Key Management & Cryptographic Security Engineer (Hyderabad)

Key Management & Cryptographic Security Engineer (Hyderabad)

06 Sep
|
Cubic Transportation Systems
|
Hyderabad

06 Sep

Cubic Transportation Systems

Hyderabad

Role Summary
We are seeking a Key Management & Cryptographic Security Engineer to manage and support our global Key Management and Encryption Security Services environment.
The role is responsible for the secure lifecycle management of cryptographic keys, certificates, keysets, HSMs, SAMs, and secure provisioning environments across multiple locations. The engineer will support key ceremonies, regional Key Injection Facilities, audits, system changes, and production incidents.
The ideal candidate will combine practical cryptography and HSM experience with strong configuration management, documentation, troubleshooting, and stakeholder coordination skills. Experience in fare collection, payments, smartcards, or secure embedded systems is preferred.

Key Responsibilities
Manage the lifecycle of cryptographic keys, certificates, and keysets, including generation, distribution, activation, rotation, renewal, revocation, backup, recovery, and secure destruction.
Manage and support Hardware Security Modules (HSMs) and associated cryptographic services.
Maintain accurate key inventories and configurations across global locations, systems, devices, and environments.
Participate in controlled key ceremonies, security audits, and secure provisioning activities.
Support regional Key Injection Facilities and associated HSM, SAM, and device-provisioning processes.
Assess the end-to-end impact of key, certificate, device, and cryptographic configuration changes.
Create and maintain technical designs, operating procedures, configuration records, runbooks, and audit evidence.
Work with development and testing teams to investigate and resolve encryption, certificate, secure-messaging, key-injection, and HSM-related issues.
Define cryptographic and security requirements for fare-collection solutions.
Support production incidents, root-cause analysis, change management, and service improvements.
Ensure cryptographic material and sensitive information are handled in accordance with approved security policies and procedures.

Required Skills and Experience
Practical experience with one or more of the following:
Cryptographic key management
Hardware Security Module development, administration,



or management
Enterprise Key Management Systems
PKI and certificate management
Secure device provisioning or key injection
Good understanding of symmetric cryptographic keys and algorithms, including:
AES
DES and Triple DES
DUKPT
Key derivation and key diversification
Message Authentication Codes
Hashing and encryption modes
Key wrapping and key exchange
Good understanding of asymmetric cryptography, including:
PKI
Public and private key pairs
Digital certificates and certificate chains
Digital signatures
Certificate Authorities and trust stores
Certificate renewal and revocation
Understanding of secure communication protocols, including TLS and mutual TLS.
Knowledge of cryptographic key-management lifecycles and applicable NIST guidance.
Experience managing security-sensitive configurations across multiple systems or environments.
Strong troubleshooting and end-to-end systems-analysis skills.
Excellent attention to detail, documentation, and communication skills.
Ability to define and follow controlled security procedures precisely.
Experience working with geographically distributed teams and business stakeholders.
Ability to participate in global support activities, planned key ceremonies, and critical incident escalation when required.

Preferred Skills
Experience in HSM product development, integration, administration, or operational management.
Experience with HSM platforms used in payment, banking, transit, or enterprise cryptographic environments.
Knowledge of HSM functions such as:
Key generation and import
Key blocks and key wrapping
Key translation
PIN and payment cryptography
Signing and verification
Secure backup and recovery
HSM clustering, resilience, and monitoring
Experience with HSMs, SAMs, Key Injection Facilities,



or secure provisioning environments.
Knowledge of payment key-management concepts such as DUKPT, Base Derivation Keys, Initial Key Serial Numbers, Key Encryption Keys, and Terminal Master Keys.
Knowledge of secure embedded systems and mobile-platform security.
Experience with contactless smartcards, particularly NXP MIFARE DESFire, or similar technologies.
Experience in fare collection, transportation, payments, banking, financial services, or another security-sensitive industry.
Knowledge of PCI PTS POI, PCI P2PE, PCI Mobile Payments on COTS, ISO/IEC 27000, or similar standards.
Experience with UMB components and S-KMS.
Familiarity with development, integration, laboratory, pre-production, and production environments.
Scripting or automation experience for validation, monitoring, reporting, or controlled operational activities.

Key Personal Attributes
Highly detail-oriented, methodical, and security-conscious.
Understands that a single incorrect key value, digit, version, or configuration can cause significant security or service impact.
Robust configuration and change-management discipline.
Able to understand the wider system impact of an individual key, certificate, HSM, or device change.
Excellent written and verbal communication skills.
Comfortable coordinating with engineering teams, suppliers, service personnel, auditors, and management.
Able to create clear procedures that can be safely followed by other engineers.
Calm and systematic when resolving complex or high-impact incidents.
Willing to stop and escalate an activity when security, authorization, or procedural requirements are not met.

Qualifications
Degree in cybersecurity, computer science, electronics, engineering, or a related discipline, or equivalent professional experience.
Relevant experience in cryptographic security, HSM development or administration, key management, PKI, payment security, embedded security, or secure provisioning.
Security or technology certifications such as CISSP, CCSP, Security+, ISO 27001, PCI, or vendor-specific HSM/KMS certifications are beneficial but not mandatory.

📌 Key Management & Cryptographic Security Engineer (Hyderabad)
🏢 Cubic Transportation Systems
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: key management & cryptographic security engineer (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: key management & cryptographic security engineer (hyderabad) / hyderabad