16 Sep
|
S.i. Systems
|
Winnipeg
16 Sep
S.i. Systems
Winnipeg
Cybersecurity Analyst to support cryptographic operations using HashiCorp Vault, PKI, and TLS/SSL certificate management - 2927
Duration: Until 30 Sep 2027 (possibility of extension) Location: Markham - Hybrid (3 days a week) Role Overview The Cryptography Analyst is responsible for delivering business-as-usual (BAU) cryptographic operations across key and secrets management, TLS/SSL certificate lifecycle, PKI services, and post-quantum cryptography (PQC) readiness. This role ensures secure, compliant, and resilient cryptographic services supporting enterprise platforms and applications. Top Required Skills:
Cryptography and Hashi Vault experience Information security incident handling Required Skills & Experience Technical Skills
HashiCorp Vault (administration and operations) Hardware Security Modules (Thales LUNA preferred) TLS/SSL certificate management and PKI Aviva: Internal Automation (APIs, scripting, CI/CD integration) Monitoring tools (Dynatrace, Rapid7, Power BI) Core Competencies Robust understanding of cryptographic principles and lifecycle Knowledge of RBAC, least privilege, and access control Experience with compliance and audit frameworks Problem-solving and troubleshooting skills Ability to operate in a 24/7 BAU environment Nice-to-Have
Experience with Kubernetes and cert-manager Exposure to Post-Quantum Cryptography (PQC) Experience in regulated industries (e.g., insurance, financial services) Key Responsibilities
Cryptography Services & Operations Provide operational support for: o HashiCorp Vault–based secrets and key management o HSM-integrated root of trust operations o TLS/SSL certificate lifecycle using platforms such as Sectigo o Cryptographic monitoring, reporting, and governance o PQC readiness, risk management, and enablement HashiCorp Vault & Secrets Management Administer and support Vault environments across production and non-production Manage: Secrets, keys, tokens, leases, and service accounts lifecycle o Authentication mechanisms and RBAC enforcement o Access Control Lists (ACLs) aligned with least privilege principles Perform: o Tenant onboarding/offboarding o Vault troubleshooting and performance tuning Aviva: Internal Support integrations with AWS KMS and external secret Platform Operations & Maintenance Conduct proactive monitoring and health checks Manage Vault upgrades, testing, and currency roadmap Support configuration changes and change management processes Coordinate off-hours support and cloud transformation HSM & Root of Trust Operations
Support Vault-HSM integration (Thales LUNA HSM) Manage: o Auto-unseal functionality o Key rotation and secure handling practices • Coordinate firmware upgrades and DR processes Certificate & PKI Lifecycle Management
Perform end-to-end certificate lifecycle operations: o Creation, renewal, revocation, replacement o Installation validation and incident troubleshooting Ensure SLA adherence (24-hour turnaround) Maintain certificate inventory and ownership records Support PKI documentation, audits, and compliance Certificate Automation & Governance Aviva: Internal
Design and operate certificate lifecycle automation Implement automation using: o ACME protocols o Vault PKI engine o Kubernetes cert-manager and cloud-native tools Maintain:
o Certificate inventory (including automation status) o Monitoring systems for renewal failures and expiry risks Enforce: o Certificate standards (CAs, algorithms, key sizes) o Security best practices (least privilege, segregation of duties) Cryptographic Inventory & Risk Management
Maintain a comprehensive cryptographic inventory: o Keys, secrets, certificates, and algorithms Identify: o Deprecated or weak cryptographic implementations Support audit, compliance, and risk assessments Conduct PQC readiness assessments Support: o Cryptographic transition strategies o Risk identification and mitigation Enable future-proof cryptographic capabilities Monitoring, Reporting & Governance
Deliver KPIs and service metrics across: o Vault operations o PKI and certificate automation o Cryptographic risk and PQC Use tools such as Dynatrace, SiteScope, Rapid7, Power BI, and Excel for reporting Security, Compliance & Resilience
Ensure compliance with security and regulatory requirements Support: o Backup and disaster recovery processes o Security investigations and audits Maintain high availability and resilience of cryptographic services Knowledge Transfer & Enablement
Develop and maintain documentation and runbooks Enable knowledge sharing across teams Drive continuous improvement and operational maturity Summary
