Position: Product Security Lead (Code Signing / PKI)
Client: Private Sector Technology Company
Location: Toronto (Hybrid)
Duration: 6 - 12 Months initially, potential for Contract to Hire
Background
Kyndryl is seeking a
Product Security Lead to support and advance an enterprise code-signing solution for key client product initiatives. This individual will be responsible for the ownership and management of signing infrastructure, PKI services, certificate and key lifecycles, and secure software release processes. The ideal candidate will possess deep hands-on experience with Windows and Linux signing workflows, HSM technologies, and embedded product security.
Qualifications
- Hands-on experience with:
- PKI (Public Key Infrastructure) and certificate management
- HSM (Hardware Security Modules) administration and integration
- AppViewX PKI+ platform
- PKCS#11 standards and integrations
- Certificate and cryptographic key lifecycle management
- Strong experience implementing, maintaining, and supporting Linux and Windows code-signing workflows using:
- OpenSSL
- Microsoft Signtool
- CI/CD pipeline integrations
- Proven experience provisioning, managing, and troubleshooting signing infrastructure, certificates, cryptographic keys, and HSM-backed signing solutions.
- Experience securing and signing:
- Firmware and embedded systems
- Secure Boot implementations
- Device identities (iDevID)
- Software releases with audited chain-of-custody controls
- Strong understanding of:
- Secure SDLC practices
- Software supply chain security
- Manufacturing and software chain-of-custody processes
- Production-grade code-signing infrastructure and operations
- Demonstrated ownership of certificate and key lifecycle processes, including issuance, rotation, renewal, revocation, storage, and governance.
- Experience integrating code-signing capabilities within enterprise development and release pipelines while maintaining security, compliance, and audit requirements.
- Ability to drive secure, scalable, and production-ready signing capabilities across enterprise environments through direct technical ownership and hands-on execution.
Expected Tasks
- Own and manage PKI, HSM, AppViewX PKI+, certificates, cryptographic keys, and signing infrastructure.
- Provision, maintain, and secure code-signing services and workflows across Windows and Linux environments.
- Implement and support signing automation using OpenSSL, Signtool, PKCS#11, and CI/CD integrations.
- Manage certificate and key lifecycle processes, including issuance, rotation, renewal, revocation, and compliance requirements.
- Support secure firmware and embedded-system signing processes, including Secure Boot and device identity implementations.
- Troubleshoot signing infrastructure, HSM integrations, PKI services, and operational issues.
- Drive scalable, secure, production-ready signing capabilities and software supply chain integrity controls.
#IndKyn
Please note this is for a contract position with one of our clients and not a full-time employment role with Kyndryl Canada.