Security Engineer (Crypto)

Talent Smart Limited
Penicuik
1 day ago
Create job alert

We are seeking a highly skilled HSM Engineer/Cryptography SME to join our Cyber Security function within a Tier 1 financial institution. This role is critical in ensuring the confidentiality, integrity, and availability of cryptographic services that underpin the bank's most sensitive systems, including payments, authentication, cloud workloads, and data‑at‑rest protection.

As the bank's internal expert on Hardware Security Modules (HSMs), you will design, implement, operate, and improve cryptographic platforms and services that support enterprise‑wide security controls. You will work closely with security architects, payments technology teams, cloud engineering, IAM, and application delivery teams to ensure secure key management practices and compliance with regulatory and audit requirements.

Key ResponsibilitiesHSM Engineering & Operations
  • Lead engineering, configuration, and life cycle management of enterprise HSM platforms (eg, Thales Luna, nCipher/nShield, PayShield, Utimaco, Entrust).

  • Manage secure key creation, rotation, distribution, backup, and archival procedures in line with industry best practice and regulatory expectations.

  • Oversee firmware upgrades, patching cycles, and platform resilience improvements.

  • Operate and troubleshoot cryptographic hardware and associated services across on‑prem and cloud environments.

  • Support the design and implementation of HSM integrations with payment systems, authentication services, PKI, and internal business applications.

Cryptography Subject Matter Expertise
  • Serve as the internal SME for cryptography, advising on algorithms, key lengths, FIPS certifications, and emerging standards (eg, PQC).

  • Provide expert guidance on crypto use cases across the bank: TLS, tokenisation, digital signatures, securing APIs, data at rest, and cloud KMS/HSM integrations.

  • Assess cryptographic risk and provide controls assurance to satisfy regulatory and audit expectations.

  • Translate complex security requirements into engineering solutions suitable for banking‑grade platforms.

Platform Design & Engineering
  • Contribute to the technical roadmap for HSM and cryptographic services, ensuring scalability, resilience, and alignment with cloud transformation initiatives.

  • Work with Architecture to define patterns, standards, and reusable components for secure key management.

  • Develop automation and tooling to streamline key management processes and reduce operational overhead.

Governance, Compliance & Audit
  • Ensure HSM processes comply with internal security policies, PCI DSS, FFIEC, SWIFT CSP, and other relevant banking regulatory frameworks.

  • Maintain full auditability of key events, system access, and life cycle changes.

  • Support internal and external audit engagements, providing evidence, walkthroughs, and control descriptions.

Stakeholder Collaboration
  • Partner with payments, digital channels, cloud engineering, platform teams, SOC, and IAM to embed secure cryptographic practices.

  • Support development teams with integrations, secure usage patterns, and troubleshooting guidance.

  • Provide technical mentorship to junior engineers and security analysts.

Required Skills & ExperienceTechnical Expertise
  • Strong hands‑on experience with enterprise HSMs such as Thales Luna (preferred), nCipher/nShield, Thales PayShield or other payment HSMs, Utimaco, Entrust (advantageous).

  • Deep understanding of key management life cycle, certificate management, and cryptographic operations.

  • Expertise in symmetric, asymmetric, and elliptic‑curve cryptography.

  • Experience working with PKI, CA hierarchies, certificate authority tooling, and trust models.

  • Experience integrating HSMs with payments platforms (FPS, CHAPS, card issuing/acquiring), authentication/SSO services, Kubernetes, cloud workloads, API gateways, or web platforms.

Software & Automation Skills
  • Scripting experience (Python, Bash, PowerShell or similar).

  • Knowledge of automation tooling and Infrastructure as Code (Terraform, Ansible) beneficial.

  • Understanding of cloud cryptographic services (AWS KMS/CloudHSM, Azure Key Vault HSM, GCP KMS).

Professional & Industry Background
  • Experience working in financial services, ideally Tier 1 banking or payments.

  • Strong understanding of regulatory frameworks governing cryptographic controls.

  • Experience working in highly controlled, audited, mission‑critical environments.

Soft Skills
  • Excellent communication skills with the ability to explain complex crypto concepts to both technical and non‑technical stakeholders.

  • Strong problem‑solving mindset with the ability to work autonomously on complex engineering challenges.

  • High attention to detail, particularly around operational discipline and audit evidence.

  • Team player with a collaborative mindset and willingness to coach others.


#J-18808-Ljbffr

Related Jobs

View all jobs

Linux Security & Cryptography Engineer

Linux Cryptography and Security Engineer

Crypto Network Specialist

Crypto Network Specialist

Crypto Devices Product Manager (Secure Mobility)

Cryptographic RTL Engineer - ASIC/FPGA - Remote

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Neurodiversity in Blockchain Careers: Turning Different Thinking into a Superpower

Blockchain is still a young, fast-changing field. It attracts people who challenge the status quo, question systems & build new ways for value, trust & identity to move around the world. That makes it a natural space for many neurodivergent people. If you live with ADHD, autism or dyslexia, you may have been told your brain is “too distracted”, “too literal” or “too chaotic” for a technical career. In reality, the same traits that can make traditional workplaces hard often line up perfectly with blockchain work – from deep focus on protocol details to creative problem-solving in DeFi, DAOs & web3 products. This guide is written for blockchain job seekers in the UK. We will cover: What neurodiversity means in a blockchain context How ADHD, autism & dyslexia strengths map to specific blockchain roles Practical workplace adjustments you can ask for under UK law How to talk about your neurodivergence during applications & interviews By the end, you will have a clearer sense of where you might thrive in blockchain – & how to turn different thinking into a strategic career advantage.

Blockchain Hiring Trends 2026: What to Watch Out For (For Job Seekers & Recruiters)

As we move into 2026, the blockchain jobs market in the UK is at an interesting crossroads. The speculative crypto boom years have cooled, some Web3 companies have downsized or disappeared, & yet demand for serious blockchain talent remains strong – especially where real-world utility, regulation & enterprise adoption meet. Tokenisation of real-world assets, regulated digital securities, central bank digital currency (CBDC) pilots, on-chain compliance tools & enterprise blockchain platforms are all moving from experiment to implementation. At the same time, hiring is more selective, funding is more cautious, & the bar for blockchain roles has risen. Whether you are a blockchain job seeker planning your next move, or a recruiter trying to build credible Web3 or enterprise blockchain teams, understanding the key blockchain hiring trends for 2026 will help you stay ahead.

Blockchain Recruitment Trends 2025 (UK): What Job Seekers Must Know About Today’s Hiring Process

Summary: UK blockchain hiring has shifted from buzzword-led CV screens to capability-driven assessments that emphasise protocol & smart‑contract security, compliance readiness, real throughput, cost-to-serve, developer ergonomics & measurable business impact across Web3 & enterprise blockchain. This guide explains what’s changed, what to expect in interviews & how to prepare—especially for smart‑contract engineers, protocol & infra engineers, security auditors, DevRel, product managers, quant/DeFi engineers, compliance specialists & Web3 growth roles. Who this is for: Solidity/Rust engineers, protocol & L2/L3 engineers, security auditors, custody/MPC specialists, blockchain data engineers, indexer/search engineers, DevOps/SRE for chains, DeFi quants, product & ecosystem leads, compliance/AML/KYC professionals targeting roles in the UK.