This role is critical in ensuring secure, automated, and compliant cryptographic operations, with a focus on operational excellence, risk reduction, and future cryptographic readiness. Duration: Until 30 Sep 2027 (possibility of extension) Location: Markham - Hybrid (3 days a week) Role Overview The Cryptography Analyst is responsible for delivering business-as-usual (BAU) cryptographic operations across key and secrets management, TLS/SSL certificate lifecycle, PKI services, and post-quantum cryptography (PQC) readiness. This role ensures secure, compliant, and resilient cryptographic services supporting enterprise platforms and applications. Top Required Skills:
Ticket management skills Cryptography and Hashi Vault experience Information security incident handling Required Skills & Experience Technical Skills
HashiCorp Vault (administration and operations) Hardware Security Modules (Thales LUNA preferred) TLS/SSL certificate management and PKI Aviva: Internal Secrets management platforms (AWS Secrets Manager, etc.) Cloud platforms (AWS preferred) Automation (APIs, scripting, CI/CD integration) Monitoring tools (Dynatrace, Rapid7, Power BI) Core Competencies Strong understanding of cryptographic principles and lifecycle Knowledge of RBAC, least privilege, and access control Experience with compliance and audit frameworks Problem-solving and troubleshooting skills Ability to operate in a 24/7 BAU environment Nice-to-Have
Experience with Kubernetes and cert-manager Exposure to Post-Quantum Cryptography (PQC) Experience in regulated industries (e.g., insurance, financial services)
Key Responsibilities
Cryptography Services & Operations Provide operational support for: o HashiCorp Vault–based secrets and key management o HSM-integrated root of trust operations o TLS/SSL certificate lifecycle using platforms such as Sectigo o Cryptographic monitoring, reporting, and governance o PQC readiness, risk management, and enablement HashiCorp Vault & Secrets Management Administer and support Vault environments across production and non-production Manage: Secrets, keys, tokens, leases, and service accounts lifecycle o Authentication mechanisms and RBAC enforcement o Access Control Lists (ACLs) aligned with least privilege principles Perform: o Tenant onboarding/offboarding o Vault troubleshooting and performance tuning Aviva: Internal Support integrations with AWS KMS and external secret Platform Operations & Maintenance Conduct proactive monitoring and health checks Manage Vault upgrades, testing, and currency roadmap Support configuration changes and change management processes Coordinate off-hours support and cloud transformation HSM & Root of Trust Operations
Support Vault-HSM integration (Thales LUNA HSM) Manage: o Auto-unseal functionality o Key rotation and secure handling practices • Coordinate firmware upgrades and DR processes Certificate & PKI Lifecycle Management
Perform end-to-end certificate lifecycle operations: o Creation, renewal, revocation, replacement o Installation validation and incident troubleshooting Ensure SLA adherence (24-hour turnaround) Maintain certificate inventory and ownership records Support PKI documentation, audits, and compliance Certificate Automation & Governance Aviva: Internal
Design and operate certificate lifecycle automation Implement automation using: o ACME protocols o Vault PKI engine o Kubernetes cert-manager and cloud-native tools Maintain: o Certificate inventory (including automation status) o Monitoring systems for renewal failures and expiry risks Enforce: o Certificate standards (CAs, algorithms, key sizes) o Security best practices (least privilege, segregation of duties) Post-Quantum Cryptography (PQC)
Conduct PQC readiness assessments Support: o Cryptographic transition strategies o Risk identification and mitigation Enable future-proof cryptographic capabilities Monitoring, Reporting & Governance
Deliver KPIs and service metrics across: o Vault operations o PKI and certificate automation o Cryptographic risk and PQC Use tools such as Dynatrace, SiteScope, Rapid7, Power BI, and Excel for reporting Security, Compliance & Resilience
Ensure compliance with security and regulatory requirements Support: o Backup and disaster recovery processes o Security investigations and audits Maintain high availability and resilience of cryptographic services Knowledge Transfer & Enablement
Develop and maintain documentation and runbooks Enable knowledge sharing across teams Drive continuous improvement and operational maturity Summary
This role is critical in ensuring secure, automated, and compliant cryptographic operations, with a focus on operational excellence, risk reduction, and future cryptographic readiness. Disclaimer: AI may be used in evaluating candidates. This posting is for an existing vacancy. #J-18808-Ljbffr
📌 Cybersecurity Analyst to support cryptographic operations using HashiCorp Vault, PKI, and TLS/SSL ce (Winnipeg)
🏢 S.i. Systems
📍 Winnipeg