Head of Cryptography, MD
State Street · Princeton, NJ · 2 days ago
OTHR$175k–$288k/yrFull-time
About the role
The Managing Director, Head of Cryptography is a senior leadership role responsible for defining, governing, and advancing the firm's enterprise cryptography, key management, secrets management, and cryptographic modernization strategy.
Responsibilities
- Define and execute the firm's comprehensive cryptography strategy, roadmap, and governance framework.
- Establish Enterprise Standards And Policies Covering Encryption at rest Encryption in transit Key management Secrets management Certificate management Digital signatures Tokenization Hardware Security Modules (HSMs) Cryptographic agility
- Ensure cryptographic capabilities support business growth, regulatory expectations, cloud transformation, and emerging technology adoption.
- Develop executive-level metrics and reporting that provide visibility into cryptographic maturity, risk exposure, and modernization progress.
- Lead enterprise initiatives to modernize the firm's cryptographic infrastructure and services.
- Drive Programs Focused On Cryptographic inventory and visibility Legacy algorithm remediation Deprecation of weak cryptographic standards Secure migration strategies Cryptographic agility Automated cryptographic lifecycle management
- Partner with engineering teams to ensure cryptographic controls remain scalable, performant, and developer-friendly.
- Establish and operate enterprise-class key management services supporting the firm's most critical systems and data.
- Lead Strategy And Execution Across Enterprise Key Management Systems (KMS) Hardware Security Modules (HSM) Secrets vaults Machine identity management Certificate lifecycle management Service-to-service authentication
- Drive Adoption Of Automated Key Lifecycle Capabilities, Including Automated provisioning Automated rotation Revocation Expiration management Recovery procedures
- Reduce operational risk through consistent, centralized, and automated cryptographic controls.
- Enable cryptographic controls into enterprise platforms.
- Develop and modernize the firm's machine identity strategy.
- Drive automation to eliminate manual certificate and identity management processes wherever possible.
- Lead the firm's post-quantum cryptography strategy.
- Develop Capabilities To Inventory cryptographic dependencies Assess quantum risk exposure Prioritize remediation efforts Establish migration roadmaps Implement cryptographic agility standards
- Partner with Enterprise Architecture and Technology leadership to ensure long-term resilience against emerging cryptographic threats.
- Provide executive guidance on evolving industry standards and regulatory expectations related to quantum readiness.
- Establish enterprise-wide processes for assessing cryptographic risks and control effectiveness.
- Drive Initiatives To Identify cryptographic gaps Evaluate implementation quality Assess key management maturity Measure cryptographic coverage Prioritize remediation by risk
- Develop governance mechanisms that ensure adherence to enterprise cryptographic standards across all technology domains.
- Ensure cryptographic controls align with regulatory, client, and industry expectations.
- Support Compliance With Frameworks Including FFIEC NIST ISO 27001 PCI DSS NYDFS GDPR SEC requirements
- Serve as the senior cryptography subject matter expert during regulatory examinations, internal audits, client assessments, and control reviews.
- Provide clear and defensible narratives regarding cryptographic controls, key management practices, and risk mitigation strategies.
- Serve as a trusted advisor to the CISO, CIO, CTO, Chief Data Officer, and senior technology leadership.
- Translate highly technical cryptographic concepts into practical business decisions and investment priorities.
- Influence enterprise architecture, platform strategy, cloud adoption, and modernization efforts through cryptographic expertise.
- Build strong partnerships across Security, Technology, Infrastructure, Data, Risk, and Compliance organizations.
- Build And Lead a World-class Cryptography Organization Responsible For Cryptography Engineering Key Management Services Secrets Management PKI Operations Machine Identity Security Cryptographic Modernization Post-Quantum Readiness
- Develop technical talent and create a culture focused on engineering excellence, automation, innovation, and operational resilience.
- Act as the firm's senior cryptographic authority and mentor for engineering and security leaders.
Qualifications
- 15+ years of experience in cybersecurity, cryptography, security engineering, or infrastructure security leadership roles.
- Demonstrated success leading enterprise cryptography or key management programs within large, highly regulated organizations.
- Deep expertise in: Applied cryptography PKI Key management HSM technologies Secrets management Certificate lifecycle management Cloud security architectures.
- Experience designing cryptographic controls across cloud-native, hybrid, and distributed environments.
- Strong understanding of post-quantum cryptography strategies and emerging cryptographic standards.
- Proven track record leading large-scale modernization and transformation initiatives.
- Experience engaging with executive leadership, regulators, auditors, and major clients.
- Recognized industry expert in cryptography and cryptographic security services.
- Strong technical depth combined with executive-level communication skills.
- Strategic thinker capable of balancing innovation, resilience, and operational effectiveness.
- Passion for automation, simplification, and engineering excellence.
- Strong understanding of cloud, identity, infrastructure, and modern application architectures.
- Ability to influence enterprise-wide technology decisions.
- Risk-focused mindset with strong governance and control discipline.
- Trusted leader with a track record of building and scaling high-performing technical organizations.
- Bachelor's degree in Computer Science, Engineering, Information Security, Mathematics, or related discipline. Advanced degree preferred.
- Relevant certifications such as CISSP, CCSP, CISM, GCFA, or specialized cryptography/security certifications are highly desirable.