Encryption Agility Engineer
Core
Senior hands-on engineer building and operating Amgen's enterprise Encryption Agility Service for Post-Quantum Cryptography (PQC) readiness, managing cryptographic inventory, discovery workflows, and remediation.
Role type
Senior IC encryption agility engineer
Builds
Enterprise cryptographic inventory, Cryptographic Bill of Materials (CBOM), discovery workflows, remediation tracking, and engineering guidance
Domain
Biotechnology / Information Security / Cryptography
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Enterprise cryptography, PKI, X.509 certificates, TLS, cipher suites, KMS, HSMs, secrets management, key lifecycle, encryption at rest, encryption in transit, cloud key services, identity protocols, certificate lifecycle automation, cryptographic discovery, CBOM-driven inventory, source code scanning, network and endpoint telemetry, cloud key service analysis, false-positive triage, data quality controls, dashboards, remediation tracking
Preferred skills
CycloneDX 1.6+, SBOM inputs, quantum-vulnerability status, hybrid TLS, proxy-based crypto agility, IPsec, MACsec, KMIP, PKCS#11, provider libraries, symmetric cryptography, HMAC, TLS termination, reverse proxies, encrypted overlays, segmentation controls, compensating controls, Certificate Lifecycle Manager (CLM), Certificate Authority (CA) modernization, Hardware Security Module (HSM) patterns, secrets management, key rotation, key retirement, storage standards, centralized or federated control options, CI/CD controls, Secure Software Development Life Cycle (SSDLC) requirements, scanning rules, developer remediation playbooks, quantum risk-prioritization, GxP systems, OT scope, vendor and third-party technical governance, NIST, IETF, NSA CNSA 2.0, ISO, HIPAA, HITRUST
Technologies
CycloneDX 1.6+, SBOM, TLS, SSH, OAuth, SAML, JWT, KMIP, PKCS#11, HSM, CLM, KMS
Responsibilities
Execute Encryption Agility Service workstreams including intake analysis, backlog execution, roadmap tracking, service metrics, reporting inputs, SOP updates, and service improvement actions. Operate enterprise cryptographic discovery across source code, binaries, cloud key services, endpoints, file systems, network traffic, PKI, certificates, KMS, secrets, vendor attestations, and SBOM inputs. Build and maintain the Amgen CBOM using CycloneDX 1.6+ including required fields, source systems, ownership attributes, quantum-vulnerability status, remediation status, data quality checks, reporting views, and asset correlation. Support tool integration and data normalization across Amgen Enterprise and cryptographic discovery platforms. Analyze cryptographic scan outputs, source code findings, certificate chains, cipher suite configurations, TLS/SSH settings, OAuth/SAML/JWT patterns, cloud key configurations, and key/secret storage patterns. Implement and document remediation patterns including hybrid TLS, proxy-based crypto agility, Network encapsulation, IPsec, MACsec, KMIP, PKCS#11, provider libraries, custom code libraries, symmetric cryptography, HMAC, TLS termination, reverse proxies, encrypted overlays, segmentation controls, compensating controls, and risk-based replacement or decommission pathways. Coordinate with DIAS, PKI service owners, certificate management teams, identity teams, cloud, infrastructure, and platform teams on certificate visibility, CLM evaluation, certificate rotation, manual-to-automated deployment migration, post-quantum PKI readiness, hybrid certificate testing, CA modernization, KMS strategy, HSM patterns, secrets management, key rotation, key retirement, storage standards, ownership, reporting, and centralized or federated control options. Partner with Application Security, AI Security, Enterprise Architecture, DevOps, and engineering teams to publish approved cryptographic libraries, secure code examples, reusable patterns, CI/CD controls, SSDLC requirements, scanning rules, developer remediation playbooks, and practical implementation guidance. Apply Amgen's approved quantum risk-prioritization approach to discovery and remediation planning for business-critical applications, high-volume sensitive data flows, third-party dependencies, identity services, legacy platforms, Key Computerized Systems (KCS), validated GxP systems, and OT scope. Support vendor and third-party technical governance with Procurement, Legal, Risk and Compliance, TPRM, and business owners by preparing technical questionnaire content, CBOM requests, evidence reviews, roadmap tracking, contract language inputs, escalation triggers, and supplier remediation follow-up. Provide technical escalation and mentoring for Global Career Framework level 4 (L4) analysts and contributors, maintain cryptographic knowledge articles and implementation guides, and track changes in NIST, IETF, NSA CNSA 2.0, ISO, HIPAA, HITRUST, and broader industry cryptography guidance.
Seniority
Senior, hands-on IC