Title: Information Security Analyst 4 - Cryptography
Location: Charlotte, NC
Work Arrangement: Hybrid
Duration: 12+ months contract with potential extension
Outstanding long-term contract opportunity! A well-known Financial Services Company is looking for a Information Security Analyst in Charlotte, NC (Hybrid).
Work with the brightest minds at one of the largest financial institutions in the world. This is a long-term contract opportunity that includes a competitive benefit package! Our client has been around for over 150 years and is continuously innovating in today's digital age. If you want to work for a company that is not only a household name, but also truly cares about satisfying customers' financial needs and helping people succeed financially.
Required Skills & Experience
- 5+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work or consulting experience, training, military experience, education.
- 7+ years of experience in Information Security, Cryptography, PKI, Encryption, Key Management, or related cybersecurity disciplines within the financial services industry.
- Deep expertise in Public Key Infrastructure (PKI) and Digital Certificate Lifecycle Management.
- Strong knowledge of cryptographic principles, algorithms, encryption technologies, and key management processes.
- Experience managing and governing certificate discovery and automation platforms such as Venafi, Keyfactor, DigiCert, or similar technologies.
- Strong understanding of Hardware Security Modules (HSMs), including deployment architectures, key protection mechanisms, and operational controls.
- Strong understanding of regulatory, audit, and compliance requirements applicable to cryptographic controls within financial institutions.
- Experience conducting cryptographic risk assessments and remediation planning.
- Experience analyzing large datasets to identify risk exposure, policy non-adherence, and operational improvement opportunities.
- Strong written and verbal communication skills with the ability to communicate effectively with technical teams, risk partners, auditors, and executive leadership.
Desired Skills & Experience
- Expertise in emerging cryptographic standards and Post-Quantum Cryptography (PQC) readiness planning.
- Experience with cloud-native cryptographic services and enterprise key management solutions.
- Experience designing and implementing governance automation solutions.
- Experience with enterprise analytics and visualization platforms such as MS Power Platform, Tableau and ServiceNow Platform Analytics.
- Experience with configuration management and asset inventory platforms, including ServiceNow CMDB and Venafi datasets.
- Knowledge of AI-assisted automation, large language models, and workflow integration capabilities.
- Relevant industry certifications such as CISSP, CCSP, CISM, CRISC, GCLD, GDSA, GLEG, GPCS, GCSA, GCLA,
What You Will Be Doing
- Consult on complex initiatives with broad impact and large-scale planning for Information Security Analysis.
- Review and analyze complex multi-faceted, larger scale or longer-term Information Security Analysis challenges that require in-depth evaluation of multiple factors including intangibles or unprecedented factors.
- Contribute to the resolution of complex and multi-faceted situations requiring solid understanding of the function, policies, procedures, and compliance requirements that meet deliverables.
- Strategically collaborate and consult with client personnel.
- Serve as a lead subject matter expert for enterprise cryptography, encryption technologies, PKI, certificate lifecycle management, and key management practices.
- Provide strategic guidance and technical leadership for digital certificate governance across the enterprise.
- Partner with application, infrastructure, cloud, and security engineering teams to design secure cryptographic solutions and address complex technical challenges.
- Develop and maintain governance frameworks, standards, policies, and control requirements related to cryptographic technologies.
- Assess cryptographic implementations and identify risks associated with certificate management, key management, encryption controls, and trust architectures.
- Lead risk assessments and provide recommendations for mitigating cryptographic vulnerabilities and control weaknesses.
- Support internal audit, regulatory examinations, and risk management activities involving cryptographic controls and key management practices.
- Monitor emerging cryptographic threats and evaluate organizational readiness for evolving standards, including Post-Quantum Cryptography (PQC).
- Provide expertise related to Hardware Security Modules (HSMs), including architecture, deployment patterns, key custody, and operational controls.
- Lead strategic initiatives to improve digital certificate discovery, inventory management, governance, and lifecycle automation.
- Evaluate and optimize enterprise certificate lifecycle management platforms including Venafi, Keyfactor, DigiCert, and related technologies.
- Analyze large-scale cryptographic, certificate, and asset datasets to identify risk trends, compliance gaps, and opportunities for operational improvement.
- Design and implement automation solutions that enhance governance visibility, policy adherence monitoring, and remediation tracking.
- Leverage AI-assisted tools, where appropriate and approved, to improve analysis, investigations, reporting, and operational efficiency.
- Mentor and provide technical guidance to cybersecurity analysts, engineers, architects, and leadership teams.
- Influence enterprise cryptographic strategy, technology roadmaps, and modernization efforts.
- Act as the primary technical escalation point for highly complex cryptographic and PKI-related issues.
- Drive continuous improvement initiatives that enhance the firm's cryptographic risk posture.
- Influence enterprise architecture and technology decisions involving cryptographic controls and trust services.
- Establish trusted partnerships across Cybersecurity, Technology Infrastructure, Architecture, Engineering, Risk, Audit, and Regulatory teams.
- Translate complex cryptographic concepts into clear business outcomes and actionable risk decisions.
- Lead initiatives that improve automation, governance maturity, operational resilience, and audit readiness.