Cyber Data Protection/PKI Specialist Senior Consultant
Recruiting for this role ends on 12/31/2026.
About the role
Serve as a subject matter expert and trusted advisor to our clients, assisting them to evaluate strategic and practical data protection and encryption requirements based on new and emerging data risks. Advise on best practices for data encryption, decryption, and secure key management.
Assist clients in designing, implementing, and operating technology and process solutions to reduce data risks, developing and leading the implementation of encryption strategies to protect sensitive data across various environments, including cloud, on-premises, and hybrid infrastructures. Manage the deployment and lifecycle of PKI systems, ensuring robust and scalable certificate management processes. Monitor and maintain the health of certificate infrastructures to prevent downtime and security breaches. Assist with developing requirements, evaluating vendor solutions, architecting, implementing, and operating data protection solutions.
Aid in the delivery of client engagements by:
- Driving day-to-day execution, communicating updates to clients and firm leadership
- Providing leadership and support to delivery teams to ensure completion and accuracy of high-quality work products
- Tracking and reporting on project timelines to ensure on-time and on-budget delivery
Stay up to date on emerging encryption technologies (e.g., post-quantum cryptography, confidential computing, secure enclaves, envelope encryption) and industry trends around cyber risk, data protection, and cryptography practices. Proactively evaluate and recommend new tools and solutions to enhance data security.
Responsibilities
- Design, implement, and operate data protection and encryption solutions
- Develop and lead encryption strategies for cloud, on-premises, and hybrid environments
- Manage PKI systems and certificate lifecycle processes
- Monitor and maintain certificate infrastructure health to prevent downtime and breaches
- Evaluate and recommend new data protection tools and technologies
- Support strategy, architecture, roadmap, and implementation workstreams
- Lead small teams and produce structured, client-ready deliverables
- Gather requirements, manage stakeholders, and facilitate workshops
- Integrate solutions across F5, load balancers, WAFs, Kubernetes, API gateways, web/app servers, and cloud platforms
Qualifications
Required:
- Bachelor's degree in Cybersecurity, Information Security, Engineering, Computer Science, Information Technology, or related field
- 5+ years of professional experience within data protection and information security, which may include Data Discovery, Data Classification and Rights Management, Data Access Governance, Data Loss Prevention, Cloud Access Security Broker, Encryption, Certificate Lifecycle Management, Cloud Security, SaaS Security
- 5+ years with PKI concepts: certificates, CAs, RA, CSR, OCSP, CRL, HSM, key management, trust chains
- 2+ years of professional experience managing and implementing encryption technologies (e.g., database encryption, file encryption, PKI, certificate lifecycle management (CLM), transport layer security (TLS)) and strong understanding of Cloud encryption concepts such as client-side encryption, bring your own key (BYOK), server-side encryption
- 2+ years developing data protection strategies, roadmaps, and frameworks
- 2+ years of total hands-on technical experience with data protection technologies
- 2+ years with CLM platforms such as AppViewX, Venafi, Keyfactor, DigiCert, or similar
- 2+ years with cryptographic standards and protocols including TLS/SSL, SSH, S/MIME, code signing, and NIST-aligned practices
- 2+ years with certificate discovery, inventory, automation, renewal, and compliance monitoring
- 2+ years supporting strategy, architecture, roadmap, and implementation workstreams
- 2+ years of hands-on understanding of integration points across F5, load balancers, WAFs, Kubernetes, API gateways, web/app servers, and cloud platforms
- 2+ years of client-facing skills: requirements gathering, stakeholder management, workshop facilitation, and executive communication
- 2+ years leading small teams/workstreams and producing structured, client-ready deliverables
- Ability to travel 25-50%, on average, based on client needs
- Limited sponsorship may be available
Preferred:
- Quantum readiness and AI protection experience
- Experience with market-leading data protection and encryption vendors (e.g., Thales, AppViewX, Venafi, Fortanix, DigiCert, Protegrity)
- Experience with public cloud (Azure, AWS, GCP) security and modern data platforms (e.g., Snowflake, Databricks, Starburst)
- Experience or familiarity with emerging data protection technologies (e.g., Secure Access Service Edge, Data Security Posture Management, Data Security Platforms, Synthetic Data)
- Familiarity with networks, firewalls, IDS/IPS, and endpoint security
- Familiarity with popular databases on Windows and UNIX platforms, including Oracle and MS SQL
- Familiarity with common identity, authentication, and directory services, such as Active Directory and LDAP
- Experience with sophisticated multinational companies and distributed business models
- Experience defining data protection use cases, documenting business requirements, and evaluating technology solutions
- Experience with data risk program design, including alignment to cybersecurity and compliance programs
- Experience working with data protection and information security policies, standards, and procedures
- Experience leading collaborative efforts across organizational silos, including IT, legal/compliance, and business executives
- Experience with cloud collaboration tools and security/compliance, particularly Microsoft 365
- Familiarity with change management, deployment, and operational processes in large IT organizations
- Experience with vendor relationship management
- Professional certifications such as CISSP, CISM, or similar
Pay
A reasonable estimate of the current range is $118,700 - $218,600. You may also be eligible to participate in a discretionary annual incentive program, subject to program rules, where awards depend on individual and organizational performance.