QNu Labs

HSM Architect

Bangalore · Full-time

Posted
27 Jul 2026
Last verified at source
9 hours ago
Apply on QNu Labs

Join us in our mission to protect the digital world with indigenous, future-proof, quantum-safe technologies.


We are looking for a Mid-Level Hardware Security Module (HSM) Architect with strong hands on experience in C/C++ and a solid understanding of cryptographic systems and HSM architecture. The ideal candidate will be responsible for designing, developing, and optimizing secure cryptographic services, key management systems, and HSM firmware/software components with a focus on performance, scalability, and high availability and read on…


Key Responsibilities:

Design and architect HSM software/firmware components including key management, cryptographic services, and secure storage.

• Develop and maintain high-performance, secure C/C++ code for cryptographic and HSM subsystems.

• Define and implement HSM interfaces such as PKCS#11, KMIP, REST, and proprietary APIs.

• Work on secure boot, firmware update, and trusted execution environments.

• Design solutions for multi-tenant, high-availability, and fault-tolerant HSM deployments.

• Perform threat modeling, security reviews, and cryptographic design validation.

• Optimize concurrency, multi-threading, and hardware acceleration (PCIe, FPGA, TPM, etc.).

• Collaborate with system, network, and cloud architects for HSM integration in enterprise and cloud environments.

• Ensure compliance with standards such as FIPS 140-2/3, Common Criteria, and ETSI where applicable.

• Provide technical leadership and mentor junior engineers.Required Skills

• Strong proficiency in C and C++ (multithreading, memory management, performance tuning).

• Deep understanding of HSM architecture:

• Key lifecycle management

• Secure key storage and isolation

• Partitioning, multi-tenancy, and access control

• HA, clustering, and disaster recovery

• Solid knowledge of cryptography:

• Symmetric: AES, HMAC,RSA, ECC

• Hashing: SHA-2, SHA-3

• PKI, TLS, digital signatures

• Random number generation and entropy sources

• Experience with cryptographic standards and APIs:

• PKCS#11 (Cryptoki), OpenSSL, Encryption

• KMIP, JCE/JCA


Understanding secure OS concepts: trusted execution, secure memory, side-channel mitigation.

• Experience with Linux system programming and kernel/user-space interaction.

Nice to Have

• Experience with commercial HSMs (Thales, Utimaco, Safenet, AWS CloudHSM, etc.).

• Knowledge of FIPS 140-2/3 certification process.

• Exposure to cloud-based KMS and HSM virtualization.

• Experience with FPGA or hardware acceleration. Education Bachelor’s or master’s degree in computer science, Electronics, Cryptography, or related field.