By contacting us you agree with the storage and handling of your data by this website.
About Triam Security:
Triam Security is revolutionizing software supply chain security through our
advanced vulnerability database platform and CleanStart product line. We provide
hardened, vulnerability-free container images with built-in security, compliance,
and performance benefits. Our mission is to transform container security by
eliminating pre-existing vulnerabilities and providing full visibility and control over
the software supply chain.
Role Overview:
As a Senior Compliance Engineer specializing in cryptography, you will lead our
efforts to ensure FIPS compliance across our container image portfolio. You will
design and implement cryptographic solutions, validate compliance with federal
standards, and work with engineering teams to maintain FIPS certification. Your
expertise will be crucial in meeting the stringent security requirements of
government and regulated industry customers.
Key Responsibilities:
- Lead the design and implementation of FIPS-compliant cryptographic
modules
- Develop and execute FIPS validation strategies for container images
- Perform cryptographic code reviews and security assessments
- Create and maintain documentation for FIPS compliance verification
- Collaborate with engineering teams to integrate compliant cryptographic
libraries
- Design testing frameworks for validating cryptographic implementations
- Maintain awareness of changes to FIPS standards and requirements
- Serve as a subject matter expert on cryptography and FIPS compliance
- Guide product teams on cryptographic best practices and compliance
requirements
Required Qualifications:
- 5+ years of experience in cryptography engineering or compliance
- Deep understanding of FIPS 140-2/140-3 requirements and validation
processes
- Experience implementing and validating cryptographic modules
- Strong knowledge of cryptographic algorithms, protocols, and standards
- Proficiency in programming languages commonly used for cryptographic
implementations
- Familiarity with Linux systems and container technologies
- Experience with compliance documentation and validation processes
- Strong analytical and problem-solving skills
Preferred Qualifications:
- Experience with FIPS validation in containerized environments
- Knowledge of additional compliance frameworks (Common Criteria, NIST
800-53)
- Background in security engineering or secure development
- Experience with hardware security modules (HSMs)
- Familiarity with supply chain security concepts
- Previous work with government security requirements
- Contributions to cryptographic libraries or security tools
- Experience with secure boot or trusted execution environments