About the role
You design key custody and recovery, so protecting somebody's information does not mean a lost device ends their digital life. These two goals genuinely conflict, and the quality of this role is in how honestly you handle the conflict rather than in picking a side.
The work
Use established cryptographic libraries and protocols for encryption, key hierarchy, rotation and secure sharing. Work with platform hardware protections where available. Model recovery contacts, service compromise and malicious insiders, and document exactly who can decrypt which data.
What good looks like
In your first 90 days, deliver a reviewed key-management design and a tested recovery prototype with explicit security assumptions.
Evidence we look for
Bring applied cryptography and secure implementation experience. Be able to reason about entropy, authentication, protocol composition and the limits of cryptographic erasure.
What we need to see
- Applied cryptography with secure implementation experience, not only design
- You reason well about entropy, authentication, and protocol composition
- You understand the limits of cryptographic erasure and do not oversell it
- You design recovery for a real person having a bad day, not for an ideal user
Nice to have
- Threshold cryptography or social recovery schemes
- Secure enclave or HSM key custody
- You have had a design reviewed or audited externally
The exercise
Explain how a user can recover after losing every device without introducing an undisclosed service-side master key.
Where and how we work
In the office together five days a week, in any of these cities. Remote-friendly around your family, arranged one person at a time.