Applied Cryptography & Key Management
Practical cryptography for developers, with hands-on Google Cloud KMS.
- Who it's for
- Working software engineers and security-minded developers
- Format
- Live workshops + hands-on labs
- Duration
- 5 weeks
Taught by practitioners with SANS/GIAC credentials and hands-on PCI DSS experience securing Cardholder Data Environments.
Overview
An applied course on using cryptography correctly in real systems — not the number theory, the engineering. You learn what each primitive is for, where teams get it wrong, and how to manage keys properly using Google Cloud KMS, with the concepts mapped to PCI DSS and other compliance requirements. Labs use Google Cloud KMS; the patterns transfer directly to AWS KMS and Azure Key Vault.
What you'll be able to do
- Choose the right primitive for the job: hashing, symmetric, asymmetric, signatures, and authenticated encryption
- Recognize and avoid the common failures — ECB mode, hardcoded keys, weak randomness, rolling your own
- Implement envelope encryption with a DEK/KEK hierarchy using Google Cloud KMS
- Set up key rotation, IAM on keys, CMEK, Cloud HSM, and audit logging
- Map key-management controls to PCI DSS requirement 3 and explain them to an auditor
Roles this prepares you for
- Backend and platform engineer
- Application security engineer
- PCI DSS / key-management work
Syllabus
- 01
Crypto primitives, the right way
Hashing vs. encryption, symmetric vs. asymmetric, digital signatures, and AEAD. What each is for, and what breaks when they are misused.
- 02
Cryptography failures in the wild
ECB penguins, hardcoded and reused keys, weak IVs and randomness, downgrade attacks, and why 'roll your own' fails. Reading real CVEs.
- 03
Key management with Google Cloud KMS
Key rings and keys, envelope encryption, the DEK/KEK hierarchy, symmetric and asymmetric keys, and encrypt/decrypt/sign operations in a lab.
- 04
Operating keys safely
Rotation schedules, IAM and separation of duties on keys, CMEK for managed services, Cloud HSM and external key managers, and audit logging.
- 05
Compliance & handoff
Mapping controls to PCI DSS requirement 3 and similar frameworks, documenting a key-management design, and a review of each participant's lab project.
Frequently asked
Do I need a math background?+
No. This is an engineering course — you use cryptographic tools correctly, you do not implement them from scratch or prove theorems.
Is this locked to Google Cloud?+
Labs use Google Cloud KMS, but envelope encryption, key hierarchies, rotation, and access control work the same way on AWS KMS and Azure Key Vault. The course calls out the differences.
How is this different from the consulting engagement?+
Consulting is us doing the review or design for your team. This course teaches your engineers to make those decisions themselves; it also runs as a private team workshop.
Ready to get started?
Book a free intro call or send us a message with your questions.