Job Summary
Key Responsibilities 1. Solution Architecture & Design Design the end‑to‑end encryption solution for sensitive workloads on AWS (technical architecture, operating model, governance framework). Integrate AWS KMS, XKS, CloudHSM with Thales HSMs and SG’s security ecosystem. Ensure solution alignment with SG’s cloud, cybersecurity, and compliance standards. Define dependency mapping, lifecycle management, and disaster recovery/BCP for key‑management services. 2. Validation & Cross‑Team Alignment Present and validate the solution with Architecture teams, Security teams, and Cloud Governance. Facilitate design reviews, architecture boards, risk assessments, and cryptographic compliance checks. Ensure full traceability of decisions, risks, and technical controls. 3. Deployment, Automation & Documentation Deploy and configure AWS KMS, XKS, CloudHSM environments and Thales integrations. Automate deployment pipelines using CI/CD, infrastructure-as-code, and DevOps tooling. Produce complete documentation (HLD, LLD, runbooks, standard operating procedures, security controls). Build dashboards and monitoring for service health, key usage, and compliance adherence. 4. Proof of Concept (POC) & Scalability Validation Execute a POC using a real-use case. Evaluate performance, scalability, operational flows, and integration reliability. Provide recommendations for optimization, security hardening, and operational efficiency. 5. Production Rollout & Service Enablement Lead the service transition from POC to production-ready state. Ensure the solution meets internal cloud platform criteria: operational readiness monitoring/alerting secure CI/CD pipelines service governance requirements Build operational workflows with OSM, Operations, Cloud, and Security teams. Drive incident response readiness, DR testing, and change control processes. 6. Knowledge Transfer & Team Upskilling Educate and mentor team members on AWS HSM, KMS, XKS, encryption models, and cloud security. Conduct training workshops, technical deep-dives, and documentation walkthroughs. Help establish an internal competency framework for AWS-based key management systems.
Key Responsibilities
Key Responsibilities 1. Solution Architecture & Design Design the end‑to‑end encryption solution for sensitive workloads on AWS (technical architecture, operating model, governance framework). Integrate AWS KMS, XKS, CloudHSM with Thales HSMs and SG’s security ecosystem. Ensure solution alignment with SG’s cloud, cybersecurity, and compliance standards. Define dependency mapping, lifecycle management, and disaster recovery/BCP for key‑management services. 2. Validation & Cross‑Team Alignment Present and validate the solution with Architecture teams, Security teams, and Cloud Governance. Facilitate design reviews, architecture boards, risk assessments, and cryptographic compliance checks. Ensure full traceability of decisions, risks, and technical controls. 3. Deployment, Automation & Documentation Deploy and configure AWS KMS, XKS, CloudHSM environments and Thales integrations. Automate deployment pipelines using CI/CD, infrastructure-as-code, and DevOps tooling. Produce complete documentation (HLD, LLD, runbooks, standard operating procedures, security controls). Build dashboards and monitoring for service health, key usage, and compliance adherence. 4. Proof of Concept (POC) & Scalability Validation Execute a POC using a real-use case. Evaluate performance, scalability, operational flows, and integration reliability. Provide recommendations for optimization, security hardening, and operational efficiency. 5. Production Rollout & Service Enablement Lead the service transition from POC to production-ready state. Ensure the solution meets internal cloud platform criteria: operational readiness monitoring/alerting secure CI/CD pipelines service governance requirements Build operational workflows with OSM, Operations, Cloud, and Security teams. Drive incident response readiness, DR testing, and change control processes. 6. Knowledge Transfer & Team Upskilling Educate and mentor team members on AWS HSM, KMS, XKS, encryption models, and cloud security. Conduct training workshops, technical deep-dives, and documentation walkthroughs. Help establish an internal competency framework for AWS-based key management systems.
Skill Requirements
Required Skills & Technical Expertise Core AWS Cryptography Expertise AWS KMS, External Key Store (XKS), CloudHSM, key lifecycle management. Integration with Thales HSMs and enterprise-grade encryption architectures. Cloud Architecture & Security Strong cloud architecture knowledge (AWS, Azure concepts an advantage). Experience designing secure cloud services for regulated workloads. Strong understanding of IAM, VPC security, encryption-in-transit/at-rest, and compliance frameworks. DevOps & Automation Experience with IaC and CI/CD pipelines (Terraform, CloudFormation, GitHub Actions, or Azure DevOps). Background in automation for deployment, monitoring, and configuration at scale. Cross-Team Collaboration Ability to work with Architecture, Cloud, OSM, Governance, and Security Compliance teams. Strong experience leading POCs, pilots, and service transition activities. Governance & Operating Model Experience defining operational models, service governance, risk assessments, and audit documentation. Preferred Qualifications Experience with enterprise HSM solutions (Thales, Luna, or equivalent). AWS Solutions Architect – Professional
Other Requirements
Preferred Qualifications Experience with enterprise HSM solutions (Thales, Luna, or equivalent). AWS Solutions Architect – Professional