Encryption Agility Engineer
On-siteHyderabad, Telangana, India
Job Summary
Execute assigned Encryption Agility Service workstreams, including intake analysis, backlog execution, roadmap tracking, and service improvement actions under the direction of the Senior Manager and Principal Architect. Operate enterprise cryptographic discovery across source code, binaries, cloud key services, endpoints, and PKI to build and maintain the Amgen Cryptographic Bill of Materials (CBOM) using CycloneDX 1.6+. Analyze scan outputs and implement remediation patterns for hybrid TLS, key management, and post-quantum readiness while coordinating with DIAS, PKI, and vendor teams on certificate lifecycle and secrets management. Partner with Application Security, DevOps, and engineering teams to publish secure code examples, CI/CD controls, and developer playbooks. Apply Amgen's quantum risk-prioritization approach to business-critical applications and validated GxP systems, providing technical escalation and mentoring for L4 analysts.
Required Qualifications
- Doctorate degree in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field
- Master's degree with 4 to 6 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field
- Bachelor's degree with 6 to 8 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field
- Diploma with 10 to 12 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field
- Strong hands-on knowledge of enterprise cryptography, including PKI, X.509 certificates, TLS, cipher suites, KMS, HSMs, secrets management, key lifecycle, encryption at rest, encryption in transit, cloud key services, identity protocols, and certificate lifecycle automation
- Practical experience with cryptographic discovery, CBOM-driven inventory, source code scanning, network and endpoint telemetry, cloud key service analysis, false-positive triage, data quality controls, dashboards, and remediation tracking
- Working knowledge of post-quantum cryptography, crypto agility, NIST-approved algorithms and standards, hybrid transition patterns, Steal-Now-Decrypt-Later (SNDL) risk reduction, and risk-prioritized remediation
- Ability to convert cryptographic policy, architecture direction, and scan findings into actionable engineering guidance across CI/CD, SSDLC, cloud platforms, PKI and certificates, KMS and secrets, identity, infrastructure, applications, third-party governance, and risk management
Desired Qualifications
- Hands-on experience with ServiceNow CMDB/GRC, Guard, Wiz, Qualys, Fortinet, Netskope, CrowdStrike, GitLab, Veracode, GitGuardian, Amazon Web Services (AWS) KMS, AWS Certificate Manager, AWS Secrets Manager, Microsoft PKI, Sectigo, HashiCorp Vault, HSMs, CLM platforms, and SIEM/data lake integrations
- Experience creating or operating CBOM/SBOM data models using CycloneDX 1.6+, Application Programming Interfaces (APIs), Comma-Separated Values (CSV), JavaScript Object Notation (JSON), dashboards, data quality checks, and audit-ready reporting
- Experience with PKI modernization, certificate automation, certificate rotation, CA hierarchy changes, hybrid certificate testing, and Post-Quantum Public Key Infrastructure (PQ-PKI) transition support
- Experience with key management and secrets management across AWS, Azure, on-premises platforms, HSMs, vault technologies, automation workflows, and centralized or federated operating models
- Experience with application security, DevOps, SSDLC governance, CI/CD quality gates, approved cryptographic libraries, static analysis, dynamic analysis, composition analysis, and developer enablement
- Experience in pharmaceutical, life sciences, regulated, validated, GxP, KCS, manufacturing, OT, or other change-controlled environments
- Scripting and automation experience with Python, PowerShell, Bash, Representational State Transfer Application Programming Interfaces (REST APIs), data pipelines, parsing of certificate or scan data, or lightweight integration development
- Certified Information Systems Security Professional (CISSP)
- Certified Cloud Security Professional (CCSP), AWS Certified Security - Specialty, Microsoft Azure Security Engineer, or equivalent cloud security certification
- Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or Certified in Risk and Information Systems Control (CRISC)
- Security+, Systems Security Certified Practitioner (SSCP), or equivalent security certification
- Relevant PKI, KMS, HSM, cryptographic discovery, certificate lifecycle management, cloud key management, or post-quantum cryptography training/certification
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.