Encryption Agility Team Architect

Amgen Inc. (IR)

Hyderabad

On-site

INR 4,500,000 - 7,500,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Amgen Inc. in Hyderabad, India, seeks a Senior Specialist Information Security to architect and govern encryption agility for PQC readiness across enterprise systems.

You will shape reference architectures, standards, and CBOM/SBOM alignment, while coordinating with PKI, DIAS, cloud, and OT teams to implement crypto agility and secure data protection.

Qualifications

  • Expert hands-on knowledge of enterprise cryptography and security architecture.
  • Experience migrating to post-quantum cryptography and crypto‑agility patterns.
  • Ability to translate policy into enforceable technical controls across CI/CD and cloud platforms.

Responsibilities

  • Lead architecture for PQC readiness and encryption governance.
  • Define target-state architecture for encryption, PKI, and key management.
  • Translate NIST PQC guidance into reference architectures and baselines.
  • Review cryptographic discovery outputs and provide remediation guidance.
  • Collaborate with DIAS, PKI, cloud, and OT teams on certificate visibility and CLM requirements.

Skills

Enterprise cryptography
Security architecture
PKI
TLS
KMS
HSMs
SBOM/CBOM
Crypto agility
Post-quantum cryptography
Cloud security
CI/CD security

Education

Doctorate degree in Information Security/Cybersecurity
Master’s degree in Information Security/Cybersecurity
Bachelor’s degree in Information Security/CCS/Engineering
Diploma with extensive security experience

Tools

AWS KMS
AWS ACM
AWS Secrets Manager
Microsoft PKI
Sectigo
HashiCorp Vault
CLM platforms
SIEM/data lake integrations
SBOM/CycloneDX 1.6+
HSMs

Job description

ABOUT AMGEN

Amgen harnesses the best of biology and technology to fight the world's toughest diseases, and make people's lives easier, fuller and longer. We discover, develop, manufacture and deliver innovative medicines to help millions of patients. Amgen helped establish the biotechnology industry more than 40 years ago and remains on the cutting-edge of innovation, using technology and human genetic data to push beyond what's known today.

Amgen helped establish the biotechnology industry more than 40 years ago and remains on the cutting-edge of innovation, using technology and human genetic data to push beyond what's known today.

ABOUT THE ROLE

The Senior Specialist Information Security - Encryption Agility Team Architect will serve as the Principal Architect for Amgen's enterprise Encryption Agility Service for Post-Quantum Cryptography (PQC) Readiness Preparation. This role is the senior technical authority for enterprise encryption, cryptography, crypto agility, and post-quantum cryptography architecture across Amgen. The role partners with the Senior Manager Information Security - Encryption Agility Service Lead to translate Amgen's post-quantum roadmap into governed standards, reference architectures, implementation patterns, discovery requirements, remediation patterns, test plans, and production rollout guidance. The role is expected to be deeply technical and hands‑on, while also able to influence enterprise architecture, application, cloud, infrastructure, identity, Public Key Infrastructure (PKI), Key Management Services (KMS), certificate management, Digital Identity Access Services (DIAS), Operational Technology (OT), and third‑party stakeholders. The architect will define what good looks like for Amgen's 2030 quantum‑ready target state and work backward to establish the architecture, tooling, policies, and patterns needed to get there. The role will create practical architecture for the Cryptographic Bill of Materials (CBOM), cryptographic discovery, Certificate Lifecycle Management (CLM), key and secret management, algorithm transition, Steal‑Now‑Decrypt‑Later (SNDL) mitigation, Post‑Quantum Public Key Infrastructure (PQ‑PKI), hybrid Transport Layer Security (TLS), approved cryptographic libraries, and compensating controls for legacy or unchangeable applications. The individual must be comfortable reviewing source code findings, certificate chains, cipher suite data, cloud key configurations, secrets management patterns, tool integrations, and vendor cryptographic evidence. This role does not replace teams that already own infrastructure, PKI/certificates, applications, identity, cloud, or OT. Instead, it sets the architecture and technical standards for how encryption and cryptography must be used, discovered, measured, modernized, and governed across those domains, and coordinates with service owners to make the PQC transition practical, measurable, and controlled in a global, regulated environment.

