
AI is analyzing your overall score…
Identifying your key strengths…
Evaluating your skill match against the job requirements…
Assessing your cultural and operational fit
PKI & Cryptography Consultant | Helping Organizations Deploy Secure PKI, Digital Signatures & Trust Services | eIDAS · HSM · TSP · eID
I help organizations turn complex PKI and cryptography challenges into secure, compliant, and working infrastructure. 19 years of hands-on work across certificate authorities, HSMs, digital signatures, eID systems, and trust services means I have seen what works, what breaks, and what actually gets an implementation across the finish line. Organizations come to me when they are serious about getting PKI done right. Whether starting from zero or modernizing what already exists, I bring the technical depth and practical experience to deliver infrastructure that holds up under real compliance scrutiny and scales with the business. 𝐇𝐞𝐫𝐞 𝐢𝐬 𝐰𝐡𝐚𝐭 𝐰𝐨𝐫𝐤𝐢𝐧𝐠 𝐰𝐢𝐭𝐡 𝐦𝐞 𝐥𝐨𝐨𝐤𝐬 𝐥𝐢𝐤𝐞: You bring the challenge. I map a clear path forward, get hands-on with your team, and stay involved until the solution is solid, documented, and running the way it should. 𝐓𝐡𝐞 𝐤𝐢𝐧𝐝 𝐨𝐟 𝐰𝐨𝐫𝐤 𝐈 𝐭𝐚𝐤𝐞 𝐨𝐧: Designing and deploying PKI architecture and certificate authorities from the ground up. Implementing qualified and advanced electronic signatures fully aligned with eIDAS. Building and integrating Trust Service Provider solutions. Configuring and managing HSMs from Utimaco, Thales Luna, and Entrust nCipher. Delivering eID and ePassport systems with biometric verification and PKI-based authentication. Providing Common Criteria consultancy for TSPs working toward compliance. Developing digital signature APIs using Java, Spring, and microservices. 𝐖𝐡𝐨 𝐮𝐬𝐮𝐚𝐥𝐥𝐲 𝐫𝐞𝐚𝐜𝐡𝐞𝐬 𝐨𝐮𝐭: CTOs and security architects who need expert hands-on a live project. Compliance leads working against an eIDAS deadline. Organizations building PKI for the first time who want it done properly rather than rebuil
University Of Central Punjab
MS, Computer Sciences
January 1, 2008 – January 1, 2010
Self-employed
PKI, Digital Signature, eIDAS & Common Criteria Consultant
June 1, 2022 – Present
E-Tuğra EBG Bilişim Teknolojileri ve Hizmetleri A.Ş
PKI Architect
June 1, 2022 – April 1, 2025
Ascertia
Product Manager
June 1, 2017 – May 1, 2022
Ascertia
Technical Lead
June 1, 2013 – May 1, 2017
Ascertia
Senior Software Engineer
June 1, 2009 – May 1, 2013
Ascertia
Software Engineer
December 1, 2006 – May 1, 2009
ADSS Server SAM (Signature Activation Module)
April 1, 2019 – Present
The Ascertia ADSS Server SAM product is a Trustworthy System Supporting Server Signing (TW4S) that offers remote digital signature services. It ensures that the Signer’s signing key or keys are only used under the sole control of the Signer and only used for the intended purpose. The Ascertia ADSS Server SAM solution ensures that the remote signer has sole control of his signing keys at Sole Control Assurance Level 2 (SCAL2) according to EN 419241-1 [6] for qualified signatures. The Ascertia ADSS Server SAM is located within its own tamper protected environment referred to as the ADSS Server SAM appliance. The CM is located inside the appliances tamper protected environment. The TOE is connected to the CM through a trusted channel. The CM is shipped as an embedded module inside the ADSS Server SAM appliance, although even in this case it is important to note that the CM has its own tamper protected environment and the same trusted channel is used for the communication as if it was an external device.
