Jobs · OTHR · Massachusetts

Encryption Engineer (DevSecOps & SDLC)

State Street · Quincy, MA · Yesterday
OTHR$120k–$203k/yrFull-time

About the role

We are seeking a highly motivated Encryption Engineer (DevSecOps & SDLC) who is passionate about building secure-by-design solutions and transforming encryption from a point-in-time security requirement into a seamlessly integrated engineering capability.

Responsibilities

  • Embed enterprise encryption and key management controls into SDLC processes, DevSecOps pipelines, and platform engineering patterns to ensure security is built into solutions from the start.
  • Design and implement secure-by-default encryption capabilities that enable application teams to adopt approved cryptographic controls with minimal effort.
  • Develop and maintain reusable automation, APIs, templates, Infrastructure-as-Code modules, and reference architectures that accelerate consistent encryption adoption across the enterprise.
  • Integrate enterprise key management, secrets management, certificate management, and encryption services into standard developer workflows and CI/CD toolchains.
  • Establish automated guardrails and policy-driven controls that validate encryption requirements throughout the software development lifecycle.
  • Partner with application development, platform engineering, cloud engineering, and architecture teams to implement approved cryptographic standards, patterns, and controls across cloud and on-premises environments.
  • Create technical standards, implementation guidance, and developer enablement materials that simplify the adoption of encryption and key management capabilities.
  • Continuously improve the organization's Encryption-by-Design program by increasing automation, reducing manual security reviews, and driving greater self-service adoption.
  • Monitor and assess encryption implementations to identify control gaps, inconsistent practices, and opportunities for standardization and remediation.
  • Support regulatory, audit, and risk management initiatives by ensuring encryption controls are consistently deployed, measurable, and supported by automated compliance evidence.
  • Drive adoption of enterprise encryption services by working closely with engineering teams to modernize legacy implementations and align new solutions with approved standards.
  • Reduce the risk of inconsistent, fragmented, or non-compliant encryption implementations through standardized patterns, automated enforcement, and scalable engineering controls.
  • Minimize design exceptions, audit findings, and operational risks by embedding cryptographic controls directly into development processes rather than relying on manual reviews and remediation activities.
  • Accelerate compliant application onboarding and delivery by providing reusable security capabilities that improve both developer experience and regulatory compliance outcomes.

Qualifications

  • A security-first mindset with a passion for building secure, resilient, and scalable technology solutions.
  • A strong engineering discipline and a commitment to automation, standardization, and continuous improvement.
  • The ability to translate security requirements into practical engineering solutions that improve both security and developer experience.
  • A collaborative approach to working across cybersecurity, architecture, engineering, infrastructure, and product teams.
  • A proactive and innovative mindset focused on eliminating friction through reusable solutions, self-service capabilities, and policy-driven automation.
  • Strong analytical and problem-solving skills with the ability to identify root causes and design sustainable solutions.
  • Effective communication skills and the ability to explain complex technical concepts to both technical and non-technical stakeholders.
  • An ownership mentality that prioritizes measurable outcomes, operational excellence, and long-term sustainability.
  • A curiosity and a passion for learning in evolving areas such as cloud security, cryptography, platform engineering, DevSecOps, and software security.
  • A commitment to reducing operational risk by replacing fragmented manual processes with scalable, automated security controls.

Preferred Qualifications

  • Bachelor's degree in Computer Science, Information Security, Software Engineering, Information Technology, Cybersecurity, or a related discipline, or equivalent practical experience.
  • 8+ years of experience in software engineering, DevSecOps, platform engineering, cloud engineering, cybersecurity engineering, or a related technical field.
  • Experience integrating security controls into SDLC processes, CI/CD pipelines, and modern software delivery platforms.
  • Working knowledge of encryption technologies, cryptographic key management, secrets management, certificate lifecycle management, and enterprise data protection controls.
  • Experience implementing security automation within development pipelines using tools such as Harness, Jenkins, or similar platforms.
  • Hands-on experience with Infrastructure-as-Code technologies, including Terraform, CloudFormation, or equivalent automation frameworks.
  • Proficiency in one or more programming or scripting languages such as Python, Java, Go, C#, JavaScript, TypeScript, PowerShell, or Bash.
  • Experience with cloud platforms including Microsoft Azure, Amazon Web Services (AWS), OCI, or Google Cloud Platform (GCP).
  • Familiarity with containerization and modern platform technologies including Kubernetes, OpenShift, and cloud-native application architectures.
  • Understanding of software architecture principles, secure coding practices, application security testing, and developer enablement methodologies.
  • Knowledge of industry security and compliance frameworks such as NIST, PCI DSS, ISO 27001, or equivalent regulatory standards.
  • Experience with enterprise key management platforms, Hardware Security Modules (HSMs), cloud KMS services, secrets management platforms, or certificate management solutions is highly desirable.
  • Relevant certifications such as CISSP, CCSP, Azure Security Engineer Associate, AWS Security Specialty, Certified Kubernetes Security Specialist (CKS), or similar certifications are a plus.

Similar jobs