Encryption Agility Team Architect
Amgen · India - Hyderabad
Job description
Career CategoryInformation SystemsJob DescriptionRole Name: Principal Information Security Architect - Encryption Agility Team Job Posting Title: Senior Specialist Information Security - Encryption Agility Team Architect Workday Job Title: Senior Specialist Information Security Department Name: Trusted Core Technologies Role GCF: 6A ABOUT AMGEN Amgen harnesses the best of biology and technology to fight the world's toughest diseases, and make people's lives easier, fuller and longer. We discover, develop, manufacture and deliver innovative medicines to help millions of patients. Amgen helped establish the biotechnology industry more than 40 years ago and remains on the cutting-edge of innovation, using technology and human genetic data to push beyond what's known today. ABOUT THE ROLE Role Description: The Senior Specialist Information Security - Encryption Agility Team Architect will serve as the Principal Architect for Amgen's enterprise Encryption Agility Service for Post-Quantum Cryptography (PQC) Readiness Preparation. This role is the senior technical authority for enterprise encryption, cryptography, crypto agility, and post-quantum cryptography architecture across Amgen. The role partners with the Senior Manager Information Security - Encryption Agility Service Lead to translate Amgen's post-quantum roadmap into governed standards, reference architectures, implementation patterns, discovery requirements, remediation patterns, test plans, and production rollout guidance. The role is expected to be deeply technical and hands-on, while also able to influence enterprise architecture, application, cloud, infrastructure, identity, Public Key Infrastructure (PKI), Key Management Services (KMS), certificate management, Digital Identity Access Services (DIAS), Operational Technology (OT), and third-party stakeholders. The architect will define what good looks like for Amgen's 2030 quantum-ready target state and work backward to establish the architecture, tooling, policies, and patterns needed to get there. The role will create practical architecture for the Cryptographic Bill of Materials (CBOM), cryptographic discovery, Certificate Lifecycle Management (CLM), key and secret management, algorithm transition, Steal-Now-Decrypt-Later (SNDL) mitigation, Post-Quantum Public Key Infrastructure (PQ-PKI), hybrid Transport Layer Security (TLS), approved cryptographic libraries, and compensating controls for legacy or unchangeable applications. The individual must be comfortable reviewing source code findings, certificate chains, cipher suite data, cloud key configurations, secrets management patterns, tool integrations, and vendor cryptographic evidence. This role does not replace teams that already own infrastructure, PKI/certificates, applications, identity, cloud, or OT. Instead, it sets the architecture and technical standards for how encryption and cryptography must be used, discovered, measured, modernized, and governed across those domains, and coordinates with service owners to make the PQC transition practical, measurable, and controlled in a global, regulated environment. Roles & Responsibilities: Serve as the Principal Architect and senior technical authority for the Encryption Agility Service, partnering with the Senior Manager to define the technical roadmap, architecture backlog, design guardrails, quality expectations, and enterprise architecture direction for Post-Quantum Cryptography (PQC) readiness. Develop Amgen’s enterprise target-state architecture for encryption, cryptography, crypto agility, and PQC readiness across applications, cloud, infrastructure, identity, Public Key Infrastructure (PKI), Key Management Services (KMS), certificates, secrets, data protection, Software as a Service (SaaS), third-party ecosystems, and related security configuration baselines. Translate National Institute of Standards and Technology (NIST) PQC standards and related cryptography guidance into Amgen reference architectures, secure patterns, technology standards, security configuration baselines, engineering implementation guidance, and the Cryptographic Bill of Materials (CBOM) operating model and data architecture, including required fields, source systems, ownership attributes, quantum-vulnerability status, remediation status, data quality checks, reporting views, Software Bill of Materials (SBOM) alignment, Subject Matter Expert interview inputs, and CycloneDX 1.6+ alignment. Define cryptographic discovery architecture, tool integration requirements, and technical evaluation criteria across source code, binaries, cloud key services, endpoints, file systems, network traffic, PKI and certificates, KMS and secrets, vendor attestations, SBOMs, Governance, Risk, and Compliance (GRC), Security Information and Event Management (SIEM)/data lake, cryptographic discovery platforms. Partner with Digital Identity Access Services Services (DIAS), PKI service owners, certificate management teams, identity teams, cloud, infrastructure, and platform teams on certificate visibility, Certificate Lifecycle Manager (CLM) requirements, Microsoft Public Key Infrastructure, Sectigo, Amazon Web Services (AWS) Certificate Manager (ACM), AWS Private Certificate Authority, hybrid certificate testing, Certificate Authority (CA) modernization, operational change windows, enterprise KMS strategy, Hardware Security Module (HSM) patterns, secrets management, key lifecycle policy, key rotation and retirement, storage standards, ownership, reporting, and centralized or federated control options. Design remediation and crypto-agility patterns for hybrid TLS, proxy-based crypto agility, Network encapsulation, Internet Protocol Security (IPsec), Media Access Control Security (MACsec), Key Management Interoperability Protocol (KMIP), Public-Key Cryptography Standard, provider libraries, custom code libraries, symmetric cryptography, Hash-Based Message Authentication Code (HMAC), legacy and unchangeable applications, TLS termination, reverse proxies, encrypted overlays, segmentation controls, compensating controls, and risk-based replacement or decommission pathways. Provide hands-on technical review of cryptographic scan outputs, source code findings, certificate chains, cipher suite configurations, Secure Shell (SSH) settings, Open Authorization (OAuth), Security Assertion Markup Language (SAML), JSON Web Token (JWT) patterns, cloud key configurations, CBOM data, key storage, secret storage, and other cryptographic implementation patterns. Partner with Application Security, Artificial Intelligence (AI) Security, Enterprise Architecture, DevOps, and engineering teams to publish approved cryptographic libraries, secure code examples, reusable patterns, Continuous Integration/Continuous Delivery (CI/CD) controls, Secure Software Development Life Cycle (SSDLC) requirements, scanning rules, developer remediation playbooks, and practical guidance for data at rest, data in transit, identity protocols, Application Programming Interfaces (APIs), certificates, secrets, key stores, service-to-service communication, external data exchanges, and high-value sensitive data flows. Apply Amgen’s approved quantum risk-prioritization approach to help sequence discovery and remediation for business-critical applications, high-volume sensitive data flows, third-party dependencies, identity services, legacy platforms, Key Computerized Systems (KCS), validated/Good Practice (GxP) systems, and Operational Technology (OT) scope; lead architecture and design reviews for PQC pilots and trials, including test environment requirements, hybrid TLS testing, Post-Quantum Public Key Infrastructure (PQ-PKI) experiments, cryptographic discovery proofs of concept, CLM/KMS evaluations, algorithm interoperability, performance impact, and rollout readiness. Support vendor, third-party, OT, and manufacturing architecture governance with Procurement, Legal, Risk and Compliance, Third Party Risk Management (TPRM), busines
Verified and listed by ActiveJobs. Applications are made directly on Amgen's own career page — we never sit in the middle.