Encryption Engineer (DevSecOps & SDLC)
State Street · Quincy, MA · Yesterday
OTHR$120k–$203k/yrFull-time
About the role
We are seeking a highly motivated Encryption Engineer (DevSecOps & SDLC) who is passionate about building secure-by-design solutions and transforming encryption from a point-in-time security requirement into a seamlessly integrated engineering capability.
Responsibilities
- Embed enterprise encryption and key management controls into SDLC processes, DevSecOps pipelines, and platform engineering patterns to ensure security is built into solutions from the start.
- Design and implement secure-by-default encryption capabilities that enable application teams to adopt approved cryptographic controls with minimal effort.
- Develop and maintain reusable automation, APIs, templates, Infrastructure-as-Code modules, and reference architectures that accelerate consistent encryption adoption across the enterprise.
- Integrate enterprise key management, secrets management, certificate management, and encryption services into standard developer workflows and CI/CD toolchains.
- Establish automated guardrails and policy-driven controls that validate encryption requirements throughout the software development lifecycle.
- Partner with application development, platform engineering, cloud engineering, and architecture teams to implement approved cryptographic standards, patterns, and controls across cloud and on-premises environments.
- Create technical standards, implementation guidance, and developer enablement materials that simplify the adoption of encryption and key management capabilities.
- Continuously improve the organization's Encryption-by-Design program by increasing automation, reducing manual security reviews, and driving greater self-service adoption.
- Monitor and assess encryption implementations to identify control gaps, inconsistent practices, and opportunities for standardization and remediation.
- Support regulatory, audit, and risk management initiatives by ensuring encryption controls are consistently deployed, measurable, and supported by automated compliance evidence.
- Drive adoption of enterprise encryption services by working closely with engineering teams to modernize legacy implementations and align new solutions with approved standards.
- Reduce the risk of inconsistent, fragmented, or non-compliant encryption implementations through standardized patterns, automated enforcement, and scalable engineering controls.
- Minimize design exceptions, audit findings, and operational risks by embedding cryptographic controls directly into development processes rather than relying on manual reviews and remediation activities.
- Accelerate compliant application onboarding and delivery by providing reusable security capabilities that improve both developer experience and regulatory compliance outcomes.
Qualifications
- A security-first mindset with a passion for building secure, resilient, and scalable technology solutions.
- A strong engineering discipline and a commitment to automation, standardization, and continuous improvement.
- The ability to translate security requirements into practical engineering solutions that improve both security and developer experience.
- A collaborative approach to working across cybersecurity, architecture, engineering, infrastructure, and product teams.
- A proactive and innovative mindset focused on eliminating friction through reusable solutions, self-service capabilities, and policy-driven automation.
- Strong analytical and problem-solving skills with the ability to identify root causes and design sustainable solutions.
- Effective communication skills and the ability to explain complex technical concepts to both technical and non-technical stakeholders.
- An ownership mentality that prioritizes measurable outcomes, operational excellence, and long-term sustainability.
- A curiosity and a passion for learning in evolving areas such as cloud security, cryptography, platform engineering, DevSecOps, and software security.
- A commitment to reducing operational risk by replacing fragmented manual processes with scalable, automated security controls.
Preferred Qualifications
- Bachelor's degree in Computer Science, Information Security, Software Engineering, Information Technology, Cybersecurity, or a related discipline, or equivalent practical experience.
- 8+ years of experience in software engineering, DevSecOps, platform engineering, cloud engineering, cybersecurity engineering, or a related technical field.
- Experience integrating security controls into SDLC processes, CI/CD pipelines, and modern software delivery platforms.
- Working knowledge of encryption technologies, cryptographic key management, secrets management, certificate lifecycle management, and enterprise data protection controls.
- Experience implementing security automation within development pipelines using tools such as Harness, Jenkins, or similar platforms.
- Hands-on experience with Infrastructure-as-Code technologies, including Terraform, CloudFormation, or equivalent automation frameworks.
- Proficiency in one or more programming or scripting languages such as Python, Java, Go, C#, JavaScript, TypeScript, PowerShell, or Bash.
- Experience with cloud platforms including Microsoft Azure, Amazon Web Services (AWS), OCI, or Google Cloud Platform (GCP).
- Familiarity with containerization and modern platform technologies including Kubernetes, OpenShift, and cloud-native application architectures.
- Understanding of software architecture principles, secure coding practices, application security testing, and developer enablement methodologies.
- Knowledge of industry security and compliance frameworks such as NIST, PCI DSS, ISO 27001, or equivalent regulatory standards.
- Experience with enterprise key management platforms, Hardware Security Modules (HSMs), cloud KMS services, secrets management platforms, or certificate management solutions is highly desirable.
- Relevant certifications such as CISSP, CCSP, Azure Security Engineer Associate, AWS Security Specialty, Certified Kubernetes Security Specialist (CKS), or similar certifications are a plus.