Cyber Data Protection/PKI Specialist Senior Consultant

Deloitte T.T.L.
Denver, CO, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Secure Shell (SSH) Client Server Models Cloud Computing Cyber Security Data Security Key Management Multi-Purpose Internet Mail Extensions (MIME) Public Key Infrastructure Systems Integration SSL Certificate Management Transport Layer Security Load Balancing
+2 more
Kubernetes Api Gateway

Job description

Experteer Overview As a Senior Consultant in Deloitte’s Cyber team, you will advise clients on data protection, encryption, and PKI strategies to mitigate data risks across cloud, on-premises, and hybrid environments. You will design, implement, and operate secure data protection solutions and certificate management programs, while guiding delivery teams and maintaining strong client relationships. You will stay ahead of encryption trends and proactively recommend tools to strengthen cyber postures. This role combines technical leadership with cross-functional collaboration to deliver measurable risk reduction. Compensation / Benefits * Serve as SME and trusted advisor for data protection, encryption, and key management requirements * Design and implement encryption strategies across cloud, on-prem, and hybrid environments * Oversee PKI lifecycle management, certificate health, and secure certificate processes * Lead encryption, data protection, and CLM implementations; evaluate vendor solutions and architect end-to-end protections * Drive day-to-day project execution, communications, and governance with clients and leadership * Mentor delivery teams and ensure high-quality client-ready deliverables * Track timelines and budgets to ensure on-time, on-scope delivery * Stay current on emerging encryption technologies and industry trends; recommend new tools to enhance data security Tasks * 5+ years in data protection and information security * 5+ years with PKI concepts: certificates, CAs, RA, CSR, OCSP, CRL, HSM, key management * 2+ years of encryption technologies (PKI, TLS, data/media/file encryption) and cloud encryption concepts (BYOK, client/server-side) * 2+ years developing data protection strategies, roadmaps, and frameworks * 2+ years hands-on experience with CLM platforms (AppViewX, Venafi, Keyfactor, DigiCert or similar) * 2+ years with cryptographic standards/protocols (TLS/SSL, SSH, S/MIME, code signing, NIST practices) * 2+ years certificate discovery, automation, renewal, compliance monitoring * 2+ years supporting strategy, architecture, and implementation workstreams * 2+ years hands-on understanding of integrations with F5, load balancers, WAFs, Kubernetes, API gateways and cloud platforms * 2+ years client-facing skills: requirements gathering, stakeholder management, workshops, executive communication * 2+ years leading small teams/workstreams and delivering client-ready outputs * Ability to travel 25-50% on average * Professional certifications such as CISSP or CISM Key requirements *

Requirements

solutions and architect end-to-end protections * Drive day-to-day project execution, communications, and governance with clients and leadership * Mentor delivery teams and ensure high-quality client-ready deliverables * Track timelines and budgets to ensure on-time, on-scope delivery * Stay current on emerging encryption technologies and industry trends; recommend new tools to enhance data security Tasks * 5+ years in data protection and information security * 5+ years with PKI concepts: certificates, CAs, RA, CSR, OCSP, CRL, HSM, key management * 2+ years of encryption technologies (PKI, TLS, data/media/file encryption) and cloud encryption concepts (BYOK, client/server-side) * 2+ years developing data protection strategies, roadmaps, and frameworks * 2+ years hands-on experience with CLM platforms (AppViewX, Venafi, Keyfactor, DigiCert or similar) * 2+ years with cryptographic standards/protocols (TLS/SSL, SSH, S/MIME, code signing, NIST practices) * 2+ years certificate discovery, aaa hands-on renewal, compliance monitoring * 2+ years supporting strategy, architecture, and implementation workstreams * 2+ years hands-on understanding of integrations with F5, load balancers, WAFs, Kubernetes, API gateways and cloud platforms * 2+ years client-facing skills: requirements gathering, stakeholder management, workshops, executive communication * 2+ years leading small teams/workstreams and delivering client-ready outputs * Ability to travel 25-50% on average * Professional certifications such as CISSP or CISM Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

1:32 min

Designing a centralized API gateway and identity provider

Axel Barbier · World Congress 2023

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

4:04 min

Overview of Kubernetes operators and custom resource definitions

Philipp Krenn · World Congress 2022

Videos

See all

Related articles

See all