Product Security Lead
Offre en anglaisThe Product Security Lead will own and manage the enterprise code-signing infrastructure, including PKI services and HSM integrations. They are responsible for securing software release processes and managing the full lifecycle of certificates and cryptographic keys.
- Télétravail
- Canada
- Publié 4 août 2026
- 1 poste
Résumé du poste
Product Security Lead (Code Signing / PKI) Position: Product Security Lead (Code Signing / PKI) Client: Private Sector Technology Company Location: CANADA - REMOTE Duration: 6 - 12 Months initially, potential for Contract to Hire Background Kyndryl is seeking a Product Security Lead to support and advance an enterprise code-signing solution for key client product initiatives. This individual will be responsible for the ownership and management of signing infrastructure, PKI services, certificate and key lifecycles, and secure software release processes. The ideal candidate will possess deep hands-on experience with Windows and Linux signing workflows, HSM technologies, and embedded product security. Qualifications Hands-on experience with: PKI (Public Key Infrastructure) and certificate management HSM (Hardware Security Modules) administration and integration AppViewX PKI+ platform PKCS#11 standards and integrations Certificate and cryptographic key lifecycle management Strong experience implementing, maintaining, and supporting Linux and Windows code-signing workflows using: OpenSSL Microsoft Signtool CI/CD pipeline integrations Proven experience provisioning, managing, and troubleshooting signing infrastructure, certificates, cryptographic keys, and HSM-backed signing solutions. Experience securing and signing: Firmware and embedded systems Secure Boot implementations Device identities (iDevID) Software releases with audited chain-of-custody controls Strong understanding of: Secure SDLC practices Software supply chain security Manufacturing and software chain-of-custody processes Production-grade code-signing infrastructure and operations Demonstrated ownership of certificate and key lifecycle processes, including issuance, rotation, renewal, revocation, storage, and governance. Experience integrating code-signing capabilities within enterprise development and release pipelines while maintaining security, compliance, and audit requirements. Ability to drive secure, scalable, and production-ready signing capabilities across enterprise environments through direct technical ownership and hands-on execution. Expected Tasks Own and manage PKI, HSM, AppViewX PKI+, certificates, cryptographic keys, and signing infrastructure. Provision, maintain, and secure code-signing services and workflows across Windows and Linux environments. Implement and support signing automation using OpenSSL, Signtool, PKCS#11, and CI/CD integrations. Manage certificate and key lifecycle processes, including issuance, rotation, renewal, revocation, and compliance requirements. Support secure firmware and embedded-system signing processes, including Secure Boot and device identity implementations. Troubleshoot signing infrastructure, HSM integrations, PKI services, and operational issues. Drive scalable, secure, production-ready signing capabilities and software supply chain integrity controls. #IndKyn Please note this is for a contract position with one of our clients and not a full-time employment role with Kyndryl Canada.
Ce que vous ferez
The Product Security Lead will own and manage the enterprise code-signing infrastructure, including PKI services and HSM integrations. They are responsible for securing software release processes and managing the full lifecycle of certificates and cryptographic keys.
Exigences
Candidates must have deep hands-on experience with PKI, HSM administration, and code-signing workflows for both Windows and Linux. Proficiency with AppViewX, OpenSSL, and securing firmware or embedded systems is required.
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- PKI
- HSM
- AppViewX PKI+
- PKCS#11
- OpenSSL
- Microsoft Signtool
- CI/CD Integration
- Certificate Lifecycle Management
- Secure Boot
- Firmware Security
- Secure SDLC
- Software Supply Chain Security
- Linux Code-Signing
- Windows Code-Signing
- Cryptographic Key Management
- Embedded Product Security
Domaines d’emploi
- Security & Safety
- Technology
- Software
- Engineering
- Consulting
Renseignements supplémentaires
- Expérience minimale
- 5+ ans
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Niveau d’expérience
- Mid-Senior level