What are the responsibilities and job description for the Data Security Engineer (HSM PKI ) position at K20s - Kinetic Technologies Private Limited?
Data Security Engineer
Location: Qatar Onside
Experience Required: 5-7 Years
Duration 1yr (Renewable)
Banking Experience Mandatory
Availability: Immediate Joiner Preferred
Position Overview
We are looking for a highly skilled Data Security Engineer with deep technical expertise in
Utimaco Hardware Security Modules (HSM) or similar kind other vendor, Key Management
Systems (KMS), Payment Security, and Public Key Infrastructure (PKI). The ideal candidate
will bring at least 5-7 years of hands-on experience in securing critical data systems, with a
specific focus on the banking and financial services sectors. This role requires someone with
a strong cryptographic background and have solid cyber security foundation and a proven
track record in deploying, managing, and optimizing security solutions for sensitive data.
Key Responsibilities
usage of cryptographic keys in line with banking compliance frameworks.
rotation, and destruction. Implement enterprise-grade encryption practices with
emphasis on security, performance, and compliance.
and enforce standards compliant with PCI DSS, EMV, and ISO 20022. Engage in securing
real-time payments, SWIFT transactions, and digital banking services.
registration authorities (RA). Administer certificate lifecycles, certificate revocation lists
(CRLs), and secure digital certificate distribution.
regulatory frameworks, including GDPR, FFIEC, and Basel III. Utilize encryption
algorithms such as AES, RSA, and ECC for optimal data protection.
mitigate vulnerabilities, ensuring that all cryptographic systems are resilient to attacks.
2, and eIDAS. Collaborate with internal audit teams to align practices with risk
management and data protection policies.
anomalies or breaches in data encryption systems.
environments. Ensure minimal latency and robust throughput in key management and
cryptographic processing.
Technical Requirements
injection, and partitioning for multiple security domains.
and ensuring keys are securely distributed and used across the enterprise.
channels, and using Hardware Security Modules to safeguard cryptographic keys used
in payment authorization and tokenization systems.
symmetric and asymmetric encryption methodologies.
validation and revocation.
Qualifications And Experience
environments such as banking, financial services, or payment processing.
Specialist) are highly preferred.
such as PCI DSS, PSD2, SWIFT CSP, and Basel III.
Personal Attributes
comprehensive data security strategies
Skills: pki infrastructures,compliance & risk management,utimaco hsm,certificate management,key management systems,security hardening,public key infrastructure,security,compliance,management,pki,hsm,encryption,data,kms,infrastructure,key management,hsm integration,public key infrastructure (pki),cryptography,payment security,data encryption,incident response,performance optimization,cryptographic algorithms,risk management,key management systems (kms)
Location: Qatar Onside
Experience Required: 5-7 Years
Duration 1yr (Renewable)
Banking Experience Mandatory
Availability: Immediate Joiner Preferred
Position Overview
We are looking for a highly skilled Data Security Engineer with deep technical expertise in
Utimaco Hardware Security Modules (HSM) or similar kind other vendor, Key Management
Systems (KMS), Payment Security, and Public Key Infrastructure (PKI). The ideal candidate
will bring at least 5-7 years of hands-on experience in securing critical data systems, with a
specific focus on the banking and financial services sectors. This role requires someone with
a strong cryptographic background and have solid cyber security foundation and a proven
track record in deploying, managing, and optimizing security solutions for sensitive data.
Key Responsibilities
- HSM Integration & Management: Design, deploy, configure, and maintain Utimaco HSMs
usage of cryptographic keys in line with banking compliance frameworks.
- Key Management Systems (KMS): Architect and operationalize Key Management
rotation, and destruction. Implement enterprise-grade encryption practices with
emphasis on security, performance, and compliance.
- Payment Security Implementation: Secure the end-to-end lifecycle of payment
and enforce standards compliant with PCI DSS, EMV, and ISO 20022. Engage in securing
real-time payments, SWIFT transactions, and digital banking services.
- PKI Deployment & Administration: Oversee Public Key Infrastructure (PKI), including
registration authorities (RA). Administer certificate lifecycles, certificate revocation lists
(CRLs), and secure digital certificate distribution.
- Banking Data Encryption: Implement encryption strategies for sensitive banking data
regulatory frameworks, including GDPR, FFIEC, and Basel III. Utilize encryption
algorithms such as AES, RSA, and ECC for optimal data protection.
- Security Hardening: Perform ongoing system hardening, security audits, and risk
mitigate vulnerabilities, ensuring that all cryptographic systems are resilient to attacks.
- Compliance & Risk Management: Ensure that all cryptographic operations adhere to
2, and eIDAS. Collaborate with internal audit teams to align practices with risk
management and data protection policies.
- Incident Response & Monitoring: Provide expert-level support during security incidents
anomalies or breaches in data encryption systems.
- Performance Optimization: Fine-tune the performance of cryptographic hardware and
environments. Ensure minimal latency and robust throughput in key management and
cryptographic processing.
Technical Requirements
- HSM Expertise: Proficiency with Utimaco HSM platforms, including CryptoServer Se,
injection, and partitioning for multiple security domains.
- KMS Proficiency: In-depth knowledge of enterprise KMS systems, such as Gemalto
and ensuring keys are securely distributed and used across the enterprise.
- Payment Security Protocols: Expertise in securing payment systems following PCI HSM,
channels, and using Hardware Security Modules to safeguard cryptographic keys used
in payment authorization and tokenization systems.
- Cryptographic Algorithms: Strong foundational knowledge of cryptographic algorithms,
symmetric and asymmetric encryption methodologies.
- PKI and Certificate Management: Extensive experience with PKI infrastructures,
validation and revocation.
Qualifications And Experience
- Education: Bachelor's or Master's degree in Computer Science, Information Security, or
- Experience: Minimum of 5-7 years of focused experience in HSM, KMS, PKI, and
environments such as banking, financial services, or payment processing.
- Industry Certifications: Certifications such as CISSP, CISM, CCSP, PCI DSS QSA, or
Specialist) are highly preferred.
- Banking Industry Experience: Strong background in securing banking and financial
such as PCI DSS, PSD2, SWIFT CSP, and Basel III.
Personal Attributes
- Availability: Must be available for immediate onboarding or with minimal notice period.
- Analytical Mindset: Capable of evaluating complex cryptographic architectures and
- Team Collaboration: Proven ability to work in cross-functional teams, including IT
comprehensive data security strategies
Skills: pki infrastructures,compliance & risk management,utimaco hsm,certificate management,key management systems,security hardening,public key infrastructure,security,compliance,management,pki,hsm,encryption,data,kms,infrastructure,key management,hsm integration,public key infrastructure (pki),cryptography,payment security,data encryption,incident response,performance optimization,cryptographic algorithms,risk management,key management systems (kms)