16 Sep
|
S.i. Systems
|
Toronto
16 Sep
S.i. Systems
Toronto
Cybersecurity Analyst to support cryptographic operations using HashiCorp Vault, PKI, and TLS/SSL certificate management - 2927 Duration: Until 30 Sep 2027 (possibility of extension) Location: Markham - Hybrid (3 days a week) Role Overview The Cryptography Analyst is responsible for delivering business-as-usual (BAU) cryptographic operations across key and secrets management, TLS/SSL certificate lifecycle, PKI services, and post-quantum cryptography (PQC) readiness. This role ensures secure, compliant, and resilient cryptographic services supporting enterprise platforms and applications.
Top Required Skills: Cryptography and Hashi Vault experience Information security incident handling Required Skills &
Experience Technical Skills HashiCorp Vault (administration and operations) Hardware Security Modules (Thales LUNA preferred) TLS/SSL certificate management and PKI Aviva: Internal Automation (APIs, scripting, CI/CD integration) Monitoring tools (Dynatrace, Rapid7, Power BI) Core Competencies Strong understanding of cryptographic principles and lifecycle Knowledge of RBAC, least privilege, and access control Experience with compliance and audit frameworks Problem-solving and troubleshooting skills Ability to operate in a 24/7 BAU environment Nice-to-Have Experience with Kubernetes and cert-manager Exposure to Post-Quantum Cryptography (PQC) Experience in regulated industries (e.g., insurance, financial services) Key Responsibilities Cryptography Services &
• Operations ~ Provide operational support for: o HashiCorp Vault–based secrets and key management o HSM-integrated root of trust operations o TLS/SSL certificate lifecycle using platforms such as Sectigo o Cryptographic monitoring, reporting, and governance o PQC readiness, risk management, and enablement HashiCorp Vault &
• Secrets Management Administer and support Vault environments across production and non-production Manage: Secrets, keys, tokens, leases, and service accounts lifecycle o Authentication mechanisms and RBAC enforcement o Access Control Lists (ACLs) aligned with least privilege principles Perform: o Tenant onboarding/offboarding o Vault troubleshooting and performance tuning Aviva: Internal Support integrations with AWS KMS and external secret Platform Operations &
• Maintenance Conduct proactive monitoring and health checks Manage Vault upgrades, testing, and currency roadmap Support configuration changes and change management processes Coordinate off-hours support and cloud transformation HSM &
• Root of Trust Operations Support Vault-HSM integration (Thales LUNA HSM) Manage: o Auto-unseal functionality o Key rotation and secure handling practices • Coordinate firmware upgrades and DR processes Certificate &
• PKI Lifecycle Management Perform end-to-end certificate lifecycle operations: o Creation, renewal, revocation, replacement o Installation validation and incident troubleshooting Ensure SLA adherence (24-hour turnaround) Maintain certificate inventory and ownership records Support PKI documentation, audits, and compliance Certificate Automation &
• Governance Aviva: Internal Design and operate certificate lifecycle automation Implement automation using: o ACME protocols o Vault PKI engine o Kubernetes cert-manager and cloud-native tools Maintain:
o Certificate inventory (including automation status) o Monitoring systems for renewal failures and expiry risks Enforce: o Certificate standards (CAs, algorithms, key sizes) o Security best practices (least privilege, segregation of duties) Cryptographic Inventory &
• Risk Management Maintain a comprehensive cryptographic inventory: o Keys, secrets, certificates, and algorithms Identify: o Deprecated or weak cryptographic implementations Support audit, compliance, and risk assessments Conduct PQC readiness assessments Support: o Cryptographic transition strategies o Risk identification and mitigation Enable future-proof cryptographic capabilities Monitoring, Reporting &
• Governance Deliver KPIs and service metrics across: o Vault operations o PKI and certificate automation o Cryptographic risk and PQC Use tools such as Dynatrace, SiteScope, Rapid7, Power BI, and Excel for reporting Security, Compliance &
• Resilience Ensure compliance with security and regulatory requirements Support: o Backup and disaster recovery processes o Security investigations and audits Maintain high availability and resilience of cryptographic services Knowledge Transfer &
• Enablement Develop and maintain documentation and runbooks Enable knowledge sharing across teams Drive continuous improvement and operational maturity Summary ~ This role is critical in ensuring secure, automated, and compliant cryptographic operations, with a focus on operational excellence, risk reduction, and future cryptographic readiness.
