HSM Architecture & Strategy Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness.
Enterprise Certificate Management Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments.
Enterprise Key Management Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption.
Post-Quantum Cryptography (PQC) Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement.
Cryptographic Standards & Governance Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams.
Relevant Experience
Enterprise Cryptographic Operations 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments.
Multi-Stakeholder Program Execution Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting.
Cryptographic Vendor Management Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis.
Regulated Environment Experience(Preferred) Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments.
API-Driven Security Services Design(Preferred) Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME.
Numbers & Facts
Location
Austin, TX
Skills
Application Programming Interface (API)unmatched
Cloud Computingunmatched
Consultingunmatched
Cost Analysisunmatched
Cryptographyunmatched
Cryptography Algorithmsunmatched
Customer Relationsunmatched
Digital Certificatesunmatched
Ecosystemsunmatched
Enterprise Protectionunmatched
Federal Information Processing Standards (FIPS)unmatched
Hybrid Cloudunmatched
Internet Securityunmatched
Migration Strategyunmatched
PCI-DSSunmatched
Product Requirements Document (PRD)unmatched
Protective Servicesunmatched
Public Key Infrastructure (PKI)unmatched
Public-Key Cryptography Standardsunmatched
Purchasing/Procurementunmatched
Relationship Managementunmatched
Risk Managementunmatched
Security Designunmatched
Vendor/Supplier Managementunmatched
Vendor/Supplier Planningunmatched
Writing Skillsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.