Cybersecurity Analyst / Cryptography Analyst
Looking for an opportunity to work on meaningful projects and cutting-edge technologies? Join a high-performing team in the insurance sector for our client and contribute to initiatives that strengthen security, support digital transformation, and drive operational excellence in a fast-paced and collaborative environment.
What is in it for you:
• Salaried: $45-55 per hour.
• Incorporated Business Rate: $52-62 per hour.
• 12-month contract with the potential for permanent employment.
• Full-time position: 37.50 hours per week.
• Occasional overtime may be required to support project requirements.
• Hybrid model: 3 days per week on-site, subject to change.
Responsibilities:
Vault & Secrets Management
• Provide operational support for HashiCorp Vault-based secrets and key management.
• Administer and support HashiCorp Vault environments across production and non-production environments.
• Manage the lifecycle of secrets, keys, tokens, leases, and service accounts.
• Maintain authentication mechanisms, role-based access control, and access control lists aligned with least privilege principles.
• Perform tenant onboarding and offboarding activities.
• Troubleshoot and optimize Vault performance.
• Support integrations with AWS KMS and external secret platforms.
• Manage Vault upgrades, testing, and currency roadmaps.
Cryptography & HSM Operations
• Support HSM-integrated root of trust operations.
• Support Vault-HSM integration, including Thales LUNA HSM environments.
• Manage auto-unseal functionality, key rotation activities, and secure key handling practices.
• Coordinate firmware upgrades and disaster recovery processes.
• Support post-quantum cryptography readiness, assessments, transition strategies, risk identification, and mitigation.
• Maintain inventories of cryptographic keys, secrets, certificates, and algorithms.
• Identify deprecated or weak cryptographic implementations.
Certificate & PKI Management
• Manage TLS/SSL certificate lifecycle activities, including creation, renewal, revocation, replacement, installation validation, and incident troubleshooting.
• Ensure certificate lifecycle service level agreement adherence.
• Maintain certificate inventory and ownership records.
• Support PKI documentation, compliance activities, audits, and governance requirements.
• Design, implement, and operate certificate lifecycle automation solutions.
• Implement automation using ACME protocols, Vault PKI engine, Kubernetes cert-manager, and cloud-native tools.
• Maintain certificate inventory, automation status records, and monitoring systems for renewal failures and expiry risks.
• Enforce certificate standards, security best practices, least privilege principles, and segregation of duties.
Monitoring, Compliance & Security
• Perform cryptographic monitoring, reporting, governance, and risk management activities.
• Conduct proactive monitoring and health checks.
• Deliver KPIs and service metrics related to Vault operations, PKI, certificate automation, cryptographic risks, and post-quantum cryptography readiness.
• Utilize monitoring and reporting tools, including Dynatrace, SiteScope, Rapid7, Power BI, and Microsoft Excel.
• Support audits, compliance reviews, and risk assessments.
• Ensure compliance with security and regulatory requirements.
• Support backup, disaster recovery, security investigations, and audit activities.
• Maintain the availability and resilience of cryptographic services.
• Participate in information security incident handling, incident response activities, and alert triage.
• Identify and address network security gaps.
Operational Support & Continuous Improvement
• Support configuration changes and change management processes.
• Coordinate off-hours support activities.
• Develop and maintain documentation and operational runbooks.
• Facilitate knowledge sharing across teams.
• Drive continuous improvement and operational maturity initiatives.
What you will need to succeed:
Required qualifications
Experience
• 1-3 years of experience.
• Experience administering and supporting HashiCorp Vault environments.
• Experience with compliance and audit frameworks.
• Experience operating in a 24/7 business-as-usual environment.
Technical and professional skills
• Ticket management skills.
• Cryptography knowledge and experience.
• HashiCorp Vault administration and operations.
• Information security incident handling.
• Hardware Security Modules knowledge and experience.
• TLS/SSL certificate management.
• Public Key Infrastructure (PKI) knowledge and experience.
• Secrets management platform experience, including HashiCorp Vault.
• Cloud platform experience.
• Automation experience, including APIs, scripting, and CI/CD integrations.
• Experience with monitoring and reporting tools.
• Strong understanding of cryptographic principles and lifecycle management.
• Knowledge of RBAC, least privilege principles, and access control.
• Problem-solving and troubleshooting skills.
Preferred qualifications
Experience
• Experience in regulated industries such as insurance or financial services.
Technical and professional skills
• Experience with Thales LUNA HSM.
• Experience with AWS cloud platforms.
• Experience with Kubernetes and cert-manager.
• Exposure to Post-Quantum Cryptography (PQC).
Soft skills
• Resourceful.
• Forward-thinking.
• Problem-solving.
• Ability to enable knowledge sharing across teams.
• Ability to drive continuous improvement and operational maturity initiatives.
Why Recruit Action?
Recruit Action (agency permit: AP-2504511) provides recruitment services through quality support and a personalized approach. As part of the screening process, some applications may be reviewed using artificial intelligence tools. Only candidates who meet the hiring criteria will be contacted.