Source description
About the role
Design, govern, and evolve the enterprise cryptographic infrastructure : including HSM platforms, certificate authorities, certificate lifecycle management systems, and enterprise key management services - across on-premises, cloud, and customer-facing environments, ensuring operational resilience through a deliberate multi-vendor strategy that balances risk mitigation, procurement agility, and technology portability. Serve as the enterprise lead for Post-Quantum Cryptography (PQC) readiness : driving cross-business-unit awareness, requirements documentation, crypto-agility planning, and global enablement by tracking emerging PQC standards, evaluating hybrid cryptographic approaches, assessing PQC-native hardware, and translating evolving mandates into actionable migration roadmaps. Author, maintain, and enforce enterprise cryptographic standards and governance frameworks : covering algorithms, protocols, PKI trust models, and key management practices - while translating complex regulatory and technical requirements (including FIPS, FedRAMP, PCI DSS, and NFI PKI) into clear, actionable guidance that diverse engineering teams can confidently implement. Lead multi-year cryptographic transformation programs : managing distributed execution across business units and technology teams, owning delivery accountability, conducting quantified cost/effort analysis for build-vs-buy and vendor consolidation decisions, managing strategic vendor relationships, and providing executive-level reporting on program progress and risk posture. Architect abstracted, API-first cryptographic services : designing certificate and key management capabilities that enable seamless backend technology portability without consumer disruption, leveraging protocols such as KMIP, PKCS#11, EST, and ACME to eliminate vendor lock-in and provide scalable, self-service cryptographic operations for enterprise consumption.
Take the first step towards your dream career - Every Dell team member brings something unique to the table. Here's what we are looking for with this role: Essential Requirement:
HSM Architecture & Strategy : Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness. Enterprise Certificate Management : Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments. Enterprise Key Management : Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption. Post-Quantum Cryptography (PQC) : Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement. Cryptographic Standards & Governance : Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams. Enterprise Cryptographic Operations: 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments.
Multi-Stakeholder Program Execution: Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting.
Cryptographic Vendor Management: Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis.
Desired Requirement: Regulated Environment Experience (Preferred): Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments.
API-Driven Security Services Design (Preferred): Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME.
More at Dell
Related open roles
Public CloudSecurityEngineer- Senior Advisor (Bengaluru)
Bangalore
Public Cloud Security Engineer- Senior Advisor (Hyderabad)
Hyderabad
Senior Analyst, Cybersecurity Engineering (Bengaluru)
Bangalore
Public Cloud Security Engineer- Senior Advisor (Bengaluru)
Bangalore
Federal Cybersecurity Senior Advisor - Security Data Management (SDM)
United States · Onsite
Senior Advisor, Cybersecurity Engineering (Hyderabad)
Hyderabad
