Comcast Cybersecurity: Principal Cybersecurity Engineer - Hsm and IOT Security

Comcast Comcast · Media · Philadelphia, PA

Principal Cybersecurity Engineer focused on designing, developing, and deploying advanced security frameworks involving PKI, HSMs, Blockchain, and cryptographic token management for embedded and enterprise platforms. Requires extensive experience in HSM administration, X.509 certificate lifecycle management, and cryptographic key management.

What you'd actually do

  1. Design, develop, and implement advanced security software, frameworks, and applications supporting PKI, HSM, IoT, and cryptographic systems.
  2. Lead the architecture and deployment of secure communication protocols, certificate management systems, and cryptographic key infrastructures.
  3. Customize and enhance existing security applications while developing processes for software updates, patch management, and version control.
  4. Provide technical leadership and establish best practices, procedures, and guidelines for secure system design and implementation.
  5. Partner with Quality Assurance and DevSecOps teams to validate that all software and hardware integrations meet security and regulatory requirements.

Skills

Required

  • Bachelor's and/or Master’s degree in Computer Science, Information Security, or a related technical field
  • 12+ years of professional experience in cybersecurity engineering or secure embedded software development
  • Proven experience with Hardware Security Modules (HSMs), preferably Thales Luna or similar
  • Strong knowledge of Public Key Infrastructure (PKI), X.509 certificate management, and cryptographic key operations
  • Hands-on experience with IoT security frameworks, secure boot, and device identity management
  • Solid understanding of encryption algorithms, digital signatures, and secure communication protocols (TLS, SSH, IPsec)
  • Proficiency in C/C++, Python, or Java
  • good grasp of operating system fundamentals and secure coding practices
  • Familiarity with Continuous Integration and Deployment tools (Jenkins, Concourse)
  • Deep understanding of the HTTP/S protocol and web security concepts
  • Experience working in Agile/Scrum development environments
  • Strong critical thinking, independent problem-solving, and adaptability to new technologies
  • Collaborative experience in multi-company or open-source industry projects

Nice to have

  • Experience with Thales, Cybertrust or nCipher HSMs for key management and integration
  • Background in embedded software development, especially RDK-based platforms
  • Knowledge of secure firmware signing and OTA update processes
  • Understanding of TPMs, secure enclaves, and lightweight cryptography for IoT
  • Familiarity with CA, KMIP, and cloud KMS integrations (AWS, Azure, GCP)
  • Experience with SSDLC practices and secure code review

What the JD emphasized

  • extensive hands-on experience in HSM administration
  • strong preference for Thales devices
  • X.509 certificate lifecycle management
  • cryptographic key management operations
  • highly adaptable professional who can quickly master new languages and technologies
  • thrive in a dynamic environment
  • work effectively across teams
  • strong emphasis is placed on innovation
  • continuous improvement
  • delivering secure, future-ready solutions
  • Proven experience with Hardware Security Modules (HSMs), preferably Thales Luna or similar
  • Strong knowledge of Public Key Infrastructure (PKI), X.509 certificate management, and cryptographic key operations
  • Hands-on experience with IoT security frameworks, secure boot, and device identity management
  • Solid understanding of encryption algorithms, digital signatures, and secure communication protocols (TLS, SSH, IPsec)
  • Proficiency in C/C++, Python, or Java
  • good grasp of operating system fundamentals and secure coding practices
  • Familiarity with Continuous Integration and Deployment tools (Jenkins, Concourse)
  • Deep understanding of the HTTP/S protocol and web security concepts
  • Experience working in Agile/Scrum development environments
  • Strong critical thinking, independent problem-solving, and adaptability to new technologies
  • Collaborative experience in multi-company or open-source industry projects
  • Experience with Thales, Cybertrust or nCipher HSMs for key management and integration
  • Background in embedded software development, especially RDK-based platforms
  • Knowledge of secure firmware signing and OTA update processes
  • Understanding of TPMs, secure enclaves, and lightweight cryptography for IoT
  • Familiarity with CA, KMIP, and cloud KMS integrations (AWS, Azure, GCP)
  • Experience with SSDLC practices and secure code review