Product Security Lead (Code Signing / PKI) at Kyndryl Canada — NeverHard
Product Security Lead (Code Signing / PKI) at Kyndryl Canada in Ontario, Canada. Apply on NeverHard.
Company
Kyndryl Canada
Location
Ontario, Canada
Type
full_time
27th July, 2026
Position: Product Security Lead (Code Signing / PKI)
Client: Private Sector Technology Company
Location: Toronto (Hybrid)
Duration: 6 - 12 Months initially, potential for Contract to Hire
Background
Kyndryl is seeking a
Product Security Lead
to support and advance an enterprise code-signing solution for key client product initiatives. This individual will be responsible for the ownership and management of signing infrastructure, PKI services, certificate and key lifecycles, and secure software release processes. The ideal candidate will possess deep hands-on experience with Windows and Linux signing workflows, HSM technologies, and embedded product security.
Qualifications
Hands-on experience with:
PKI (Public Key Infrastructure) and certificate management
HSM (Hardware Security Modules) administration and integration
AppViewX PKI+ platform
PKCS#11 standards and integrations
Certificate and cryptographic key lifecycle management
Strong experience implementing, maintaining, and supporting
Linux and Windows code-signing workflows
using:
OpenSSL
Microsoft Signtool
CI/CD pipeline integrations
Proven experience provisioning, managing, and troubleshooting signing infrastructure, certificates, cryptographic keys, and HSM-backed signing solutions.
Experience securing and signing:
Firmware and embedded systems
Secure Boot implementations
Device identities (iDevID)
Software releases with audited chain-of-custody controls
Strong understanding of:
Secure SDLC practices
Software supply chain security
Manufacturing and software chain-of-custody processes
Production-grade code-signing infrastructure and operations
Demonstrated ownership of certificate and key lifecycle processes, including issuance, rotation, renewal, revocation, storage, and governance.
Experience integrating code-signing capabilities within enterprise development and release pipelines while maintaining security, compliance, and audit requirements.
Ability to drive secure, scalable, and production-ready signing capabilities across enterprise environments through direct technical ownership and hands-on execution.
Expected Tasks
Own and manage PKI, HSM, AppViewX PKI+, certificates, cryptographic keys, and signing infrastructure.
Provision, maintain, and secure code-signing services and workflows across Windows and Linux environments.
Implement and support signing automation using OpenSSL, Signtool, PKCS#11, and CI/CD integrations.
Manage certificate and key lifecycle processes, including issuance, rotation, renewal, revocation, and compliance requirements.
Support secure firmware and embedded-system signing processes, including Secure Boot and device identity implementations.
Troubleshoot signing infrastructure, HSM integrations, PKI services, and operational issues.
Drive scalable, secure, production-ready signing capabilities and software supply chain integrity controls.
#IndKyn
Please note this is for a contract position with one of our clients and not a full-time employment role with Kyndryl Canada.