Encryption Program Analyst, AVP, Hybrid
State StreetAbout the role
Who we are looking for
State Street is seeking an experienced Encryption Program Analyst, AVP to help design, implement, and optimize enterprise-wide encryption and key management solutions across cloud, on-premises, and IoT environments in a highly regulated environment. This role will be responsible for defining cryptographic strategies, ensuring compliance with regulatory standards, and leading the integration of encryption services across a diverse infrastructure.
As a financial institution increasingly adopting hybrid cloud and IoT-enabled banking solutions, this role will play a critical part in securing data at rest, in transit, and in use, ensuring end-to-end cryptographic protection across applications, infrastructure, and connected devices. The ideal candidate will have deep expertise in cryptographic key management, Hardware Security Modules (HSMs), cloud security, IoT encryption protocols, and enterprise data protection.
Why this role is important to us
Our technology function, Global Technology Services (GTS), is vital to State Street and is the key enabler for our business to deliver data and insights to our clients. We’re driving the company’s digital transformation and expanding business capabilities using industry best practices and advanced technologies such as cloud, artificial intelligence and robotics process automation.
We offer a collaborative environment where technology skills and innovation are valued in a global organization. We’re looking for top technical talent to join our team and deliver creative technology solutions that help us become an end-to-end, next-generation financial services company.
What you will be responsible for
As an Encryption Analyst you will:
- Implement and maintain the enterprise cryptographic strategy, ensuring alignment with security, compliance, and business objectives.
- Define and maintain key lifecycle management processes and procedures, including key generation, rotation, revocation, and decommissioning for cloud, on-premises, and IoT environments.
- Support the deploy of centralized Key Management Systems (KMS), including cloud-native KMS (AWS KMS, Azure Key Vault, OCI KMS), and enterprise HSMs
- Ensure robust data encryption methodologies are applied to data stored in databases, applications, and IoT connected devices.
- Collaborate with cloud security and DevSecOps teams to integrate encryption and key management into CI/CD pipelines and Infrastructure as Code (IaC) deployments.
- Develop IoT encryption frameworks to secure IoT devices.
- Support the integration of encryption solutions into applications, databases, cloud services, IoT platforms, and enterprise infrastructure.
- Collaborate with application security, infrastructure, and DevSecOps teams to embed cryptographic security controls into software development and deployment processes.
- Support post-quantum cryptography (PQC) readiness by evaluating and preparing for emerging threats to encryption security.
- Ensure compliance with NIST 800-57, PCI DSS, FIPS 140-2/3, ISO 27001, GDPR, FFIEC, and IoT security (NIST 800-183, ETSI EN 303 645).
- Developing governance frameworks for encryption and cryptographic key management, including policies for key storage, access control, logging, and auditing.
- Conduct risk assessments, vulnerability testing, and security reviews for cryptographic implementations, IoT ecosystems, and cloud security controls.
- Act as a key stakeholder in security audits, regulatory assessments, and IoT security standardization efforts.
- Provide Technical support and training to internal teams on encryption best practices, cloud security, and IoT security.
- Stay ahead of advancements in cryptographic algorithms, quantum computing risks, and emerging IoT security frameworks.
- Drive innovation in encryption automation, integrating key management with DevSecOps, and Infrastructure as Code (IaC).
What we value
These skills will help you succeed in this role
- Strong proficiency in Python, PowerShell, Bash, or Java.
- Understanding of cryptographic algorithms (AES, RSA, ECC), hardware security modules (HSMs), and secure key storage practices.
- Experience working in financial institutions or other highly regulated industries.
- Hands-on Experience with key management systems (Fortanix, ASW KMS, Azure Key Vault, OCI KMS).
- Experience with Kubernetes, Terraform, Ansible, Chef, and CI/CD automation.
Education & Preferred Qualifications
- You have multiyear (>4 years) experience within Cybersecurity including SecOps, Cloud Security, and secure architecture.
- Bachelor's Degree in Computer Science/Engineering, related discipline, or equivalent work experie
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Lead Information Security Engineer - Data at Rest Encryption Infrastructure Engineering and Delivery
Wells Fargo
$224,000/yr
Information Security Analyst Senior (Encryption/KMI) (5458) (TS/SCI CI Poly) (Ft. Bragg, NC)
smxtech
Staff Technical Program Manager, Queryable Encryption
mongodb