SME - IT security
United States
Job Description
SME - IT security
Others, Texas

Job Summary

HSM Architecture & Strategy – Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness.\\\\r\\\\n2. Enterprise Certificate Management – Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments.\\\\r\\\\n3. Enterprise Key Management– Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption.\\\\r\\\\n4. Post-Quantum Cryptography (PQC) – Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement.\\\\r\\\\n5. Cryptographic Standards & Governance – Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams.\\\\r\\\\n\\\\r\\\\nRelevant Experience\\\\r\\\\n\\\\r\\\\n1. Enterprise Cryptographic Operations – 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments.\\\\r\\\\n2. Multi-Stakeholder Program Execution – Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting.\\\\r\\\\n3. Cryptographic Vendor Management – Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis.\\\\r\\\\n4. Regulated Environment Experience(Preferred) – Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments.\\\\r\\\\n5. API-Driven Security Services Design(Preferred) – Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME.\\\\r\\\\n

Key Responsibilities

HSM Architecture & Strategy – Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness.\\\\r\\\\n2. Enterprise Certificate Management – Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments.\\\\r\\\\n3. Enterprise Key Management– Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption.\\\\r\\\\n4. Post-Quantum Cryptography (PQC) – Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement.\\\\r\\\\n5. Cryptographic Standards & Governance – Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams.\\\\r\\\\n\\\\r\\\\nRelevant Experience\\\\r\\\\n\\\\r\\\\n1. Enterprise Cryptographic Operations – 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments.\\\\r\\\\n2. Multi-Stakeholder Program Execution – Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting.\\\\r\\\\n3. Cryptographic Vendor Management – Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis.\\\\r\\\\n4. Regulated Environment Experience(Preferred) – Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments.\\\\r\\\\n5. API-Driven Security Services Design(Preferred) – Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME.\\\\r\\\\n

Skill Requirements

HSM Architecture & Strategy – Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness.\\\\r\\\\n2. Enterprise Certificate Management – Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments.\\\\r\\\\n3. Enterprise Key Management– Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption.\\\\r\\\\n4. Post-Quantum Cryptography (PQC) – Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement.\\\\r\\\\n5. Cryptographic Standards & Governance – Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams.\\\\r\\\\n\\\\r\\\\nRelevant Experience\\\\r\\\\n\\\\r\\\\n1. Enterprise Cryptographic Operations – 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments.\\\\r\\\\n2. Multi-Stakeholder Program Execution – Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting.\\\\r\\\\n3. Cryptographic Vendor Management – Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis.\\\\r\\\\n4. Regulated Environment Experience(Preferred) – Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments.\\\\r\\\\n5. API-Driven Security Services Design(Preferred) – Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME.\\\\r\\\\n

Other Requirements

HSM Architecture & Strategy – Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness.\\\\r\\\\n2. Enterprise Certificate Management – Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments.\\\\r\\\\n3. Enterprise Key Management– Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption.\\\\r\\\\n4. Post-Quantum Cryptography (PQC) – Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement.\\\\r\\\\n5. Cryptographic Standards & Governance – Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams.\\\\r\\\\n\\\\r\\\\nRelevant Experience\\\\r\\\\n\\\\r\\\\n1. Enterprise Cryptographic Operations – 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments.\\\\r\\\\n2. Multi-Stakeholder Program Execution – Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting.\\\\r\\\\n3. Cryptographic Vendor Management – Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis.\\\\r\\\\n4. Regulated Environment Experience(Preferred) – Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments.\\\\r\\\\n5. API-Driven Security Services Design(Preferred) – Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME.\\\\r\\\\n

Maximum Salary (US): 
Minimum Salary (US): 
Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion. 

 

Compensation and Benefits

A candidate’s pay within the range will depend on their skills, experience, education, and other factors permitted by law. This role may also be eligible for performance-based bonuses subject to company policies. In addition, this role is eligible for the following benefits subject to company policies: medical, dental, vision, pharmacy, life, accidental death & dismemberment, and disability insurance; employee assistance program; 401(k) retirement plan; 10 days of paid time off per year (some positions are eligible for need-based leave with no designated number of leave days per year); and 10 paid holidays per year.