Senior Security Engineer – Cryptographic Strategy & Post-Quantum Readiness (PQR)
Company
BLS360 Location
Remote – India Experience:
8+ Years Employment Type:
Full-Time
About BLS360 BLS360
is a cybersecurity and digital transformation company focused on Identity & Access Management (IAM), Identity Governance & Administration (IGA), privileged access, cloud security, and enterprise security transformation. We are looking for a
Senior Security Engineer – Cryptographic Strategy & Post-Quantum Readiness (PQR)
to join our team and help transform enterprise cryptographic strategy into scalable, automated, and operational security services.
About the Role This is a hands-on engineering role focused on enterprise cryptographic services, certificate lifecycle automation, cryptographic visibility, and
Post-Quantum Readiness (PQR) . The engineer will work closely with platform, application, infrastructure, cloud, DevSecOps, and security teams to enable self-service certificate management through DigiCert , automate certificate lifecycle processes, establish a
Cryptographic Bill of Materials (CBOM) , and build the foundations required for future
Post-Quantum Cryptography (PQC)
migration. The ideal candidate combines strong security engineering fundamentals with practical experience in
PKI, certificates, TLS/SSL, automation, cloud, APIs, CI/CD, and cryptographic technologies .
Key Responsibilities · Implement enterprise cryptographic strategy through practical security platforms, services, automation, engineering standards, and operational controls. · Design, implement, and expand
DigiCert self-service capabilities for application and infrastructure teams. · Build secure workflows for certificate request, approval, issuance, renewal, revocation, and reporting . · Automate enterprise certificate lifecycle management across applications, infrastructure, cloud, and other technology platforms. · Integrate certificate automation with
CI/CD pipelines, cloud platforms, Infrastructure-as-Code, secrets management, load balancers, APIs, and application platforms . · Establish and maintain a
Cryptographic Bill of Materials (CBOM)
covering cryptographic assets, certificates, algorithms, keys, protocols, libraries, dependencies, ownership, business criticality, and lifecycle status. · Support cryptographic discovery and inventory across applications, endpoints, networks, cloud services,
PKI environments, and third-party technologies . · Identify and remediate certificate expiration risks, weak or legacy cryptographic configurations, hard-coded cryptographic dependencies, and crypto-agility gaps. · Develop reusable implementation patterns, automation scripts, runbooks, dashboards, technical documentation, and operational controls. · Support
Post-Quantum Readiness (PQR)
and
Post-Quantum Cryptography (PQC)
initiatives, including readiness assessments, migration planning, hybrid cryptography pilots, and technology evaluations. · Track implementation progress, technical dependencies, risks, and remediation activities and escalate blockers when necessary. · Provide hands-on technical guidance to application, infrastructure, cloud, and security teams adopting enterprise cryptographic services. · Collaborate with senior engineers and architects to evaluate emerging cryptographic technologies, standards, and implementation approaches.
Required Qualifications · 8+ years of hands-on experience in security engineering, platform engineering, DevSecOps, cloud engineering, infrastructure engineering, or application engineering. · Strong practical experience with
PKI, X.509 certificates, TLS/SSL, Certificate Authorities (CA), certificate lifecycle management, and key management . · Experience administering, integrating, or automating enterprise certificate-management platforms. · DigiCert experience strongly preferred. · Solid automation and scripting experience using
Python, PowerShell, Bash, Java, Go, or similar languages . · Experience with
REST APIs, CI/CD pipelines, Git, Terraform, Ansible, containers, and/or Kubernetes . · Hands-on experience with
AWS, Azure, and/or Google Cloud , including cloud certificate, key-management, secrets-management, identity, and network-security services. · Solid understanding of applied cryptography, including:
o Encryption o Hashing o Digital signatures o Key exchange o PKI o Cryptographic protocols o Cryptographic libraries · Ability to troubleshoot complex certificate, TLS, trust-store, key, and cryptographic configuration issues in production environments. · Strong communication, documentation, troubleshooting, and collaboration skills. · Ability to work effectively with distributed global teams in a remote environment.
Preferred Qualifications · Experience implementing certificate self-service portals . · Experience with certificate automation and
ACME, SCEP, or EST workflows. · Experience building certificate lifecycle integrations and enterprise PKI services. · Experience creating or maintaining a
CBOM, cryptographic inventory, SBOM, CMDB, or asset-discovery program . · Familiarity with
Post-Quantum Cryptography (PQC), Post-Quantum Readiness (PQR), crypto-agility , and emerging standards such as
ML-KEM and ML-DSA . · Experience with
HSMs, cloud KMS, secrets-management platforms, code signing, mTLS, API security, or enterprise PKI modernization . · Experience working in a large, regulated, or highly distributed enterprise environment .
What You Will Work With Cryptography & PKI: PKI
- X.509
- TLS/SSL
- Certificate Authorities
- Certificate Lifecycle Management
- DigiCert
- HSM
- KMS
- mTLS
- Code Signing Automation & DevSecOps: Python
- PowerShell
- Bash
- Java
- Go
- REST APIs
- CI/CD
- Git
- Terraform
- Ansible
- Kubernetes
- Infrastructure-as-Code Cloud & Security: AWS
- Azure
- Google Cloud
- Secrets Management
- Identity
- Network Security Post-Quantum Readiness: PQC
- PQR
- Crypto-Agility
- CBOM
- ML-KEM
- ML-DSA
Why Join BLS360? At BLS360, you will have the opportunity to work on enterprise-scale cybersecurity and identity transformation initiatives while developing expertise across emerging security technologies. This role provides an opportunity to contribute to the evolution of enterprise cryptographic security—from certificate automation and PKI modernization to cryptographic visibility and Post-Quantum Readiness . If you are a hands-on security engineer who enjoys solving complex security challenges, building automation, and working across cloud, infrastructure, application, and security teams, we would like to hear from you.
How to Apply Interested candidates can apply through LinkedIn or share their updated resume with BLS360. BLS360 – Cybersecurity & Digital Transformation
📌 Senior Security Engineer – Cryptographic Strategy & Post-Quantum Readiness (PQR) (Mumbai)
🏢 BLS360
📍 Mumbai