ROLES & RESPONSIBILITIES
  • Serve as the Principal Architect and senior technical authority for the Encryption Agility Service, partnering with the Senior Manager to define the technical roadmap, architecture backlog, design guardrails, quality expectations, and enterprise architecture direction for Post‑Quantum Cryptography (PQC) readiness.
  • Develop Amgen’s enterprise target‑state architecture for encryption, cryptography, crypto agility, and PQC readiness across applications, cloud, infrastructure, identity, Public Key Infrastructure (PKI), Key Management Services (KMS), certificates, secrets, data protection, Software as a Service (SaaS), third‑party ecosystems, and related security configuration baselines.
  • Translate National Institute of Standards and Technology (NIST) PQC standards and related cryptography guidance into Amgen reference architectures, secure patterns, technology standards, security configuration baselines, engineering implementation guidance, and the Cryptographic Bill of Materials (CBOM) operating model and data architecture, including required fields, source systems, ownership attributes, quantum‑vulnerability status, remediation status, data quality checks, reporting views, Software Bill of Materials (SBOM) alignment, Subject Matter Expert interview inputs, and CycloneDX 1.6+ alignment.
  • Define cryptographic discovery architecture, tool integration requirements, and technical evaluation criteria across source code, binaries, cloud key services, endpoints, file systems, network traffic, PKI and certificates, KMS and secrets, vendor attestations, SBOMs, Governance, Risk, & Compliance (GRC), Security Information and Event Management (SIEM)/data lake, cryptographic discovery platforms.
  • Partner with Digital Identity Access Services Services (DIAS), PKI service owners, certificate management teams, identity teams, cloud, infrastructure, and platform teams on certificate visibility, Certificate Lifecycle Manager (CLM) requirements, Microsoft Public Key Infrastructure, Sectigo, Amazon Web Services (AWS) Certificate Manager (ACM), AWS Private Certificate Authority, hybrid certificate testing, Certificate Authority (CA) modernization, operational change windows, enterprise KMS strategy, Hardware Security Module (HSM) patterns, secrets management, key lifecycle policy, key rotation and retirement, storage standards, ownership, reporting, and centralized or federated control options.
  • Design remediation and crypto‑agility patterns for hybrid TLS, proxy‑based crypto agility, Network encapsulation, Internet Protocol Security (IPsec), Media Access Control Security (MACsec), Key Management Interoperability Protocol (KMIP), Public‑Key Cryptography Standard, provider libraries, custom code libraries, symmetric cryptography, Hash‑Based Message Authentication Code (HMAC), legacy and unchangeable applications, TLS termination, reverse proxies, encrypted overlays, segmentation controls, compensating controls, and risk‑based replacement or decommission pathways.
  • Provide hands‑on technical review of cryptographic scan outputs, source code findings, certificate chains, cipher suite configurations, Secure Shell (SSH) settings, Open Authorization (OAuth), Security Assertion Markup Language (SAML), JSON Web Token (JWT) patterns, cloud key configurations, CBOM data, key storage, secret storage, and other cryptographic implementation patterns.
  • Partner with Application Security, Artificial Intelligence (AI) Security, Enterprise Architecture, DevOps, and engineering teams to publish approved cryptographic libraries, secure code examples, reusable patterns, Continuous Integration/Continuous Delivery (CI/CD) controls, Secure Software Development Life Cycle (SSDLC) requirements, scanning rules, developer remediation playbooks, and practical guidance for data at rest, data in transit, identity protocols, Application Programming Interfaces (APIs), certificates, secrets, key stores, service‑to‑service communication, external data exchanges, and high‑value sensitive data flows.
  • Apply Amgen’s approved quantum risk‑prioritization approach to help sequence discovery and remediation for business‑critical applications, high‑volume sensitive data flows, third‑party dependencies, identity services, legacy platforms, Key Computerized Systems (KCS), validated/Good Practice (GxP) systems, and Operational Technology (OT) scope; lead architecture and design reviews for PQC pilots and trials, including test environment requirements, hybrid TLS testing, Post‑Quantum Public Key Infrastructure (PQ‑PKI) experiments, cryptographic discovery proofs of concept, CLM/KMS evaluations, algorithm interoperability, performance impact, and rollout readiness.
  • Support vendor, third‑party, OT, and manufacturing architecture governance with Procurement, Legal, Risk and Compliance, Third Party Risk Management (TPRM), business owners, and site stakeholders by defining technical questionnaire content, CBOM requests, evidence expectations, roadmap review criteria, contract language inputs, escalation triggers, passive‑only discovery assumptions, vendor firmware roadmaps, boundary architecture, validated system impacts, revalidation planning, and handoffs where direct remediation ownership remains outside the Encryption Agility Service.
  • Maintain and refresh cryptographic architecture artifacts, Security Configuration Baselines (SCBs), Standard Operating Procedures (SOPs), technical standards, exception patterns, remediation decision trees, and implementation guides; provide top‑level technical escalation for architecture exceptions, discovery tool gaps, false‑positive triage, certificate lifecycle risks, key management patterns, protocol and cipher decisions, vendor evidence gaps, and complex remediation tradeoffs; mentor Global Career Framework level 5 (L5) and Global Career Framework level 4 (L4) engineers, analysts, and contributors; and maintain awareness of Internet Engineering Task Force (IETF), National Security Agency Commercial National Security Algorithm Suite 2.0 (NSA CNSA 2.0), International Organization for Standardization (ISO), Health Insurance Portability and Accountability Act (HIPAA), Health Information Trust Alliance (HITRUST), and broader industry cryptography guidance to translate changes into Amgen architecture decisions and backlog items.
Basic Qualifications and Experience

