Job Title: Cybersecurity Analyst
Location: Markham, ON
Estimated Duration: 12 Months

Description:
Job Title: Cryptography Analyst
Role Overview The Cryptography Analyst is responsible for delivering business-as-usual (BAU) cryptographic operations across key and secrets management, TLS/SSL certificate lifecycle, PKI services, and post-quantum cryptography (PQC) readiness. This role ensures secure, compliant, and resilient cryptographic services supporting enterprise platforms and applications.
Summary
This role is critical in ensuring secure, automated, and compliant cryptographic operations, with a focus on operational excellence, risk reduction, and future cryptographic readiness.
Key Responsibilities
Cryptography Services & Operations
Provide operational support for: o HashiCorp Vault–based secrets and key management o HSM-integrated root of trust operations o TLS/SSL certificate lifecycle using platforms such as Sectigo o Cryptographic monitoring, reporting, and governance o PQC readiness, risk management, and enablement

 2. HashiCorp Vault & Secrets Management
Administer and support Vault environments across production and non-production
Manage: Secrets, keys, tokens, leases, and service accounts lifecycle o Authentication mechanisms and RBAC enforcement o Access Control Lists (ACLs) aligned with least privilege principles
Perform: o Tenant onboarding/offboarding o Vault troubleshooting and performance tuning client: Internal
Support integrations with AWS KMS and external secret

3.Platform Operations & Maintenance
Conduct proactive monitoring and health checks
Manage Vault upgrades, testing, and currency roadmap
Support configuration changes and change management processes
Coordinate off-hours support and cloud transformation

4.HSM & Root of Trust Operations
Support Vault-HSM integration (Thales LUNA HSM)
Manage: o Auto-unseal functionality o Key rotation and secure handling practices • Coordinate firmware upgrades and DR processes

5. Certificate & PKI Lifecycle Management
Perform end-to-end certificate lifecycle operations: o Creation, renewal, revocation, replacement
Installation validation and incident troubleshooting
Ensure SLA adherence (24-hour turnaround)
Maintain certificate inventory and ownership records
Support PKI documentation, audits, and compliance

6. Certificate Automation & Governance client: Internal
Design and operate certificate lifecycle automation
Implement automation using: o ACME protocols o Vault PKI engine o Kubernetes cert-manager and cloud-native tools
Maintain: o Certificate inventory (including automation status) o Monitoring systems for renewal failures and expiry risks
Enforce: o Certificate standards (CAs, algorithms, key sizes) o Security best practices (least privilege, segregation of duties)

7. Cryptographic Inventory & Risk Management
Maintain a comprehensive cryptographic inventory: o Keys, secrets, certificates, and algorithms
Identify: o Deprecated or weak cryptographic implementations
Support audit, compliance, and risk assessments

8. Post-Quantum Cryptography (PQC)
Conduct PQC readiness assessments
Support: o Cryptographic transition strategies o Risk identification and mitigation
Enable future-proof cryptographic capabilities

9. Monitoring, Reporting & Governance
Deliver KPIs and service metrics across: o Vault operations o PKI and certificate automation o Cryptographic risk and PQC
Use tools such as Dynatrace, SiteScope, Rapid7, Power BI, and Excel for reporting

10. Security, Compliance & Resilience
Ensure compliance with security and regulatory requirements
Support: o Backup and disaster recovery processes o Security investigations and audits
Maintain high availability and resilience of cryptographic services

11. Knowledge Transfer & Enablement
Develop and maintain documentation and runbooks
Enable knowledge sharing across teams
Drive continuous improvement and operational maturity

Required Skills & Experience Technical Skills

  • HashiCorp Vault (administration and operations)
  • Hardware Security Modules (Thales LUNA preferred)
  • TLS/SSL certificate management and PKI client: Internal
  • Secrets management platforms (AWS Secrets Manager, etc.)
  • Cloud platforms (AWS preferred)
  • Automation (APIs, scripting, CI/CD integration)
  • Monitoring tools (Dynatrace, Rapid7, Power BI) Core Competencies
  • Strong understanding of cryptographic principles and lifecycle
  • Knowledge of RBAC, least privilege, and access control
  • Experience with compliance and audit frameworks
  • Problem-solving and troubleshooting skills
  • Ability to operate in a 24/7 BAU environment

Nice-to-Have

  • Experience with Kubernetes and cert-manager
  • Exposure to Post-Quantum Cryptography (PQC)
  • Experience in regulated industries (e.g., insurance, financial services)

The pay range that the employer reasonably expects to pay for this position is between CA$52.00 and CA$58.00

Our voluntary benefits offering includes medical, dental, vision and retirement benefits.

This posting is for an existing vacancy.

If you believe this post to be fraudulent, please report by clicking here

Tundra Technical Solutions is a global workforce and technology delivery firm, ranked by Staffing Industry Analysts as one of the largest in North America. At Tundra, we aren't just hiring top talent at the world's most recognizable brands; we are pioneers of social recruitment. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other legally protected characteristics. We welcome and encourage diversity in the workplace.

We use artificial intelligence tools to help our recruiters screen and assess talent. These tools do not replace human decision making in the process.

Not interested in this position, but know somebody who might be? Check out our Referral Reward Program, referrals are a big secret behind our success. As always, we’re on the lookout for great people. And we know that you know great people!