Duration: Until 30 Sep 2027 (possibility of extension) Location: Markham - Hybrid (3 days a week) Role Overview The Cryptography Analyst is responsible for delivering business-as-usual (BAU) cryptographic operations across key and secrets management, TLS/SSL certificate lifecycle, PKI services, and post-quantum cryptography (PQC) readiness. This role ensures secure, compliant, and resilient cryptographic services supporting enterprise platforms and applications.
Top Required Skills: Ticket management skills Cryptography and Hashi Vault experience Information security incident handling Required Skills &
Experience Technical Skills HashiCorp Vault (administration and operations) Hardware Security Modules (Thales LUNA preferred) TLS/SSL certificate management and PKI Aviva: Internal Secrets management platforms (AWS Secrets Manager, etc.) Cloud platforms (AWS preferred) Automation (APIs, scripting, CI/CD integration) Monitoring tools (Dynatrace, Rapid7, Power BI) Core Competencies Solid understanding of cryptographic principles and lifecycle Knowledge of RBAC, least privilege, and access control Experience with compliance and audit frameworks Problem-solving and troubleshooting skills Ability to operate in a 24/7 BAU environment Nice-to-Have Experience with Kubernetes and cert-manager Exposure to Post-Quantum Cryptography (PQC) Experience in regulated industries (e.g., insurance, financial services)
Key Responsibilities Cryptography Services &
• Operations ~ Provide operational support for: o HashiCorp Vault–based secrets and key management o HSM-integrated root of trust operations o TLS/SSL certificate lifecycle using platforms such as Sectigo o Cryptographic monitoring, reporting, and governance o PQC readiness, risk management, and enablement HashiCorp Vault &
• Secrets Management Administer and support Vault environments across production and non-production Manage: Secrets, keys, tokens, leases, and service accounts lifecycle o Authentication mechanisms and RBAC enforcement o Access Control Lists (ACLs) aligned with least privilege principles Perform: o Tenant onboarding/offboarding o Vault troubleshooting and performance tuning Aviva: Internal Support integrations with AWS KMS and external secret Platform Operations &
• Maintenance Conduct proactive monitoring and health checks Manage Vault upgrades, testing, and currency roadmap Support configuration changes and change management processes Coordinate off-hours support and cloud transformation HSM &
• Root of Trust Operations Support Vault-HSM integration (Thales LUNA HSM) Manage: o Auto-unseal functionality o Key rotation and secure handling practices • Coordinate firmware upgrades and DR processes Certificate &
• PKI Lifecycle Management Perform end-to-end certificate lifecycle operations: o Creation, renewal, revocation, replacement o Installation validation and incident troubleshooting Ensure SLA adherence (24-hour turnaround) Maintain certificate inventory and ownership records Support PKI documentation, audits, and compliance Certificate Automation &
• Governance Aviva: Internal Design and operate certificate lifecycle automation Implement automation using: o ACME protocols o Vault PKI engine o Kubernetes cert-manager and cloud-native tools Maintain: o Certificate inventory (including automation status) o Monitoring systems for renewal failures and expiry risks Enforce: o Certificate standards (CAs, algorithms, key sizes) o Security best practices (least privilege, segregation of duties) Post-Quantum Cryptography (PQC) Conduct PQC readiness assessments Support: o Cryptographic transition strategies o Risk identification and mitigation Enable future-proof cryptographic capabilities Monitoring, Reporting &
• Governance Deliver KPIs and service metrics across: o Vault operations o PKI and certificate automation o Cryptographic risk and PQC Use tools such as Dynatrace, SiteScope, Rapid7, Power BI, and Excel for reporting Security, Compliance &
• Resilience Ensure compliance with security and regulatory requirements Support: o Backup and disaster recovery processes o Security investigations and audits Maintain high availability and resilience of cryptographic services Knowledge Transfer &
• Enablement Develop and maintain documentation and runbooks Enable knowledge sharing across teams Drive continuous improvement and operational maturity Summary ~ This role is critical in ensuring secure, automated, and compliant cryptographic operations, with a focus on operational excellence, risk reduction, and future cryptographic readiness.
Disclaimer: AI may be used in evaluating candidates. This posting is for an existing vacancy.
📌 Cybersecurity Analyst to support cryptographic operations using HashiCorp Vault, PKI, and TLS/SSL certificate management - 2927 (Toronto)
🏢 S.i. Systems
📍 Toronto