Integration with QuoVadis Trust/Link Enterprise Web Service
January 1, 2015 – Present
QuoVadis, a leading provider of online authentication and encryption services, has released a new generation of its Trust/Link service which allows organisations to manage in real-time the full lifecycle of their digital certificates, from signup to revocation or renewal. ADSS CA Server provides support to integrate with QuoVadis TLEWS for the certificate issuance.
PAdES Part4-LTV Digital Signature
April 1, 2014 – May 1, 2014
This is the desktop base application which is the alternative of ADOBE PDF WRITER to use for Digital Signatures developed in C#.Net.The product was already equipped with conventional digital signatures creation process and it was required to add the support for PADES PART4 LTV Signatures and Customization of Hashing Algorithm. Working on Digital Signature,now a days a new fashion has been evolved i.e. Long-term Signature which we normally say PAdES LTV.Converting a desktop product to accommodate the LTV signature was a challenging task.The understanding of all the formalities and every small details is important.Completed the task with minimum bugs making it acceptable in standard market.
ADSS Go>Sign Service
July 1, 2012 – January 1, 2013
ADSS Go>Sign Service is a complete solution for browser-based document viewing, form-filling, advanced signing/authentication and centralised signature verification. Due to its zero footprint design, it removes all the difficulties associated with deploying and supporting locally installed software.
Secure Email Server (SES)
February 1, 2008 – Present
ADSS Secure Email Server is a full secure MTA server that quite literally drops-in to your existing mail infrastructure to seamlessly and automatically verify incoming signed emails and attachments. Signature verification is carried out by making calls to ADSS Server. Policy rules are set up to govern how to route emails that fail to verify or fail to be trusted. Trusted emails are sent on to the intended recipient.
ADSS Go>Sign Applet
January 1, 2007 – Present
ADSS Go>Sign Applet has been designed to make client-side digital signatures easy to implement and use within any web application. It removes all the difficulties associated with locally installed software. In multi-third party environments such as Business to Business (B2B), Business to Customers (B2C) or Government to Citizens (G2C) there is a clear need for zero installation signing. No organization wishes to own the problems that might arise from installing and using desktop software and increasingly local security policies do not allow this. ADSS Go>Sign Applet is a perfect solution for client-side signing. It has been designed to enable busy, non-technical people to sign documents and data. It works within modern browsers to allow citizens and businesses to go green, eliminate paper and avoid postage and handling costs. Use Go>Sign Applet to protect internal or external financial reports, HR, legal, sales and marketing, support services, compliance, engineering or architectural drawings, in fact any document where trust in authorship, integrity and approval are required.
Advanced Digital Signature Services
January 1, 2006 – Present
ADSS [Advanced Digital Signature Services] was a web-centric server-side solution that allows authentication and non-repudiation of people, contents and document source. ADSS protects data confidentiality, data alteration and impersonation of all types of files by long-term digital signatures, trust management, identity management and validation, encryption, PDF signatures and time-stamping. We’ve implemented multiple applied cryptography related RFC’s & PKCS. ADSS was based on core and enterprise technologies of Java.
Cultural Fit Analysis
The candidate's extensive experience in a specialized domain (PKI, Digital Signatures) and long-term commitment to a single company (Ascertia) before transitioning to consulting indicates a focused and dedicated professional. The project descriptions highlight a strong emphasis on security, compliance, and robust system design, which aligns well with a security-conscious culture. The breadth of roles from Software Engineer to Product Manager suggests adaptability and a willingness to take on diverse responsibilities within the security domain.
Soft Skills & Operational Fit
The candidate's experience as a Product Manager and Technical Lead at Ascertia suggests strong leadership, team management (30+ members), and communication skills, including interaction with customers and participation in industry forums. The ability to define roadmaps and lead certification processes indicates strategic thinking and operational effectiveness. The long tenure at Ascertia (16+ years) demonstrates loyalty and deep domain expertise.