← All open roles

H42 Β· Private information and trust

Applied Cryptography and Key Recovery Engineer

Protect personal information without making a lost device the end of a person's digital life. You will design key custody and recovery.

Pilot expansionOffice-first9 cities

About the role

You design key custody and recovery, so protecting somebody's information does not mean a lost device ends their digital life. These two goals genuinely conflict, and the quality of this role is in how honestly you handle the conflict rather than in picking a side.

The work

Use established cryptographic libraries and protocols for encryption, key hierarchy, rotation and secure sharing. Work with platform hardware protections where available. Model recovery contacts, service compromise and malicious insiders, and document exactly who can decrypt which data.

What good looks like

In your first 90 days, deliver a reviewed key-management design and a tested recovery prototype with explicit security assumptions.

Evidence we look for

Bring applied cryptography and secure implementation experience. Be able to reason about entropy, authentication, protocol composition and the limits of cryptographic erasure.

What we need to see

  • Applied cryptography with secure implementation experience, not only design
  • You reason well about entropy, authentication, and protocol composition
  • You understand the limits of cryptographic erasure and do not oversell it
  • You design recovery for a real person having a bad day, not for an ideal user

Nice to have

  • Threshold cryptography or social recovery schemes
  • Secure enclave or HSM key custody
  • You have had a design reviewed or audited externally

The exercise

Explain how a user can recover after losing every device without introducing an undisclosed service-side master key.

Where and how we work

In the office together five days a week, in any of these cities. Remote-friendly around your family, arranged one person at a time.