Fortunately, the Interchain Foundation has worked with a team to build a key management server for validators. You can find documentation on how to use it here, it is used extensively in production. You are not limited to using this tool, there are also HSMs, there is not a recommended HSM.
Currently Tendermint uses Ed25519 keys which are widely supported across the security sector and HSMs.