Employment OS for your Business

Senior Security Engineer / Architect – Key Management Services (KMS)

Canberra, Australian Capital Territory 2600, Australia • Full-time
AI Job Summary
  • 8+ years' experience in cyber security engineering, security architecture, cryptographic engineering or related.
  • Design and implement enterprise KMS solutions incl. AWS KMS, Azure Key Vault, Google Cloud KMS or HashiCorp Vault.
  • Ability to obtain and maintain TSPV; NV2 holders considered with uplift to TSPV mandatory.

Role Type

On-site • Contract • Full-time • Experienced

Description

About the Role

We are seeking an experienced Senior Security Engineer / Security Architect to lead the design and implementation of an enterprise-grade Key Management Services (KMS) solution.

This is a specialist role focused exclusively on the architecture, engineering and delivery of cryptographic key management capabilities. The successful candidate will work closely with technical teams, security stakeholders and client representatives to design secure, scalable and compliant cryptographic services that protect critical systems and sensitive information.

This role is ideal for someone with deep expertise in PKI, Hardware Security Modules (HSMs), cryptographic services and secure system architecture, particularly within Government, Defence or other highly regulated environments.

Key Details

  • Canberra based (on-site)
  • 12-month contract
  • ASAP Start
  • TSPV required; NV2 holders will be considered, with uplift to TSPV mandatory.

Key Responsibilities:

  • Lead the architecture, design and implementation of enterprise Key Management Services (KMS).
  • Design cryptographic solutions that align with industry best practice and client security requirements.
  • Develop secure key lifecycle management processes including key generation, storage, rotation, distribution, escrow, archival and destruction.
  • Design and integrate Hardware Security Module (HSM) backed cryptographic services.
  • Architect and implement Public Key Infrastructure (PKI) solutions, including Certificate Authorities (CAs), certificate lifecycle management and trust models.
  • Develop secure integration patterns between KMS platforms and enterprise applications, databases, cloud services and infrastructure.
  • Produce high-quality architecture documentation including solution designs, security patterns, interface specifications and implementation guides.
  • Conduct security design reviews and provide technical assurance across cryptographic implementations.
  • Work closely with engineering teams during implementation to ensure architectural intent is maintained.
  • Identify technical risks and provide mitigation strategies throughout project delivery.

Required Experience

  • 8+ years’ experience in cyber security engineering, security architecture, cryptographic engineering or a related discipline.
  • Demonstrated experience designing and implementing enterprise Key Management Services (KMS) solutions.
    • AWS KMS
    • Azure Key Vault
    • Google Cloud KMS
    • HashiCorp Vault (or equivalent secrets management/KMS platforms)
  • Strong understanding of cryptographic key lifecycle management, including key generation, storage, distribution, rotation, archival and destruction.
  • Experience designing and integrating cryptographic services into enterprise applications, infrastructure and cloud environments.
  • Strong understanding of symmetric and asymmetric cryptography, encryption, digital signatures, authentication and trust services.
  • Experience developing security architecture documentation, solution designs and implementation artefacts.
  • Experience working within regulated or high-assurance environments (e.g. Defence, Government, Critical Infrastructure or Financial Services).
  • Hands-on experience designing and implementing Hardware Security Module (HSM) backed cryptographic services.
    • Thales
    • Entrust
    • Utimaco
    • Luna HSM
    • Equivalent enterprise HSM platforms

Desirable Experience

  • Experience designing and implementing Public Key Infrastructure (PKI) solutions.
    • Microsoft Active Directory Certificate Services (AD CS)
    • Certificate Authority (CA) design and management
    • Certificate lifecycle management
    • Digital certificate provisioning and trust models
  • Experience with one or more of the following technologies and practices:
    • Secrets management platforms
    • Certificate lifecycle management platforms
    • Code signing infrastructure
    • TLS and Mutual TLS (mTLS) implementations
    • Cryptographic API integration
    • Secure DevSecOps pipelines
    • Zero Trust architecture
    • Container security and Kubernetes secrets management
    • Identity and Access Management (IAM) integration
    • High Availability (HA) and Disaster Recovery (DR) design for cryptographic services

Company Overview

https://opescyber.com.au/