17 Sep
|
S.i. Systems
|
Toronto
17 Sep
S.i. Systems
Toronto
Cybersecurity Analyst to support cryptographic operations using HashiCorp Vault, PKI, and TLS/SSL certificate management - 2927
Duration: Until 30 Sep 2027 (possibility of extension)
Location: Markham - Hybrid (3 days a week)
Role Overview The Cryptography Analyst is responsible for delivering business-as-usual (BAU) cryptographic operations across key and secrets management, TLS/SSL certificate lifecycle, PKI services, and post-quantum cryptography (PQC) readiness. This role ensures secure, compliant, and resilient cryptographic services supporting enterprise platforms and applications.
Top Required Skills:
- Cryptography and Hashi Vault experience
- Information security incident handling
Required Skills & Experience Technical Skills
- HashiCorp Vault (administration and operations)
- Hardware Security Modules (Thales LUNA preferred)
- TLS/SSL certificate management and PKI Aviva: Internal
- Automation (APIs, scripting, CI/CD integration)
- Monitoring tools (Dynatrace, Rapid7, Power BI) Core Competencies
- Solid understanding of cryptographic principles and lifecycle
- Knowledge of RBAC, least privilege, and access control
- Experience with compliance and audit frameworks
- Problem-solving and troubleshooting skills
- Ability to operate in a 24/7 BAU environment
Nice-to-Have
- Experience with Kubernetes and cert-manager
- Exposure to Post-Quantum Cryptography (PQC)
- Experience in regulated industries (e.g., insurance, financial services)
Key Responsibilities
Cryptography Services & Operations
- Provide operational support for: o HashiCorp Vault–based secrets and key management o HSM-integrated root of trust operations o TLS/SSL certificate lifecycle using platforms such as Sectigo o Cryptographic monitoring, reporting, and governance o PQC readiness, risk management, and enablement
HashiCorp Vault & Secrets Management
- Administer and support Vault environments across production and non-production
- Manage: Secrets, keys, tokens, leases, and service accounts lifecycle o Authentication mechanisms and RBAC enforcement o Access Control Lists (ACLs) aligned with least privilege principles
- Perform: o Tenant onboarding/offboarding o Vault troubleshooting and performance tuning Aviva: Internal
- Support integrations with AWS KMS and external secret
Platform Operations & Maintenance
- Conduct proactive monitoring and health checks
- Manage Vault upgrades, testing, and currency roadmap
- Support configuration changes and change management processes
- Coordinate off-hours support and cloud transformation
HSM & Root of Trust Operations
- Support Vault-HSM integration (Thales LUNA HSM)
- Manage: o Auto-unseal functionality o Key rotation and secure handling practices • Coordinate firmware upgrades and DR processes
Certificate & PKI Lifecycle Management
- Perform end-to-end certificate lifecycle operations: o Creation, renewal, revocation, replacement o Installation validation and incident troubleshooting
- Ensure SLA adherence (24-hour turnaround)
- Maintain certificate inventory and ownership records
- Support PKI documentation, audits, and compliance
Certificate Automation & Governance Aviva: Internal
- Design and operate certificate lifecycle automation
- Implement automation using: o ACME protocols o Vault PKI engine o Kubernetes cert-manager and cloud-native tools
- Maintain:
o Certificate inventory (including automation status) o Monitoring systems for renewal failures and expiry risks
- Enforce: o Certificate standards (CAs, algorithms, key sizes) o Security best practices (least privilege, segregation of duties)
Cryptographic Inventory & Risk Management
- Maintain a comprehensive cryptographic inventory: o Keys, secrets, certificates, and algorithms
- Identify: o Deprecated or weak cryptographic implementations
- Support audit, compliance, and risk assessments
- Conduct PQC readiness assessments
- Support: o Cryptographic transition strategies o Risk identification and mitigation
- Enable future-proof cryptographic capabilities
Monitoring, Reporting & Governance
- Deliver KPIs and service metrics across: o Vault operations o PKI and certificate automation o Cryptographic risk and PQC
- Use tools such as Dynatrace, SiteScope, Rapid7, Power BI, and Excel for reporting
Security, Compliance & Resilience
- Ensure compliance with security and regulatory requirements
- Support: o Backup and disaster recovery processes o Security investigations and audits
- Maintain high availability and resilience of cryptographic services
Knowledge Transfer & Enablement
- Develop and maintain documentation and runbooks
- Enable knowledge sharing across teams
- Drive continuous improvement and operational maturity
Summary
- This role is critical in ensuring secure, automated, and compliant cryptographic operations, with a focus on operational excellence, risk reduction, and future cryptographic readiness.