Doctorate degree and 2 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience OR Master's degree with 8 to 10 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience OR Bachelor's degree with 10 to 14 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience OR Diploma with 14 to 18 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience

Functional Skills
Must‑Have Skills
  • Expert hands‑on knowledge of enterprise cryptography and security architecture, including PKI, X.509 certificates, TLS, cipher suites, KMS, HSMs, secrets management, key lifecycle, encryption at rest, encryption in transit, cloud key services, identity protocols, and certificate lifecycle automation.
  • Practical experience architecting cryptographic modernization, crypto agility, post‑quantum cryptography, hybrid transition patterns, discovery‑to‑remediation workflows, CBOM‑driven inventory, and Steal‑Now‑Decrypt‑Later risk reduction in a complex enterprise environment.
  • Strong ability to translate cryptographic policy and standards into enforceable technical controls across CI/CD, SSDLC, cloud platforms, PKI/certificates, KMS/secrets, identity, infrastructure, applications, third‑party governance, and risk management.
  • Ability to perform hands‑on analysis of cryptographic discovery findings, source code patterns, certificate chains, TLS/cipher data, cloud key configurations, key rotation status, secrets exposure, and architecture designs, then convert findings into practical remediation guidance.
Good‑to‑Have Skills
  • Hands‑on experience with ServiceNow CMDB/GRC, Guard, Wiz, Qualys, Fortinet, Netskope, CrowdStrike, GitLab, Veracode, GitGuardian, AWS KMS, AWS ACM, AWS Secrets Manager, Microsoft PKI, Sectigo, HashiCorp Vault, HSMs, CLM platforms, and SIEM/data lake integrations.
  • Experience designing or operating CBOM/SBOM data models using CycloneDX 1.6+, Application Programming Interfaces (APIs), Comma‑Separated Values (CSV), JavaScript Object Notation (JSON), dashboards, data quality controls, and audit‑ready reporting.
  • Experience designing PKI modernization, certificate automation, certificate rotation, Certificate Authority hierarchy changes, hybrid certificate testing, and PQ‑PKI transition plans.
  • Experience designing key management and secrets management architecture across AWS, Azure, on‑premises platforms, HSMs, Vault technologies, automation workflows, and centralized or federated operating models.
  • Experience with application security, Development, Security, and Operations (DevSecOps), SSDLC governance, CI/CD quality gates, approved cryptographic libraries, static analysis, dynamic analysis, composition analysis, and developer enablement.
  • Experience in pharmaceutical, life sciences, regulated, validated, GxP, KCS, manufacturing, OT, or other change‑controlled environments where architecture changes may trigger validation or quality review.
  • Experience with vendor and third‑party risk management, supplier cryptographic questionnaires, contract requirement inputs, roadmap evidence review, Software as a Service (SaaS) platform dependencies, and vendor escalation.
  • Scripting and automation experience with Python, PowerShell, Bash, Representational State Transfer (REST) APIs, data pipelines, parsing of certificate or scan data, or lightweight integration development.
Professional Certifications

