Job Summary
HSM Architecture & Strategy – Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness.\\\\r\\\\n2. Enterprise Certificate Management – Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments.\\\\r\\\\n3. Enterprise Key Management– Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption.\\\\r\\\\n4. Post-Quantum Cryptography (PQC) – Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement.\\\\r\\\\n5. Cryptographic Standards & Governance – Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams.\\\\r\\\\n\\\\r\\\\nRelevant Experience\\\\r\\\\n\\\\r\\\\n1. Enterprise Cryptographic Operations – 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments.\\\\r\\\\n2. Multi-Stakeholder Program Execution – Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting.\\\\r\\\\n3. Cryptographic Vendor Management – Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis.\\\\r\\\\n4. Regulated Environment Experience(Preferred) – Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments.\\\\r\\\\n5. API-Driven Security Services Design(Preferred) – Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME.\\\\r\\\\n
Key Responsibilities
HSM Architecture & Strategy – Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness.\\\\r\\\\n2. Enterprise Certificate Management – Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments.\\\\r\\\\n3. Enterprise Key Management– Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption.\\\\r\\\\n4. Post-Quantum Cryptography (PQC) – Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement.\\\\r\\\\n5. Cryptographic Standards & Governance – Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams.\\\\r\\\\n\\\\r\\\\nRelevant Experience\\\\r\\\\n\\\\r\\\\n1. Enterprise Cryptographic Operations – 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments.\\\\r\\\\n2. Multi-Stakeholder Program Execution – Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting.\\\\r\\\\n3. Cryptographic Vendor Management – Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis.\\\\r\\\\n4. Regulated Environment Experience(Preferred) – Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments.\\\\r\\\\n5. API-Driven Security Services Design(Preferred) – Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME.\\\\r\\\\n
Skill Requirements
HSM Architecture & Strategy – Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness.\\\\r\\\\n2. Enterprise Certificate Management – Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments.\\\\r\\\\n3. Enterprise Key Management– Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption.\\\\r\\\\n4. Post-Quantum Cryptography (PQC) – Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement.\\\\r\\\\n5. Cryptographic Standards & Governance – Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams.\\\\r\\\\n\\\\r\\\\nRelevant Experience\\\\r\\\\n\\\\r\\\\n1. Enterprise Cryptographic Operations – 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments.\\\\r\\\\n2. Multi-Stakeholder Program Execution – Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting.\\\\r\\\\n3. Cryptographic Vendor Management – Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis.\\\\r\\\\n4. Regulated Environment Experience(Preferred) – Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments.\\\\r\\\\n5. API-Driven Security Services Design(Preferred) – Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME.\\\\r\\\\n
Other Requirements
HSM Architecture & Strategy – Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness.\\\\r\\\\n2. Enterprise Certificate Management – Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments.\\\\r\\\\n3. Enterprise Key Management– Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption.\\\\r\\\\n4. Post-Quantum Cryptography (PQC) – Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement.\\\\r\\\\n5. Cryptographic Standards & Governance – Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams.\\\\r\\\\n\\\\r\\\\nRelevant Experience\\\\r\\\\n\\\\r\\\\n1. Enterprise Cryptographic Operations – 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments.\\\\r\\\\n2. Multi-Stakeholder Program Execution – Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting.\\\\r\\\\n3. Cryptographic Vendor Management – Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis.\\\\r\\\\n4. Regulated Environment Experience(Preferred) – Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments.\\\\r\\\\n5. API-Driven Security Services Design(Preferred) – Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME.\\\\r\\\\n