secrets Management
Administer and support Vault environments across production and non-production
Manage: Secrets, keys, tokens, leases, and service accounts lifecycle o Authentication mechanisms and RBAC enforcement o Access Control Lists (ACLs) aligned with least privilege principles
Perform: o Tenant onboarding/offboarding o Vault troubleshooting and performance tuning Aviva: Internal
Support integrations with AWS KMS and external secret
Platform Operations & Maintenance
Conduct proactive monitoring and health checks
Manage Vault upgrades, testing, and currency roadmap
Support configuration changes and change management processes
Coordinate off-hours support and cloud transformation
HSM & Root of Trust Operations Support Vault-HSM integration (Thales LUNA HSM)
Manage: o Auto-unseal functionality o Key rotation and secure handling practices • Coordinate firmware upgrades and DR processes
Certificate & PKI Lifecycle Management Perform end-to-end certificate lifecycle operations: o Creation, renewal, revocation, replacement o Installation validation and incident troubleshooting
Ensure SLA adherence (24-hour turnaround)
Maintain certificate inventory and ownership records
Support PKI documentation, audits, and compliance
Certificate Automation & Governance Aviva: Internal Design and operate certificate lifecycle automation
Implement automation using: o ACME protocols o Vault PKI engine o Kubernetes cert-manager and cloud-native tools
Maintain:
o Certificate inventory (including automation status) o Monitoring systems for renewal failures and expiry risks
Enforce: o Certificate standards (CAs, algorithms, key sizes) o Security best practices (least privilege, segregation of duties)
Cryptographic Inventory & Risk Management Maintain a comprehensive cryptographic inventory: o Keys, secrets, certificates, and algorithms
Identify: o Deprecated or weak cryptographic implementations
Support audit, compliance, and risk assessments
Conduct PQC readiness assessments
Support: o Cryptographic transition strategies o Risk identification and mitigation
Enable future-proof cryptographic capabilities
Monitoring, Reporting & Governance Deliver KPIs and service metrics across: o Vault operations o PKI and certificate automation o Cryptographic risk and PQC
Use tools such as Dynatrace, SiteScope, Rapid7, Power BI, and Excel for reporting
Security, Compliance & Resilience Ensure compliance with security and regulatory requirements
Support: o Backup and disaster recovery processes o Security investigations and audits
Maintain high availability and resilience of cryptographic services
Knowledge Transfer & Enablement Develop and maintain documentation and runbooks
Enable knowledge sharing across teams
Drive continuous improvement and operational maturity
Summary This role is critical in ensuring secure, automated, and compliant cryptographic operations, with a focus on operational excellence, risk reduction, and future cryptographic readiness.
Duration: Until 30 Sep 2027 (possibility of extension)
Location: Markham - Hybrid (3 days a week)
Role Overview The Cryptography Analyst is responsible for delivering business-as-usual (BAU) cryptographic operations across key and secrets management, TLS/SSL certificate lifecycle, PKI services, and post-quantum cryptography (PQC) readiness. This role ensures secure, compliant, and resilient cryptographic services supporting enterprise platforms and applications.
Top Required Skills: Ticket management skills
Cryptography and Hashi Vault experience
Information security incident handling
Required Skills & Experience Technical Skills HashiCorp Vault (administration and operations)
Hardware Security Modules (Thales LUNA preferred)
TLS/SSL certificate management and PKI Aviva: Internal
Secrets management platforms (AWS Secrets Manager, etc.)
Cloud platforms (AWS preferred)
Automation (APIs, scripting, CI/CD integration)
Monitoring tools (Dynatrace, Rapid7, Power BI) Core Competencies
Strong understanding of cryptographic principles and lifecycle
Knowledge of RBAC, least privilege, and access control
Experience with compliance and audit frameworks
Problem-solving and troubleshooting skills
Ability to operate in a 24/7 BAU environment
Nice-to-Have Experience with Kubernetes and cert-manager
Exposure to Post-Quantum Cryptography (PQC)
Experience in regulated industries (e.g., insurance, financial services)
Key Responsibilities Cryptography Services & Operations
Provide operational support for: o HashiCorp Vault–based secrets and key management o HSM-integrated root of trust operations o TLS/SSL certificate lifecycle using platforms such as Sectigo o Cryptographic monitoring, reporting, and governance o PQC readiness, risk management, and enablement
HashiCorp Vault & Secrets Management
Administer and support Vault environments across production and non-production
Manage: Secrets, keys, tokens, leases, and service accounts lifecycle o Authentication mechanisms and RBAC enforcement o Access Control Lists (ACLs) aligned with least privilege principles
Perform: o Tenant onboarding/offboarding o Vault troubleshooting and performance tuning Aviva: Internal
Support integrations with AWS KMS and external secret
Platform Operations & Maintenance
Conduct proactive monitoring and health checks
Manage Vault upgrades, testing, and currency roadmap
Support configuration changes and change management processes
Coordinate off-hours support and cloud transformation
HSM & Root of Trust Operations Support Vault-HSM integration (Thales LUNA HSM)
Manage: o Auto-unseal functionality o Key rotation and secure handling practices • Coordinate firmware upgrades and DR processes
Certificate & PKI Lifecycle Management Perform end-to-end certificate lifecycle operations: o Creation, renewal, revocation, replacement o Installation validation and incident troubleshooting
Ensure SLA adherence (24-hour turnaround)
Maintain certificate inventory and ownership records
Support PKI documentation, audits, and compliance
Certificate Automation & Governance Aviva: Internal Design and operate certificate lifecycle automation
Implement automation using: o ACME protocols o Vault PKI engine o Kubernetes cert-manager and cloud-native tools
Maintain: o Certificate inventory (including automation status) o Monitoring systems for renewal failures and expiry risks
Enforce: o Certificate standards (CAs, algorithms, key sizes) o Security best practices (least privilege, segregation of duties)
Post-Quantum Cryptography (PQC) Conduct PQC readiness assessments
Support: o Cryptographic transition strategies o Risk identification and mitigation
Enable future-proof cryptographic capabilities
Monitoring, Reporting & Governance Deliver KPIs and service metrics across: o Vault operations o PKI and certificate automation o Cryptographic risk and PQC
Use tools such as Dynatrace, SiteScope, Rapid7, Power BI, and Excel for reporting
Security, Compliance & Resilience Ensure compliance with security and regulatory requirements
Support: o Backup and disaster recovery processes o Security investigations and audits
Maintain high availability and resilience of cryptographic services
Knowledge Transfer & Enablement Develop and maintain documentation and runbooks
Enable knowledge sharing across teams
Drive continuous improvement and operational maturity
Summary This role is critical in ensuring secure, automated, and compliant cryptographic operations, with a focus on operational excellence, risk reduction, and future cryptographic readiness.
Disclaimer:
AI may be used in evaluating candidates.
This posting is for an existing vacancy.
#J-18808-Ljbffr
📌 Cybersecurity Analyst to support cryptographic operations using HashiCorp Vault, PKI, and TLS/SSL ce (Ontario)
🏢 S.i. Systems
📍 Ontario