Head of Cryptography, MD
State Street · Clifton, NJ · 2 days ago
OTHR$175k–$288k/yrFull-time
About the role
The Managing Director, Head of Cryptography is a senior leadership role responsible for defining, governing, and advancing the firm's enterprise cryptography, key management, secrets management, and cryptographic modernization strategy.
Responsibilities
- Define and execute the firm's comprehensive cryptography strategy, roadmap, and governance framework.
- Cover encryption at rest, encryption in transit, key management, secrets management, certificate management, digital signatures, tokenization, hardware security modules (HSMs), and cryptographic agility.
- Develop executive-level metrics and reporting that provide visibility into cryptographic maturity, risk exposure, and modernization progress.
- Lead enterprise initiatives to modernize the firm's cryptographic infrastructure and services.
- Partner with engineering teams to ensure cryptographic controls remain scalable, performant, and developer-friendly.
- Establish and operate enterprise-class key management services supporting the firm's most critical systems and data.
- Drive adoption of automated key lifecycle capabilities, including automated provisioning, rotation, revocation, expiration management, and recovery procedures.
- Enable cryptographic controls into enterprise platforms, multi-cloud environments, SaaS platforms, containerized workloads, Kubernetes environments, and modern application architectures.
- Develop a roadmap that reduces operational complexity while improving security resilience across all environments.
- Develop and modernize the firm's machine identity strategy.
- Lead efforts to secure and manage certificates, APIs, service accounts, workload identities, non-human identities, and infrastructure identities.
- Implement cryptographic agility standards and establish migration roadmaps.
- Provide executive guidance on evolving industry standards and regulatory expectations related to quantum readiness.
- Establish enterprise-wide processes for assessing cryptographic risks and control effectiveness.
- Evaluate implementation quality, assess key management maturity, measure cryptographic coverage, and prioritize remediation by risk.
- Engage with executive leadership, regulators, auditors, and major clients.
- Translate highly technical cryptographic concepts into practical business decisions and investment priorities.
- Influence enterprise architecture, platform strategy, cloud adoption, and modernization efforts through cryptographic expertise.
- Build strong partnerships across Security, Technology, Infrastructure, Data, Risk, and Compliance organizations.
- Develop technical talent and create a culture focused on engineering excellence, automation, innovation, and operational resilience.
- Act as the firm's senior cryptographic authority and mentor for engineering and security leaders.
Qualifications
- 15+ years of experience in cybersecurity, cryptography, security engineering, or infrastructure security leadership roles.
- Demonstrated success leading enterprise cryptography or key management programs within large, highly regulated organizations.
- Deep expertise in applied cryptography, PKI, key management, HSM technologies, secrets management, certificate lifecycle management, and cloud security architectures.
- Experience designing cryptographic controls across cloud-native, hybrid, and distributed environments.
- Strong understanding of post-quantum cryptography strategies and emerging cryptographic standards.
- Proven track record leading large-scale modernization and transformation initiatives.
- Experience engaging with executive leadership, regulators, auditors, and major clients.
- Bachelor's degree in Computer Science, Engineering, Information Security, Mathematics, or related discipline.
- Advanced degree preferred.
- Relevant certifications such as CISSP, CCSP, CISM, GCFA, or specialized cryptography/security certifications are highly desirable.