Software Engineer, SecureMachines

Hi, I'm Nithin Ram Kalava.

I'm a software engineer at SecureMachines, working on Cloud HSM: the cloud services and infrastructure that let applications use hardware security modules remotely, across both cloud and on-prem. Right now I'm the primary engineer connecting our HSMs to a national identity system that serves over a billion people. On the side, I maintain pqc, a post-quantum cryptography library that other developers use.

Cloud services & infrastructure HSM, PKCS#11, JCE Post-Quantum Crypto Low-level systems
01

What I do at work

Where I spend my days right now.

SecureMachines

Software Engineer

Since Nov 2025

Cryptographic security · Bengaluru

  • As the primary engineer on our national identity work, I integrate our HSMs into a biometric identity system that serves over a billion people, and into an open-source identity platform that governments deploy.
  • I'm building SecureMachines' enterprise Cloud HSM: the cloud services and infrastructure that let organizations use our hardware security modules remotely, staying compatible with the KMS, SignServer and PKCS#11 tooling they already run, across both cloud and on-prem.
  • I designed and built parts of Augha, a customer-facing Entropy-as-a-Service platform on Google Cloud (Compute Engine, Cloud Run, Cloud KMS, Firestore, Memorystore, API Gateway, load balancers and HA VPN).
  • I built a JCE provider and helped bring HSM support to Linux, writing C shared libraries (.so) and wiring up PKCS#11 so existing applications use the hardware with no code changes.
  • I optimized the protocol and implementation for our cryptographic operations, bringing the latency down from around 1.8 seconds to about 11 milliseconds.
  • On the side, I built a lightweight REST API over PKCS#11 so developers can try our post-quantum HSM without wiring up the native interface first.
Java / JCECPKCS#11Google CloudCloud KMSHA VPNSignServerLinux
02

Things I've built

A few projects I made end to end, outside of work.

FEATURED · 01

pqc

Post-quantum cryptography for JavaScript

A pure-JavaScript implementation of the NIST post-quantum standards (ML-KEM, ML-DSA and SLH-DSA, covering FIPS 203, 204 and 205), built for the web with no native dependencies and an accompanying research paper.

  • npm downloads3,493
  • ML-KEM keygens / sec2,300+
  • NIST standards3
JavaScript (ESM)FIPS 203/204/205Lattice cryptonpm
03

What I work with

The tools I reach for most.

Languages

JavaCPythonTypeScriptSQLBashTcl

Cryptography & security

HSMsPKCS#11JCEKMSSignServerPost-quantum (ML-KEM, ML-DSA, SLH-DSA)

Cloud & infrastructure

Google CloudCloud RunCloud KMSFirestoreHA VPNAWSLinuxDockerCI/CD

Web & data

Next.jsReactNode.jsPostgreSQLREST APIsPandas

I also have AWS and Google Cloud training and a handful of machine-learning and data-science certificates, but most of what I use day to day I learned by building the things above.

04

About me

The short version.

I studied computer science and joined SecureMachines right after. Most of what I know I learned by building things and taking them apart: web apps, data pipelines, a machine-learning project, a cryptography library, and now the cloud infrastructure behind hardware security modules.

I'm not tied to one stack or one domain. I move across web, data, machine learning, cryptography and low-level systems, and I pick up new tools quickly, so I can slot into most kinds of software work. What I enjoy most are the problems close to the hardware, where a small mistake is the difference between secure and not, and I like making complicated systems simple enough for other people to actually use.

Outside of work I build PCs, run a small home lab, tinker with Linux, throw darts, and watch far too many films. I recently moved to Bengaluru for this job, and I'm slowly learning Kannada.

05

Get in touch

I read everything that comes in.

Happy to talk about cryptography, HSMs, cloud infrastructure, or any interesting systems problem. The quickest way to reach me is email.