Certified Information Systems Security Professional (CISSP) (required) Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or Certified in Risk and Information Systems Control (CRISC) (preferred) Certified Cloud Security Professional (CCSP), AWS Certified Security - Specialty, Microsoft Azure Security Engineer, or equivalent cloud security certification (preferred) The Open Group Architecture Framework (TOGAF) or Sherwood Applied Business Security Architecture (SABSA) (preferred) Information Technology Infrastructure Library (ITIL), Scaled Agile Framework (SAFe), product management, program management, or equivalent delivery certification (preferred) Relevant PKI, KMS, HSM, cryptographic discovery, certificate lifecycle management, cloud key management, or post‑quantum cryptography training/certification (preferred)

Soft Skills

Excellent analytical, troubleshooting, and problem‑solving skills. Strong technical leadership and architecture facilitation skills. Strong verbal and written communication skills for technical, business, legal, procurement, compliance, and executive audiences. Ability to translate complex cryptographic and quantum risk into clear business impact, architecture decisions, and practical remediation options. Ability to influence without direct authority across global security, Digital, Technology and Innovation (DTI), DIAS, procurement, legal, compliance, OT, infrastructure, cloud, and application teams. High degree of initiative, accountability, judgment, and self‑motivation in ambiguous or evolving technical domains. Ability to manage multiple architecture priorities, competing stakeholder needs, and long‑running transformation roadmaps successfully. Team oriented, with a focus on shared outcomes, reusable patterns, practical implementation, and service maturity. Ability to balance hands‑on technical analysis with enterprise architecture leadership and service governance. Strong coaching and mentoring skills for Global Career Framework level 5 (L5) and Global Career Framework level 4 (L4) engineers, analysts, and technical contributors. Strong presentation, documentation, and public speaking skills for architecture forums, technical reviews, and leadership updates. Comfort building a new enterprise capability and helping mature operating models, architecture governance, metrics, and standards from the ground up.

EQUAL OPPORTUNITY STATEMENT

Amgen is an Equal Opportunity employer and will consider you without regard to your race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status. We will ensure that individuals with disabilities are provided with reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request an accommodation. . Amgen is committed to unlocking the potential of biology for patients suffering from serious illnesses by discovering, developing, manufacturing and delivering innovative human therapeutics. This approach begins by using tools like advanced human genetics to unravel the complexities of disease and understand the fundamentals of human biology. Amgen focuses on areas of high unmet medical need and leverages its biologics manufacturing expertise to strive for solutions that improve health outcomes and dramatically improve people's lives. A biotechnology pioneer since 1980, Amgen has grown to be one of the world's leading independent biotechnology companies, has reached millions of patients around the world and is developing a pipeline of medicines with breakaway potential. For more information, visit www.amgen.com and follow us on www.twitter.com/amgen

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Encryption Agility Engineer
Encryption Agility Engineer

Amgen Inc. (IR) • Hyderabad

On-site
INR 1,800,000 - 3,000,000
Encryption Agility Service Lead
Encryption Agility Service Lead

Amgen Inc. (IR) • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Encryption Agility Analyst
Encryption Agility Analyst

Amgen Inc. (IR) • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Encryption Agility Team Architect
Encryption Agility Team Architect

Amgen • Hyderabad

On-site
INR 3,500,000 - 6,500,000
Encryption Agility Service Lead
Encryption Agility Service Lead

Amgen • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Encryption Agility Engineer
Encryption Agility Engineer

Amgen • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Encryption Agility Analyst
Encryption Agility Analyst

Amgen • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Principal Solution Architect
Principal Solution Architect

Amgen Inc. (IR) • Hyderabad

On-site
INR 3,500,000 - 6,500,000
Data & Information Architect
Data & Information Architect

Amgen Inc. (IR) • Hyderabad

On-site
INR 2,000,000 - 3,500,000
Equal Opportunity Employer
Sr. Manager, Data Architecture
Sr. Manager, Data Architecture

Amgen Inc. (IR) • Hyderabad

On-site
INR 4,500,000 - 6,500,000