About the Role
About the Role
The Senior Middleware / PKCS#11 Engineer will be responsible for the technical ownership of host-side cryptographic integrations within the Infrastructure Layer. This role involves designing and building middleware and drivers that connect desktop applications with hardware tokens and cryptographic providers.
Key Responsibilities
- Cryptographic Stack Integration: Develop and maintain host-resident middleware and provider modules supporting PKCS#11, Microsoft CNG/KSP, legacy CAPI, and smartcard/DSC token driver interfaces.
- Producer Layer Implementation: Implement the Model A eSign producer to capture live Application Service Provider (ASP) evidence flows end-to-end.
- Hardware Interoperability: Lead physical lab testing to integrate and regression-test commercial DSC token vendors plus 1 Hardware Security Module (HSM).
- Offline Fault Tolerance: Design replay-safe resubmission logic for offline execution modes, ensuring zero duplicate custody entries during fault injection.
- Strict Fail-Closed Architecture: Enforce absolute error honesty across the evidence generation pipeline, ensuring zero fabricated or inferred field values under adversarial conditions.
- Technical Leadership: Serve as the day-to-day technical lead for Pod B (Producers), collaborating with embedded hardware engineers and the Chief Trust Architect.
Required Qualifications & Experience
- Experience: 5–10 years of hands-on host-side cryptographic system integration.
- Core Cryptographic Domains: Deep expertise in PKCS#11, Microsoft CNG/KSP, CAPI, smartcards, and DSC token stacks.
- Industry Background: Proven track record with hardware token vendors, Certifying Authority (CA) integration teams, or Banking/BFSI digital signing platform developers.
- Technical Languages: High proficiency in system-level languages such as C, C++, Rust, or Go.
- Standards Knowledge: Strong understanding of X.509 certificates, CMS SignedData (RFC 5652), PKCS#7, and Cryptographic Service Providers (CSPs).
Requirements
Cryptographic System Integration
5–10 years of hands-on experience in host-side cryptographic system integration.
PKCS#11 Expertise
Deep expertise in PKCS#11, Microsoft CNG/KSP, CAPI, smartcards, and DSC token stacks.
Technical Languages
High proficiency in system-level languages such as C, C++, Rust, or Go.
Standards Knowledge
Strong understanding of X.509 certificates and Cryptographic Service Providers.
Nice to Have
Experience with hardware token vendors or Banking/BFSI digital signing platforms.
Experience in leading technical teams and collaborating with hardware engineers.