- Company Name
- HONEYWELL
- Job Title
- Senior Advanced Cybersecurity Engineer – PKI & Key Management
- Job Description
-
Job title: Senior Advanced Cybersecurity Engineer – PKI & Key Management
Role Summary: Lead architect and operational manager of Public Key Infrastructure (PKI) and Key Management Services (KMS) for aerospace product security. Design, deploy, and govern cryptographic systems across product development, DevSecOps pipelines, and internal tooling to ensure secure software releases, identity validation, and compliance with aerospace standards.
Expactations:
- Own end‑to‑end PKI/KMS architecture, including root/ICA hierarchy, certificate lifecycle, revocation, and key storage.
- Integrate cryptographic functions into CI/CD, code signing, secure boot, and secure configuration.
- Ensure adherence to NIST, FIPS 140‑2, DO‑326A, DO‑178C security addenda, and other regulatory frameworks.
- Mentor junior engineers and collaborate with cross‑functional teams (risk, compliance, DevSecOps).
Key Responsibilities:
- Design, implement, and maintain PKI/KMS solutions for internal tooling, product development, and engineering ops.
- Define certificate management policies, root CA/ICA hierarchies, OCSP, key rotation, and revocation mechanisms.
- Embed cryptographic operations into DevSecOps pipelines—code signing, secure config, and secure boot processes.
- Provide support for encryption, authentication, and identity validation across CI/CD and engineering workflows.
- Lead investigations and audits of certificate/key compromise, misuse, or unauthorized access.
- Partner with risk, compliance, and cybersecurity teams to meet aerospace standards and regulatory requirements.
- Evaluate emerging crypto technologies; recommend modernization for legacy tooling.
- Mentoring and knowledge transfer to junior engineers and stakeholders.
- Manage HSM deployment and KMS across cloud, hybrid, and on‑prem environments.
- Contribute to PKI governance models and enterprise cryptographic policies.
Required Skills:
- Advanced knowledge of X.509, certificate authorities, OCSP, key rotation, HSM integration, and secure key storage.
- Hands‑on experience with smartcards, TPMs, encrypted containers, automation platforms, and secure engineering enablement tooling (e.g., Black Duck Hub, secure Jira workflows, Ansible).
- Proficiency in Java/Groovy, Linux OS, and scripting for DevSecOps automation.
- Deep understanding of secure software lifecycle practices and DevSecOps environments.
- Familiarity with regulatory and cryptographic compliance standards (FIPS 140‑2, NIST 800 series, DO‑178C, DO‑326A).
- Strong interpersonal, facilitation, and conflict‑resolution skills; ability to negotiate priorities across diverse stakeholder groups.
- Experience in designing secure architectures in regulated domains such as aerospace, defense, and critical infrastructure.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Engineering, or related field.
- 8+ years in cybersecurity with direct PKI/KMS domain expertise; 3+ years with X.509, certificate authorities, OCSP, HSM, and secure key storage.
- Certifications: Certified Encryption Specialist (ECES), GIAC Cryptography & Crypto Foundations (GCF), or equivalent.
- Experience with Agile software development practices.