Senior Security Engineer – Cryptographic Strategy & Post-Quantum Readiness (PQR)
What security roles in crypto pay
64 salaries · our own dataMost security roles in crypto pay between $145k and $268k, with a median of $202k.
As a Senior Security Engineer at BLS360, you will transform enterprise cryptographic strategy into scalable, automated, and operational security services. This hands-on role focuses on enterprise cryptographic services, certificate lifecycle automation, cryptographic visibility, and Post-Quantum Readiness (PQR). You will work closely with platform, application, infrastructure, cloud, DevSecOps, and security teams to enable self-service certificate management through DigiCert, automate certificate lifecycle processes, establish a Cryptographic Bill of Materials (CBOM), and build the foundations for future Post-Quantum Cryptography (PQC) migration.
What you'll do
- Implement enterprise cryptographic strategy through practical security platforms, services, automation, engineering standards, and operational controls
- Design, implement, and expand DigiCert self-service capabilities for application and infrastructure teams
- Build secure workflows for certificate request, approval, issuance, renewal, revocation, and reporting
- Automate enterprise certificate lifecycle management across applications, infrastructure, cloud, and other technology platforms
- Integrate certificate automation with CI/CD pipelines, cloud platforms, Infrastructure-as-Code, secrets management, load balancers, APIs, and application platforms
- Establish and maintain a Cryptographic Bill of Materials (CBOM) covering cryptographic assets, certificates, algorithms, keys, protocols, libraries, dependencies, ownership, business criticality, and lifecycle status
- Support cryptographic discovery and inventory across applications, endpoints, networks, cloud services, PKI environments, and third-party technologies
- Identify and remediate certificate expiration risks, weak or legacy cryptographic configurations, hard-coded cryptographic dependencies, and crypto-agility gaps
- Develop reusable implementation patterns, automation scripts, runbooks, dashboards, technical documentation, and operational controls
- Support Post-Quantum Readiness (PQR) and Post-Quantum Cryptography (PQC) initiatives, including readiness assessments, migration planning, hybrid cryptography pilots, and technology evaluations
- Track implementation progress, technical dependencies, risks, and remediation activities and escalate blockers when necessary
- Provide hands-on technical guidance to application, infrastructure, cloud, and security teams adopting enterprise cryptographic services
- Collaborate with senior engineers and architects to evaluate emerging cryptographic technologies, standards, and implementation approaches
What you bring
- 8+ years of hands-on experience in security engineering, platform engineering, DevSecOps, cloud engineering, infrastructure engineering, or application engineering
- Strong practical experience with PKI, X.509 certificates, TLS/SSL, Certificate Authorities (CA), certificate lifecycle management, and key management
- Experience administering, integrating, or automating enterprise certificate-management platforms
- Strong automation and scripting experience using Python, PowerShell, Bash, Java, Go, or similar languages
- Experience with REST APIs, CI/CD pipelines, Git, Terraform, Ansible, containers, and/or Kubernetes
- Hands-on experience with AWS, Azure, and/or Google Cloud, including cloud certificate, key-management, secrets-management, identity, and network-security services
- Solid understanding of applied cryptography, including encryption, hashing, digital signatures, key exchange, PKI, cryptographic protocols, and cryptographic libraries
- Ability to troubleshoot complex certificate, TLS, trust-store, key, and cryptographic configuration issues in production environments
- Strong communication, documentation, troubleshooting, and collaboration skills
- Ability to work effectively with distributed global teams in a remote environment
Nice to have
- DigiCert experience
- Experience implementing certificate self-service portals
- Experience with certificate automation and ACME, SCEP, or EST workflows
- Experience building certificate lifecycle integrations and enterprise PKI services
- Experience creating or maintaining a CBOM, cryptographic inventory, SBOM, CMDB, or asset-discovery program
- Familiarity with Post-Quantum Cryptography (PQC), Post-Quantum Readiness (PQR), crypto-agility, and emerging standards such as ML-KEM and ML-DSA
- Experience with HSMs, cloud KMS, secrets-management platforms, code signing, mTLS, API security, or enterprise PKI modernization
- Experience working in a large, regulated, or highly distributed enterprise environment
About BLS360
BLS360 is a cybersecurity and digital transformation company focused on Identity and Access Management (IAM), Identity Governance and Administration (IGA), privileged access, cloud security, and enterprise security transformation.
