Product Security Lead (Code Signing / PKI)

Product Security Lead (Code Signing / PKI)

  • Location: Toronto, ON and Richardson, TX 

We at Raise are hiring a Product Security Lead (Code Signing / PKI) for one of our top clients. After establishing themselves as an industry leader, they’re now expanding their team to meet rising demand. We’re hiring right now; if you’re interested, apply below for your chance to join a great place to work.

Core Responsibilities:

PKI, HSM & Signing Infrastructure Ownership

  • Own and manage enterprise PKI services, HSM platforms, AppViewX PKI+, certificates, cryptographic keys, and signing infrastructure.
  • Provision, configure, maintain, secure, and monitor HSM-backed code-signing services across enterprise environments.
  • Administer PKCS#11 integrations and resolve interoperability issues between signing tools, applications, HSMs, and PKI services.
  • Maintain reliable, scalable, and production-ready signing capabilities for critical product initiatives.

Windows, Linux & CI/CD Signing Workflows

  • Implement and support Windows and Linux code-signing workflows using Microsoft SignTool, OpenSSL, and associated platform tooling.
  • Integrate signing capabilities into enterprise CI/CD, build, release, and artifact-management pipelines.
  • Automate secure signing processes while preserving key protection, access controls, traceability, compliance, and audit requirements.
  • Troubleshoot signing failures, certificate-chain issues, HSM connectivity, PKCS#11 integrations, and operational workflow interruptions.

Certificate & Cryptographic Key Lifecycle Management

  • Own certificate and key lifecycle processes, including issuance, secure storage, rotation, renewal, revocation, retirement, and recovery planning.
  • Establish and maintain governance, access, approval, monitoring, and audit controls for signing assets and cryptographic material.
  • Coordinate certificate renewals and key rotations to minimize disruption to development, manufacturing, and release activities.
  • Maintain accurate standards, inventories, procedures, operational records, and audit evidence.

Firmware, Embedded Systems & Device Identity

  • Support secure firmware and embedded-system signing processes throughout product development and release lifecycles.
  • Enable and maintain Secure Boot signing implementations and associated trust relationships.
  • Support device identity implementations, including iDevID certificates and related provisioning processes.
  • Partner with product and manufacturing teams to enforce secure, traceable handoffs of signed artifacts.

Secure SDLC & Software Supply-Chain Security

  • Embed code-signing requirements and controls within secure development and product release processes.
  • Strengthen software supply-chain integrity through authenticated artifacts, controlled signing services, and auditable chain-of-custody practices.
  • Collaborate with engineering, DevOps, release, security, compliance, and manufacturing stakeholders to resolve risks and operational gaps.
  • Drive scalable improvements to production signing architecture, automation, resiliency, and operational readiness.

Priority Technical Requirements

Candidates must demonstrate direct, hands-on ownership in the following areas:

  • Direct practitioner ownership: Candidates must demonstrate direct hands-on ownership of code-signing infrastructure, HSM-backed signing services, AppViewX PKI+, embedded-security controls, or enterprise PKI operations. Security-adjacent experience without direct implementation and operational ownership is not sufficient for this role.
  • PKI and cryptographic services: Enterprise PKI, certificate management, HSM administration and integration, AppViewX PKI+, and PKCS#11 standards and integrations.
  • Certificate and key lifecycle ownership: Issuance, secure storage, rotation, renewal, revocation, retirement, governance, compliance, and audit support.
  • Cross-platform code signing: Linux and Windows signing workflows using OpenSSL, Microsoft SignTool, and CI/CD pipeline integrations.
  • Embedded product security: Firmware and embedded-system signing, Secure Boot implementations, device identities such as iDevID, and production release controls.
  • Software supply-chain integrity: Secure SDLC, manufacturing and software chain-of-custody processes, and production-grade code-signing operations.

Technical Qualifications:

Required Experience:

  • Direct experience implementing, maintaining, and supporting enterprise PKI, certificate services, HSM-backed signing solutions, and AppViewX PKI+.
  • Hands-on administration and integration experience with HSM technologies and PKCS#11.
  • Strong experience with OpenSSL, Microsoft SignTool, Windows and Linux signing workflows, and CI/CD integrations.
  • Demonstrated ownership of certificate and cryptographic key lifecycle processes and governance.
  • Experience securing firmware, embedded systems, Secure Boot implementations, device identities such as iDevID, and software releases with audited chain-of-custody controls.
  • Strong understanding of Secure SDLC, software supply-chain security, manufacturing controls, and production code-signing operations.

Preferred Experience:

  • Experience supporting enterprise product development, embedded technology, or manufacturing environments.
  • Experience designing or improving high-availability, scalable code-signing services.
  • Ability to translate security and audit requirements into practical engineering controls and operating procedures.

Soft Skills & Working Style:

  • Hands-on technical owner: Comfortable directly administering platforms, diagnosing failures, and driving issues through resolution.
  • Security and control focused: Applies disciplined protection, access, traceability, compliance, and audit practices.
  • Cross-functional collaborator: Works effectively with engineering, DevOps, release, security, compliance, and manufacturing teams.
  • Documentation discipline: Produces clear architecture records, operating procedures, lifecycle standards, runbooks, and audit evidence.

Looking for meaningful work? We can help!

Raise is an established hiring firm with over 65 years of experience. We believe strongly in making the world a better place through work, which is why we’re a certified B Corporation and donate 10% of our profits to charity.

We strive to build teams that reflect the diversity of the communities we work in. We encourage all qualified applicants to apply, including people from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with visible/nonvisible disabilities.

We have a dedicated webpage for accommodations where you can learn more about what we offer and request accommodation: https://raise.jobs/accommodations/

In order to submit candidates for roles, our clients will sometimes require personal information to confirm the identity of applicants and their legal status to work. Raise will never ask you for personal or banking information unless you have been selected for a job. If you are ever unsure about the legitimacy of this or another job posting by Raise (or have any other questions), please contact us at +1 800-567-9675 or hello@raiserecruiting.com

Product Security Lead (Code Signing / PKI)

Similar job opportunities:

When you apply for a job with us, you consent to the use of automated screening tools — including voice and text analysis — for this job and future jobs with Raise. These tools help us review resumes, assess qualifications, and make initial recommendations; however, all final reviews and hiring decisions are made by people. Questions? Contact us at hello@raiserecruiting.com

Search all jobs:

Search jobs by title or keyword
Click here

Keep exploring!