Match score not available

Engineering Lead – Key Management

Remote: 
Full Remote
Contract: 
Salary: 
130 - 205K yearly
Experience: 
Senior (5-10 years)

Offer summary

Qualifications:

Bachelor's degree in Computer Science or related field, Strong proficiency in Python, PowerShell, or Java, Experience with RESTful APIs and key management systems, Familiarity with PKI automation and cryptographic algorithms.

Key responsabilities:

  • Lead a team in cryptographic solutions
  • Collaborate with stakeholders on key management strategies
  • Design integrations for key management systems
  • Develop APIs and automate key processes

Charles River Development logo
Charles River Development https://www.crd.com
1001 - 5000 Employees
See all jobs

Job description

Who we are looking for

State Street is seeking a skilled Engineering Lead – Key Management with expertise in cryptographic key and certificate management to design, develop, and maintain automation solutions that enhance the security, efficiency, and scalability of our enterprise cryptographic infrastructure.  This role will focus on integrating key management systems (KMS), public key infrastructure (PKI), and hardware security modules (HSMs) with enterprise applications, cloud environments, IoT and DevSecOps workflows.

The Ideal candidate has experience with the secure automation, scripting, API development, and integrating cryptographic solutions within financial or highly regulated environments.

This role can be performed in a hybrid model, where you can balance work from home and office to match your needs and role requirements.

What you will be responsible for

  • Lead a team of developers and engineers in designing and implementing cryptographic automation and integrations solutions.
  • Provide technical direction and mentorship, ensuring best practices in secure coding, automation, and cryptographic integrations.
  • Collaborate with senior stakeholders, including security architects, compliance teams, and DevSecOps leads to define and drive key management strategies.
  • Design and implement integrations between cryptographic key and certificate management systems and enterprise applications, cloud platforms, and security tools.
  • Develop and maintain APIs, microservices, and automation scripts to streamline cryptographic operations.
  • Enable seamless integration with multi-cloud key management services (AWS KMS, Azure Key Vault, OCI KMS)
  • Collaborate with security architects, application teams, and DevSecOps engineers to embed encryption and certificate management into CI/CD pipelines.
  • Automate key lifecycle processes such as key generation, rotation, distribution, revocation and decommissioning.
  • Implement certificate automation solutions (ACME protocol, automated issuance/renewal via API-driven PKI).
  • Build monitoring and alerting mechanisms to detect cryptographic anomalies and improve operational efficiency.
  • Ensure automation and integrations align with cryptographic policies, compliance and regulations (PCI DSS, GDPR, FIPS 140-2/3), and security best practices.
  • Work closely with risk and compliance teams to provide audit trails and access control mechanisms for key and certificate operations.
  • Assist in vulnerability management and patching of cryptographic components and automation workflows.
  • Troubleshoot integration and automation issues, ensuring high availability and reliability of cryptographic services.
  • Stay up to date on emerging encryption technologies, cloud security trends, and automation frameworks.
  • Provide technical documentation and training for internal teams on cryptographic integration best practices.

Education & Preferred Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field. Advanced degree or certifications (e.g., CISSP, CISM) preferred or equivalent work experience.
  • Strong proficiency in Python, PowerShell, Bash, or Java for automation and integrations.
  • Experience with RESTful APIs, JSON, XML, and WebSockets to integrate key management solutions
  • Hands-on Experience with key management systems (HashiCorp Vault, ASW KMS, Azure Key Vault, OCI KMS).
  • Familiarity with X.509 certificates, PKI automation, TLS/SSL, ACME protocol, and certificate lifecycle management.
  • Experience with Kubernetes, Terraform, Ansible, Chef, and CI/CD automation.
  • Understanding of cryptographic algorithms (AES, RSA, ECC), hardware security modules (HSMs), and secure key storage practices.
  • Experience working in financial institutions or other highly regulated industries.
  • Knowledge of blockchain technology and its cryptographic principles is a plus.
  • Certifications such as CISSP, CISM, AWS Security Specialty, HashiCorp Certified Vault Associate or CCSK.
  • Familiarity with security frameworks such as NIST 800-57, ISO 27001 or PCI DSS.

Are you the right candidate? Yes!

We truly believe in the power that comes from the diverse backgrounds and experiences our employees bring with them. Although each vacancy details what we are looking for, we don’t necessarily need you to fulfil all of them when applying. If you like change and innovation, seek to see the bigger picture, make data driven decisions and are a good team player, you could be a great fit.

Why this role is important to us

Our technology function, Global Technology Services (GTS), is vital to State Street and is the key enabler for our business to deliver data and insights to our clients. We’re driving the company’s digital transformation and expanding business capabilities using industry best practices and advanced technologies such as cloud, artificial intelligence and robotics process automation.

We offer a collaborative environment where technology skills and innovation are valued in a global organization. We’re looking for top technical talent to join our team and deliver creative technology solutions that help us become an end-to-end, next-generation financial services company.

Join us if you want to grow your technical skills, solve real problems and make your mark on our industry.

About State Street

What we do. State Street is one of the largest custodian banks, asset managers and asset intelligence companies in the world. From technology to product innovation, we’re making our mark on the financial services industry. For more than two centuries, we’ve been helping our clients safeguard and steward the investments of millions of people. We provide investment servicing, data & analytics, investment research & trading and investment management to institutional clients.

Work, Live and Grow. We make all efforts to create a great work environment. Our benefits packages are competitive and comprehensive. Details vary by location, but you may expect generous medical care, insurance and savings plans, among other perks. You’ll have access to flexible Work Programs to help you match your needs. And our wealth of development programs and educational support will help you reach your full potential.

Inclusion, Diversity and Social Responsibility. We truly believe our employees’ diverse backgrounds, experiences and perspectives are a powerful contributor to creating an inclusive environment where everyone can thrive and reach their maximum potential while adding value to both our organization and our clients. We warmly welcome candidates of diverse origin, background, ability, age, sexual orientation, gender identity and personality. Another fundamental value at State Street is active engagement with our communities around the world, both as a partner and a leader. You will have tools to help balance your professional and personal life, paid volunteer days, matching gift programs and access to employee networks that help you stay connected to what matters to you.

State Street is an equal opportunity and affirmative action employer.

Salary Range:

$130,000 - $205,000 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

State Street's Speak Up Line

Required profile

Experience

Level of experience: Senior (5-10 years)
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Team Leadership
  • Collaboration
  • Mentorship
  • Problem Solving

Related jobs