HSM & PKI Security Engineer
About this role
Location: Dammam, Saudi Arabia
Employment Type: Full-Time | Onsite
Project Duration: Long-term project assignment
About the Role
We are seeking an experienced HSM & PKI Security Engineer to operate, secure, and support enterprise Hardware Security Module and Public Key Infrastructure environments.
The engineer will be responsible for HSM administration, cryptographic key protection, high availability, backup and recovery, PKI integrations, certificate lifecycle activities, and coordination with the HSM OEM.
Key Responsibilities
- Administer and operate Thales Luna HSM infrastructure.
- Manage HSM partitions, security domains, roles, access controls, and high-availability configurations.
- Support HSM backup, recovery, cloning, and disaster recovery procedures.
- Manage PED/MFA and secure administrative access to HSM infrastructure.
- Support integration of HSM with enterprise applications, databases, servers, and security platforms.
- Protect and manage cryptographic keys in accordance with security policies.
- Support Microsoft Certificate Authority and AD CS environments.
- Support public certificate lifecycle management, including issuance, renewal, installation, and revocation.
- Coordinate with DigiCert or other public Certificate Authority providers.
- Troubleshoot certificate, PKI, TLS/SSL, and HSM-related incidents.
- Perform health checks, maintenance, testing, and technical validation.
- Coordinate technical activities with OEM/vendor engineers.
- Maintain HSM/PKI documentation, configuration records, procedures, and recovery runbooks.
- Support audit, compliance, and security assessment requirements.
Required Qualifications & Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or related discipline.
- 5+ years of experience in HSM, PKI, cryptography, certificate management, or enterprise security.
- Strong knowledge of PKI, X.509 certificates, TLS/SSL, RSA, ECC, AES, and cryptographic key management.
- Hands-on experience with enterprise HSM technologies.
- Experience with Microsoft AD CS / Certificate Services is highly desirable.
- Experience supporting enterprise or government cybersecurity environments is preferred.
- Must be available full-time onsite in Dammam.
Required Certification
- CompTIA Security+ or equivalent recognized security certification.
Preferred Certifications & Training
- Thales Luna HSM official training/certification.
- Microsoft PKI / AD CS certification or advanced PKI training.
- Vendor-specific HSM administration certification.
- Relevant cryptography or PKI professional certification.
Core Competencies
HSM | PKI | Cryptography | AD CS | Certificate Management | TLS/SSL | Key Protection | High Availability | Backup & Recovery | Troubleshooting
Candidates should clearly indicate their HSM, PKI, certificate-management platforms, and vendor training/certifications on their CV.
Frequently Asked Questions
Is the salary disclosed for the HSM & PKI Security Engineer position at CCDS?
Where is the HSM & PKI Security Engineer position at CCDS located?
Is the HSM & PKI Security Engineer role at CCDS full-time or part-time?
How do I apply for the HSM & PKI Security Engineer position at CCDS?
When was the HSM & PKI Security Engineer job at CCDS posted?
You'll be redirected to CCDS's official application page on workable.