Duration: Until 30 Sep 2027 (possibility of extension)
Location: Markham - Hybrid (3 days a week)
Role Overview The Cryptography Analyst is responsible for delivering business-as-usual (BAU) cryptographic operations across key and secrets management, TLS/SSL certificate lifecycle, PKI services, and post-quantum cryptography (PQC) readiness. This role ensures secure, compliant, and resilient cryptographic services supporting enterprise platforms and applications.
Top Required Skills:
- Ticket management skills
- Cryptography and Hashi Vault experience
- Information security incident handling
Required Skills & Experience Technical Skills
- HashiCorp Vault (administration and operations)
- Hardware Security Modules (Thales LUNA preferred)
- TLS/SSL certificate management and PKI Aviva: Internal
- Secrets management platforms (AWS Secrets Manager, etc.)
- Cloud platforms (AWS preferred)
- Automation (APIs, scripting, CI/CD integration)
- Monitoring tools (Dynatrace, Rapid7, Power BI) Core Competencies
- Strong understanding of cryptographic principles and lifecycle
- Knowledge of RBAC, least privilege, and access control
- Experience with compliance and audit frameworks
- Problem-solving and troubleshooting skills
- Ability to operate in a 24/7 BAU environment
Nice-to-Have
- Experience with Kubernetes and cert-manager
- Exposure to Post-Quantum Cryptography (PQC)
- Experience in regulated industries (e.g., insurance, financial services)
Key Responsibilities
Cryptography Services & Operations
- Provide operational support for: o HashiCorp Vault–based secrets and key management o HSM-integrated root of trust operations o TLS/SSL certificate lifecycle using platforms such as Sectigo o Cryptographic monitoring, reporting, and governance o PQC readiness, risk management, and enablement
HashiCorp Vault & Secrets Management
- Administer and support Vault environments across production and non-production
- Manage: Secrets, keys, tokens, leases, and service accounts lifecycle o Authentication mechanisms and RBAC enforcement o Access Control Lists (ACLs) aligned with least privilege principles
- Perform: o Tenant onboarding/offboarding o Vault troubleshooting and performance tuning Aviva: Internal
- Support integrations with AWS KMS and external secret
Platform Operations & Maintenance
- Conduct proactive monitoring and health checks
- Manage Vault upgrades, testing, and currency roadmap
- Support configuration changes and change management processes
- Coordinate off-hours support and cloud transformation
HSM & Root of Trust Operations
- Support Vault-HSM integration (Thales LUNA HSM)
- Manage: o Auto-unseal functionality o Key rotation and secure handling practices • Coordinate firmware upgrades and DR processes
Certificate & PKI Lifecycle Management
- Perform end-to-end certificate lifecycle operations: o Creation, renewal, revocation, replacement o Installation validation and incident troubleshooting
- Ensure SLA adherence (24-hour turnaround)
- Maintain certificate inventory and ownership records
- Support PKI documentation, audits, and compliance
Certificate Automation & Governance Aviva: Internal
- Design and operate certificate lifecycle automation
- Implement automation using: o ACME protocols o Vault PKI engine o Kubernetes cert-manager and cloud-native tools
- Maintain: o Certificate inventory (including automation status) o Monitoring systems for renewal failures and expiry risks
- Enforce: o Certificate standards (CAs, algorithms, key sizes) o Security best practices (least privilege, segregation of duties)
Post-Quantum Cryptography (PQC)
- Conduct PQC readiness assessments
- Support: o Cryptographic transition strategies o Risk identification and mitigation
- Enable future-proof cryptographic capabilities
Monitoring, Reporting & Governance
- Deliver KPIs and service metrics across: o Vault operations o PKI and certificate automation o Cryptographic risk and PQC
- Use tools such as Dynatrace, SiteScope, Rapid7, Power BI, and Excel for reporting
Security, Compliance & Resilience
- Ensure compliance with security and regulatory requirements
- Support: o Backup and disaster recovery processes o Security investigations and audits
- Maintain high availability and resilience of cryptographic services
Knowledge Transfer & Enablement
- Develop and maintain documentation and runbooks
- Enable knowledge sharing across teams
- Drive continuous improvement and operational maturity
Summary
- This role is critical in ensuring secure, automated, and compliant cryptographic operations, with a focus on operational excellence, risk reduction, and future cryptographic readiness.
Disclaimer:
AI may be used in evaluating candidates.
This posting is for an existing vacancy.
📌 Cybersecurity Analyst to support cryptographic operations using HashiCorp Vault, PKI, and TLS/SSL certificate management - 2927 (Toronto)
🏢 S.i. Systems
📍 Toronto