Product Security Lead (Code Signing / PKI+HSM)

Richardson, TX, US • Posted 7 hours ago • Updated 7 hours ago
Contract Independent
Contract W2
18 Months
No Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • PKI
  • Lifecycle Management
  • Hierarchical Storage Management

Summary

Role :- Product Security Lead (Code Signing / PKI)

Location:- Richardson, TX- Onsite

Contract 

 

JOB DESCRIPTION

Enterprise code signing | PKI & HSM | AppViewX PKI+ | Embedded security | Secure software releases

 

Position Summary

seeking a Product Security Lead to support and advance an enterprise code-signing solution for key client product initiatives. This individual will own and manage signing infrastructure, PKI services, certificate and cryptographic key lifecycles, and secure software release processes.

The ideal candidate will bring deep hands-on experience with Windows and Linux signing workflows, HSM technologies, AppViewX PKI+, PKCS#11 integrations, embedded product security, and audited software chain-of-custody controls. This is a practitioner role requiring direct technical ownership and execution.

Priority Technical Requirements

Candidates must demonstrate direct, hands-on ownership in the following areas:

·       Direct practitioner ownership: Candidates must demonstrate direct hands-on ownership of code-signing infrastructure, HSM-backed signing services, AppViewX PKI+, embedded-security controls, or enterprise PKI operations. Security-adjacent experience without direct implementation and operational ownership is not sufficient for this role.

·       PKI and cryptographic services: Enterprise PKI, certificate management, HSM administration and integration, AppViewX PKI+, and PKCS#11 standards and integrations.

·       Certificate and key lifecycle ownership: Issuance, secure storage, rotation, renewal, revocation, retirement, governance, compliance, and audit support.

·       Cross-platform code signing: Linux and Windows signing workflows using OpenSSL, Microsoft SignTool, and CI/CD pipeline integrations.

·       Embedded product security: Firmware and embedded-system signing, Secure Boot implementations, device identities such as iDevID, and production release controls.

·       Software supply-chain integrity: Secure SDLC, manufacturing and software chain-of-custody processes, and production-grade code-signing operations.

Core Responsibilities

1. PKI, HSM & Signing Infrastructure Ownership

·       Own and manage enterprise PKI services, HSM platforms, AppViewX PKI+, certificates, cryptographic keys, and signing infrastructure.

·       Provision, configure, maintain, secure, and monitor HSM-backed code-signing services across enterprise environments.

·       Administer PKCS#11 integrations and resolve interoperability issues between signing tools, applications, HSMs, and PKI services.

·       Maintain reliable, scalable, and production-ready signing capabilities for critical product initiatives.

2. Windows, Linux & CI/CD Signing Workflows

·       Implement and support Windows and Linux code-signing workflows using Microsoft SignTool, OpenSSL, and associated platform tooling.

·       Integrate signing capabilities into enterprise CI/CD, build, release, and artifact-management pipelines.

·       Automate secure signing processes while preserving key protection, access controls, traceability, compliance, and audit requirements.

·       Troubleshoot signing failures, certificate-chain issues, HSM connectivity, PKCS#11 integrations, and operational workflow interruptions.

3. Certificate & Cryptographic Key Lifecycle Management

·       Own certificate and key lifecycle processes, including issuance, secure storage, rotation, renewal, revocation, retirement, and recovery planning.

·       Establish and maintain governance, access, approval, monitoring, and audit controls for signing assets and cryptographic material.

·       Coordinate certificate renewals and key rotations to minimize disruption to development, manufacturing, and release activities.

·       Maintain accurate standards, inventories, procedures, operational records, and audit evidence.

4. Firmware, Embedded Systems & Device Identity

·       Support secure firmware and embedded-system signing processes throughout product development and release lifecycles.

·       Enable and maintain Secure Boot signing implementations and associated trust relationships.

·       Support device identity implementations, including iDevID certificates and related provisioning processes.

·       Partner with product and manufacturing teams to enforce secure, traceable handoffs of signed artifacts.

5. Secure SDLC & Software Supply-Chain Security

·       Embed code-signing requirements and controls within secure development and product release processes.

·       Strengthen software supply-chain integrity through authenticated artifacts, controlled signing services, and auditable chain-of-custody practices.

·       Collaborate with engineering, DevOps, release, security, compliance, and manufacturing stakeholders to resolve risks and operational gaps.

·       Drive scalable improvements to production signing architecture, automation, resiliency, and operational readiness.

Technical Qualifications

Required Experience

·       Direct experience implementing, maintaining, and supporting enterprise PKI, certificate services, HSM-backed signing solutions, and AppViewX PKI+.

·       Hands-on administration and integration experience with HSM technologies and PKCS#11.

·       Strong experience with OpenSSL, Microsoft SignTool, Windows and Linux signing workflows, and CI/CD integrations.

·       Demonstrated ownership of certificate and cryptographic key lifecycle processes and governance.

·       Experience securing firmware, embedded systems, Secure Boot implementations, device identities such as iDevID, and software releases with audited chain-of-custody controls.

·       Strong understanding of Secure SDLC, software supply-chain security, manufacturing controls, and production code-signing operations.

Preferred Experience

·       Experience supporting enterprise product development, embedded technology, or manufacturing environments.

·       Experience designing or improving high-availability, scalable code-signing services.

·       Ability to translate security and audit requirements into practical engineering controls and operating procedures.

Soft Skills & Working Style

o   Hands-on technical owner: Comfortable directly administering platforms, diagnosing failures, and driving issues through resolution.

o   Security and control focused: Applies disciplined protection, access, traceability, compliance, and audit practices.

o   Cross-functional collaborator: Works effectively with engineering, DevOps, release, security, compliance, and manufacturing teams.

o   Documentation discipline: Produces clear architecture records, operating procedures, lifecycle standards, runbooks, and audit evidence.

 

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91173415
  • Position Id: 9077442
  • Posted 7 hours ago
Contact the job poster
VS

Vikas Suhag

Recruiter @ Opulent Global Technologies Inc.
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Addison, Texas

Today

Easy Apply

Contract

Depends on Experience

Dallas, Texas

23d ago

Easy Apply

Contract

50 - 55

Dallas, Texas

Yesterday

Easy Apply

Contract

$50+

Hybrid in Dallas, Texas

Today

Easy Apply

Contract

Depends on Experience

Search all similar jobs