Location: Remote, India
Experience: 5–10+ years
Reporting to: Senior Security Engineer / Cryptographic Strategy Lead
We are seeking a hands-on Implementation Engineer to help turn enterprise cryptographic strategy and Post-Quantum Readiness (PQR) goals into practical, scalable services. This role will focus on enabling self-service certificate capabilities through DigiCert, automating certificate lifecycle management, and establishing a Cryptographic Bill of Materials (CBOM) across the enterprise.
The ideal candidate is an experienced engineer who can work directly with platform, application, infrastructure, cloud, and security teams to deliver automation, improve cryptographic visibility, reduce certificate-related operational risk, and build crypto-agile foundations for future PQC migration.
ResponsibilitiesImplement enterprise cryptographic strategy through practical platforms, services, automation, and engineering standards.
Enable and expand DigiCert self-service capabilities for application and infrastructure teams, including secure certificate request, approval, issuance, renewal, revocation, and reporting workflows.
Design, build, and support automated certificate lifecycle management across enterprise environments.
Integrate certificate automation with CI/CD pipelines, cloud platforms, infrastructure-as-code, secrets-management tools, load balancers, APIs, and application platforms.
Establish and maintain a Cryptographic Bill of Materials (CBOM) that documents cryptographic assets, certificates, algorithms, keys, protocols, libraries, dependencies, ownership, business criticality, and lifecycle status.
Support cryptographic discovery and inventory efforts across applications, endpoints, networks, cloud services, PKI, and third-party technologies.
Help identify and remediate certificate expiration risk, weak or legacy cryptographic configurations, hard-coded cryptographic dependencies, and gaps in crypto-agility.
Develop reusable implementation patterns, runbooks, technical documentation, dashboards, and operational controls for certificate and cryptographic services.
Partner with senior engineers and architects on PQR and PQC initiatives, including readiness assessments, migration planning, hybrid cryptography pilots, and technology evaluations.
Track implementation progress, technical dependencies, risks, and remediation status; escalate blockers to the senior lead as needed.
Provide hands-on technical support and guidance to application and infrastructure teams adopting enterprise cryptographic services.
5–10 years of hands-on experience in security engineering, platform engineering, DevSecOps, cloud engineering, infrastructure engineering, or application engineering.
Practical experience with PKI, X.509 certificates, TLS/SSL, certificate authorities, certificate lifecycle management, and key-management concepts.
Experience administering, integrating, or automating enterprise certificate-management platforms; DigiCert experience is strongly preferred.
Experience building automation with Python, PowerShell, Bash, Java, Go, or similar languages.
Familiarity with REST APIs, CI/CD pipelines, Git-based workflows, Terraform, Ansible, containers, and/or Kubernetes.
Experience working in AWS, Azure, and/or Google Cloud, including cloud certificate, key-management, secrets, identity, and network-security services.
Understanding of applied cryptography, including encryption, hashing, digital signatures, key exchange, PKI, protocols, and cryptographic libraries.
Ability to troubleshoot certificate, TLS, trust-store, key, and cryptographic configuration issues in production environments.
Strong communication and documentation skills, with the ability to work effectively in a remote, cross-functional global team.
Experience implementing certificate self-service portals, certificate automation, ACME/SCEP/EST workflows, or certificate lifecycle integrations.
Experience creating or maintaining a CBOM, cryptographic inventory, software bill of materials, configuration-management database, or asset-discovery program.
Familiarity with Post-Quantum Cryptography, Post-Quantum Readiness, crypto-agility, and emerging standards such as ML-KEM and ML-DSA.
Experience with HSMs, cloud KMS services, secrets-management platforms, code signing, mTLS, API security, or enterprise PKI modernization.
Experience in a large, regulated, or highly distributed enterprise environment.
Skills Required
- 5-10 years of hands-on experience in security engineering, platform engineering, DevSecOps, cloud engineering, infrastructure engineering, or application engineering
- Practical experience with PKI, X.509 certificates, TLS/SSL, certificate authorities, certificate lifecycle management, and key-management concepts
- Experience administering, integrating, or automating enterprise certificate-management platforms
- Experience building automation with Python, PowerShell, Bash, Java, Go, or similar languages
- Familiarity with REST APIs, CI/CD pipelines, Git-based workflows, Terraform, Ansible, containers, and/or Kubernetes
- Experience with AWS, Azure, and/or Google Cloud, including certificate, key-management, secrets, identity, and network-security services
- Understanding of applied cryptography, including encryption, hashing, digital signatures, key exchange, PKI, protocols, and cryptographic libraries
- Ability to troubleshoot certificate, TLS, trust-store, key, and cryptographic configuration issues in production
- Strong communication and documentation skills in a remote, cross-functional global team
- Experience implementing certificate self-service portals, certificate automation, ACME, SCEP, or EST workflows
- Experience creating or maintaining a CBOM, software bill of materials, configuration-management database, or asset-discovery program
- Familiarity with Post-Quantum Cryptography, Post-Quantum Readiness, crypto-agility, ML-KEM, and ML-DSA
- Experience with HSMs, cloud KMS, secrets-management platforms, code signing, mTLS, API security, or enterprise PKI modernization
- Experience in a large, regulated, or highly distributed enterprise environment
What We Do
For 25 years, Lawinger Consulting, Inc., has provided innovative IT solutions to help our clients thrive • Our clients range from Fortune 500 companies (General Mills, 3M, Lifetouch, Medtronic, State of Minnesota & others) seeking global team partnerships to small businesses requiring inexpensive, low-maintenance solutions. We provide Staffing Services in the following areas: • Managed Services - supporting applications on a wide variety of platforms • Custom Application Development in.NET / Java / Javascript / Ruby on Rails • Business Analysis / Project Management • Quality Assurance / Software Testing - Manual and Automated approaches • Our industries include manufacturing, financial services, government and nonprofits. • Our hardware engineers are experts in configuring systems on Windows, Unix, Linux and mainframe platforms. Why do so many clients work with LCI? • We listen to our clients needs • We analyze their applications and infrastructure to understand their current state • Based on that analysis, we offer creative, effective IT solutions • We understand the importance of cost containment • We approach every client with the intent on building a long-term relationship
.jpeg)







