Cryptography Engineer
The job description
Tech stack. AES, RSA, ECC, and post-quantum algorithms, TLS 1.3, PKI and certificate management, HSMs and KMS, OpenSSL and libsodium, Python or Rust, crypto agility planning
About the role
You will own the cryptographic foundations for a technology company whose products depend on encryption implemented correctly: key management, TLS deployment, and data protection operating reliably at scale. The team reviews every cryptographic design in the company and operates the infrastructure that keeps keys safe across environments. You will also lead the long migration toward post-quantum algorithms before it becomes an emergency. This role matters because a single cryptographic misuse can silently undermine every other security control in the stack, and your review is the checkpoint that catches it before customers are ever affected. Precision, patience, and mathematical rigor define your daily work on the team.
What you will achieve
- Design and operate the centralized key management service that issues, rotates, and revokes keys for all production systems with fully auditable controls.
- Eliminate deprecated TLS versions and weak cipher suites across 100 percent of public-facing endpoints, verified by continuous scanning.
- Review cryptographic designs for new products, catching dangerous misuse patterns like ECB mode, static IVs, or homegrown algorithms before they ship.
- Build automated scanning that flags hardcoded secrets, weak parameters, and outdated libraries in code and configuration.
- Ship the post-quantum migration plan, completing a full inventory of algorithm dependencies and sequencing the transition by risk.
What you will bring
Must-haves
- 2 to 5 years working hands-on with applied cryptography in production systems, beyond academic study.
- Strong understanding of symmetric and asymmetric primitives, secure hashing, and key exchange protocols.
- Hands-on experience with PKI operations: certificate issuance, rotation, revocation, and CA hierarchy management.
- Familiarity with HSMs, cloud KMS services, and envelope encryption patterns for data protection.
- Ability to read protocol specifications carefully and spot implementation pitfalls that break security guarantees.
- Software engineering skills in Python, Go, or Rust sufficient to build and maintain reliable crypto tooling.
- Paranoia in the right measure: you assume implementations are guilty until proven correct.
Nice-to-haves
- Knowledge of post-quantum algorithms such as ML-KEM and ML-DSA and their migration challenges.
- Experience with formal verification methods or professional cryptographic code auditing.
- Contributions to open-source cryptographic libraries.
- Familiarity with FIPS 140 validation processes and requirements.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta