> Markdown version of [/jobs/ext/1501881-consultant-cryptography-security-architect](https://www.wearedevelopers.com/jobs/ext/1501881-consultant-cryptography-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Consultant, Cryptography Security Architect - **Company:** Dell Technologies Inc. - **Location:** Hopkinton, MA, United States - **Experience:** Expert - **Salary:** $176,800.0 - $228,800.0 - **Contract:** Permanent contract - **Skills:** Abstraction Layers, Application Programming Interfaces (APIs), Cloud Computing, Cyber Security, Database Encryption, Federal Information Processing Standards (FIPS), Key Management, PCI Data Security Standards, Public Key Infrastructure, Requirements Management, SSL Certificate Management, Backend, Api Design - **Published:** July 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=341be751504ef7ef ## About the Role HSM Architecture & Strategy: Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness. * Enterprise Certificate Management: Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments. * Enterprise Key Management: Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption. * Post-Quantum Cryptography (PQC): Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement. * Cryptographic Standards & Governance: Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams. * Enterprise Cryptographic Operations: 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments. * Multi-Stakeholder Program Execution: Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting. * Cryptographic Vendor Management: Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis., * Regulated Environment Experience (Preferred): Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments. * API-Driven Security Services Design (Preferred): Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME. ## Description As a Cryptography Security Architect, you will be responsible for setting the architectural vision for Dell's enterprise cryptographic infrastructure. You will work across Dell's Cybersecurity, IT and Business Units to develop buy-in and partnerships for large strategic initiatives that will drive Dell's evolution into the next generation of cryptography. You will develop and lead methods and techniques for identifying and advocating effective security solutions and own thought leadership and coordination of reviews of available tools, technologies, and processes to secure all aspects of the enterprise., * Design, govern, and evolve the enterprise cryptographic infrastructure: including HSM platforms, certificate authorities, certificate lifecycle management systems, and enterprise key management services - across on-premises, cloud, and customer-facing environments, ensuring operational resilience through a deliberate multi-vendor strategy that balances risk mitigation, procurement agility, and technology portability. * Serve as the enterprise lead for Post-Quantum Cryptography (PQC) readiness: driving cross-business-unit awareness, requirements documentation, crypto-agility planning, and global enablement by tracking emerging PQC standards, evaluating hybrid cryptographic approaches, assessing PQC-native hardware, and translating evolving mandates into actionable migration roadmaps. * Author, maintain, and enforce enterprise cryptographic standards and governance frameworks: covering algorithms, protocols, PKI trust models, and key management practices - while translating complex regulatory and technical requirements (including FIPS, FedRAMP, PCI DSS, and NFI PKI) into clear, actionable guidance that diverse engineering teams can confidently implement. * Lead multi-year cryptographic transformation programs: managing distributed execution across business units and technology teams, owning delivery accountability, conducting quantified cost/effort analysis for build-vs-buy and vendor consolidation decisions, managing strategic vendor relationships, and providing executive-level reporting on program progress and risk posture. * Architect abstracted, API-first cryptographic services: designing certificate and key management capabilities that enable seamless backend technology portability without consumer disruption, leveraging protocols such as KMIP, PKCS#11, EST, and ACME to eliminate vendor lock-in and provide scalable, self-service cryptographic operations for enterprise consumption. * Design, govern, and evolve the enterprise cryptographic infrastructure: including HSM platforms, certificate authorities, certificate lifecycle management systems, and enterprise key management services - across on-premises, cloud, and customer-facing environments, ensuring operational resilience through a deliberate multi-vendor strategy that balances risk mitigation, procurement agility, and technology portability. * Serve as the enterprise lead for Post-Quantum Cryptography (PQC) readiness: driving cross-business-unit awareness, requirements documentation, crypto-agility planning, and global enablement by tracking emerging PQC standards, evaluating hybrid cryptographic approaches, assessing PQC-native hardware, and translating evolving mandates into actionable migration roadmaps. * Author, maintain, and enforce enterprise cryptographic standards and governance frameworks: covering algorithms, protocols, PKI trust models, and key management practices - while translating complex regulatory and technical requirements (including FIPS, FedRAMP, PCI DSS, and NFI PKI) into clear, actionable guidance that diverse engineering teams can confidently implement. * Lead multi-year cryptographic transformation programs: managing distributed execution across business units and technology teams, owning delivery accountability, conducting quantified cost/effort analysis for build-vs-buy and vendor consolidation decisions, managing strategic vendor relationships, and providing executive-level reporting on program progress and risk posture. * Architect abstracted, API-first cryptographic services: designing certificate and key management capabilities that enable seamless backend technology portability without consumer disruption, leveraging protocols such as KMIP, PKCS#11, EST, and ACME to eliminate vendor lock-in and provide scalable, self-service cryptographic operations for enterprise consumption. ## Related Videos - [API Design - Getting Started](https://www.wearedevelopers.com/videos/33-api-design-getting-started) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [An alternative approach to digital sovereignty: Confidential Computing](https://www.wearedevelopers.com/videos/100043-an-alternative-approach-to-digital-sovereignty-confidential-computing) - [Rest API Antipatterns](https://www.wearedevelopers.com/videos/100208-rest-api-antipatterns) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)