Amgen logo
AmgenPosted 1 month ago

Encryption Agility Analyst

On-siteHyderabad, Telangana, India

Full TimeEnterprise

Job Summary

Conduct cryptographic inventory validation and maintain Cryptographic Bill of Materials (CBOM) records using CycloneDX 1.6+ across Amgen's enterprise systems. Collect and verify data from source code, binaries, cloud key services, and vendor attestations while reviewing scan outputs, certificate chains, and cipher suite configurations under technical guidance. Coordinate with Digital Identity Access Service, PKI, and application security teams to track remediation status, manage false-positive triage, and prepare reporting views for dashboards and operational documentation. Support post-quantum cryptography readiness by documenting evidence, updating tickets, and escalating complex design exceptions to senior engineers. Maintain SOPs, knowledge articles, and exception records while monitoring industry standards including NIST, IETF, and HIPAA.

Required Qualifications

  • Master's degree with 1 to 3 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field
  • Bachelor's degree with 3 to 5 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field
  • Diploma with 7 to 9 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field
  • Working knowledge of information security and foundational enterprise cryptography, including PKI, X.509 certificates, TLS, cipher suites, KMS, secrets management, key lifecycle, encryption at rest, encryption in transit, cloud key services, and identity protocols
  • Experience reviewing security tool outputs, maintaining inventory records, validating data quality, documenting findings, updating tickets, and supporting dashboards or operational reports
  • Basic understanding of post-quantum cryptography, crypto agility, cryptographic discovery, CBOM/SBOM concepts, risk-based remediation, and Steal-Now-Decrypt-Later (SNDL) risk
  • Ability to follow technical guidance, document evidence clearly, coordinate with service owners, and escalate complex cryptographic findings or exceptions appropriately
  • Excellent analytical, troubleshooting, and problem-solving skills
  • Strong attention to detail and commitment to accurate inventory, evidence, and reporting data
  • Strong verbal and written communication skills for technical and non-technical stakeholders
  • Ability to translate findings into clear documentation, tickets, summaries, and escalation notes
  • Ability to work effectively with global, virtual teams across security, Digital, Technology and Innovation (DTI), DIAS, procurement, legal, compliance, OT, infrastructure, cloud, and application teams
  • High degree of initiative, accountability, and self-motivation while working under technical direction
  • Ability to manage multiple work items, evidence requests, and remediation tracking activities successfully
  • Team oriented, with a focus on shared outcomes, practical execution, and service maturity
  • Comfort learning an emerging technical domain and helping mature a new enterprise capability from the ground up

Desired Qualifications

  • Experience with ServiceNow CMDB/GRC, Guard, Wiz, Qualys, Fortinet, Netskope, CrowdStrike, GitLab, Veracode, GitGuardian, Amazon Web Services (AWS) KMS, AWS Certificate Manager, AWS Secrets Manager, Microsoft PKI, Sectigo, HashiCorp Vault, HSMs, CLM platforms, or SIEM/data lake tools
  • Experience supporting CBOM/SBOM data management using CycloneDX 1.6+, Application Programming Interfaces (APIs), Comma-Separated Values (CSV), JavaScript Object Notation (JSON), spreadsheets, dashboards, data quality checks, and audit-ready reporting
  • Experience supporting certificate lifecycle activities, certificate expiration tracking, certificate ownership updates, certificate rotation evidence, or PKI operational reporting
  • Experience supporting cloud security, application security, DevOps, SSDLC governance, CI/CD quality gates, static analysis, dynamic analysis, composition analysis, or developer remediation tracking
  • Experience in pharmaceutical, life sciences, regulated, validated, GxP, KCS, manufacturing, OT, or other change-controlled environments
  • Experience supporting vendor or third-party risk activities, supplier questionnaires, roadmap tracking, evidence collection, or Software as a Service platform dependency analysis
  • Foundational scripting or data handling experience with Python, PowerShell, Bash, Representational State Transfer Application Programming Interfaces (REST APIs), CSV files, JSON files, or lightweight reporting automation
  • Security+, Systems Security Certified Practitioner (SSCP), or equivalent foundational security certification
  • Certified Information Systems Security Professional (CISSP) Associate, CISSP, Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or Certified in Risk and Information Systems Control (CRISC)
  • Certified Cloud Security Professional (CCSP), AWS Certified Security - Specialty, Microsoft Azure Security Engineer, or equivalent cloud security certification
  • Information Technology Infrastructure Library (ITIL), Scaled Agile Framework (SAFe), product management, or equivalent delivery certification
  • Relevant PKI, KMS, HSM, cryptographic discovery, certificate lifecycle management, cloud key management, or post-quantum cryptography training/certification

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce