Ovii Job Board

Middleware / PKCS#11 Engineer

Digital Trust Infrastructure India Limited

Pune, IN • Onsite - Pune, IN • Full-Time • 4+ years

Posted 2026-08-27 Apply by 2026-12-25 Tech & Engg

Job Description

We are seeking an experienced Senior Middleware / PKCS#11 Engineer to serve as the core technical owner of host-side cryptographic integrations for the Infrastructure Layer. You will be responsible for designing and building low-level host middleware, virtual drivers, and abstraction layers that interface desktop applications (e.g., Adobe Acrobat, web browsers) with underlying hardware tokens (QDSD), PKCS#11 providers, Microsoft CNG/KSP stacks, and remote eSign gateways.

Key Responsibilities

  • Cryptographic Stack Integration: Develop and maintain host-resident middleware and provider modules supporting PKCS#11, Microsoft CNG/KSP, legacy CAPI, and smartcard/DSC token driver interfaces.

  • Producer Layer Implementation: Implement the Model A eSign producer to capture live Application Service Provider (ASP) evidence flows end-to-end.

  • Hardware Interoperability: Lead physical lab testing to integrate and regression-test  commercial DSC token vendors plus 1 Hardware Security Module (HSM).

  • Offline Fault Tolerance: Design replay-safe resubmission logic for offline execution modes, ensuring zero duplicate custody entries during fault injection.

  • Strict Fail-Closed Architecture: Enforce absolute error honesty across the evidence generation pipeline, ensuring zero fabricated or inferred field values under adversarial conditions.

  • Technical Leadership: Serve as the day-to-day technical lead for Pod B (Producers), collaborating with embedded hardware engineers and the Chief Trust Architect.

Required Qualifications & Experience

  • Experience: 5–10 years of hands-on host-side cryptographic system integration.

  • Core Cryptographic Domains: Deep expertise in PKCS#11, Microsoft CNG/KSP, CAPI, smartcards, and DSC token stacks.

  • Industry Background: Proven track record with hardware token vendors, Certifying Authority (CA) integration teams, or Banking/BFSI digital signing platform developers.

  • Technical Languages: High proficiency in system-level languages such as C, C++, Rust, or Go.

  • Standards Knowledge: Strong understanding of X.509 certificates, CMS SignedData (RFC 5652), PKCS#7, and Cryptographic Service Providers (CSPs).

Skills

  • Cryptographic Stack Integration
  • Producer Layer Implementation
  • PKCS#11
  • C
  • EMBEDDED C
  • Hardware Interoperability

Benefits

  • Medical Cover
  • Gym Membership
  • Parental Leave