> Markdown version of [/jobs/ext/1636487-cryptography-solutions-architect](https://www.wearedevelopers.com/jobs/ext/1636487-cryptography-solutions-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cryptography Solutions Architect - **Company:** Lorien - **Location:** London, UK - **Contract:** Temporary contract - **Skills:** Amazon Web Services, Architectural Patterns, Public-Key Cryptography, Microsoft Azure, Cloud Computing, Cloud Engineering, Continuous Integration, Software Design Patterns, Digital Signature, Federal Information Processing Standards (FIPS), Key Management, Network Service, PCI Data Security Standards, Migration Manager, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Policy as Code, Google Cloud, Data Classification, Delivery Pipeline, Togaf, Hashicorp, Oracle Cloud Infrastructure, Devsecops, Microservices - **Published:** July 9, 2026 - **Apply:** https://www.reed.co.uk/jobs/cryptography-solutions-architect/57107149 ## About the Role * Advanced knowledge of applied cryptography, encryption technologies (including PGP/GPG), key management including cloud-native KMS (Azure/AWS/OCI/GCP), HashiCorp, KMaaS , HSMs, certificates and security protocols. * Thorough knowledge and implementation experience automating key lifecycle management, deploying key ownership models (i.e. BYOK/HYOK), key-sovereignty, and key governance tools across hybrid environments (including Azure, AWS, OCI, GCP). * Experience with encryption-in-use models and key management specifics. * Proven experience building crypto-agility (library baselines, cipher suite standards, algorithm rollout/deprecation) and PQC awareness with pragmatic migration planning. * Experience working with cloud infrastructure and microservices (Azure, AWS, OCI), and networking services. * Deep understanding of cryptographic algorithms, protocols, and standards, including symmetric and asymmetric cryptography, hashing, digital signatures, and key exchange mechanisms. * Broad knowledge of regulatory and controls/frameworks in industry (NIST, FIPS, ISO, IETF, PCI, SOC, CSF, ISO27001, DORA, GDPR, SABSA/TOGAF) * Ability to translate cryptographic policy and standards into practical, secure-by-design architecture patterns and engineering-ready solution designs. * Experience engaging with engineering, platform, security, and risk teams to embed cryptographic best practices across the technology delivery lifecycle. Desirable Experience * Familiarity with post-quantum cryptographic algorithms and enterprise hybrid transition approaches. * Experience with emerging cryptographic techniques i.e. homomorphic encryption, multi-party computation (MPC), threshold cryptography, trusted execution environments (TEEs). * Familiarity with cryptographic considerations in DevSecOps pipelines, including secrets management, certificate automation, and policy-as-code. * Thorough knowledge of traditional platform delivery approaches, technologies and op models, and a thorough appreciation of the capabilities of the major cloud platforms (Azure, AWS, GCP and OCI). ## Description * Design and implement cryptographic key management solutions, ensuring key ownership (HYOK, BYOK) is aligned to risk appetite, covering HSMs, cloud key services (Azure Key Vault, AWS KMS, GCP Cloud KMS), KMaaS, and on-premises key stores. * Shape the key sovereignty and crypto-agility and post-quantum readiness strategies for algorithm deprecation and PQC adoption. * Align cryptographic controls with regulatory requirements, data sovereignty, data classification & Zero Trust principles, and key sovereignty (BYOK/HYOK/DKE patterns). * Produce high-quality architecture artefacts: HLDs, LLDs, reference architecture, architecture decision records (ADRs), design patterns, standards, key hierarchy models, TIME models, technology radars to support engineering and platform teams. * Provide SME leadership to support vendor engagement, RFP and technical evaluations, proof-of-value, and architecture assessment for new products and services. * Assess the architectural implications of emerging cryptographic technologies and standards (e.g. NIST PQC outputs, homomorphic encryption, MPC), providing informed recommendations on adoption and transition pathways. * Collaborate with Engineering, Platform & Operations teams to ensure architectural patterns are translated into practical, operable implementations, consistently embedded into development pipelines, CI/CD workflows, and infrastructure-as-code, promoting a secure-by-design and automation-first culture. * Embed cryptography governance and controls in designs, adhering to Cryptography Standards and aligning with NIST, FIPS, ISO27001/2, SOC2, DORA, HIPPA, PCI DSS, and relevant financial services and privacy regulations. ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [Post-Quantum Cryptography: Preparing for Q-Day](https://www.wearedevelopers.com/videos/100179-post-quantum-cryptography-preparing-for-q-day) - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)