Cyber Data Protection/PKI Specialist Senior Consultant

Deloitte T.T.L.
San Francisco, CA, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Secure Shell (SSH) Client Server Models Cloud Computing Cyber Security Key Management Multi-Purpose Internet Mail Extensions (MIME) Public Key Infrastructure Transport Layer Security Load Balancing Kubernetes Api Gateway

Job description

Experteer Overview In this role you will act as a subject matter expert in data protection and PKI to help clients design, implement, and operate encryption and key-management solutions. You’ll collaborate with cross-functional teams to reduce data risks across cloud, on-premises, and hybrid environments. You will guide clients on PKI lifecycle management, certificate health, and compliance while staying ahead of emerging encryption technologies. This role offers scope to influence security strategy within Deloitte’s Cyber Strategy & Transformation practice and deliver measurable protection improvements for client environments. Compensation / Benefits * Serve as SME and trusted advisor on data protection, encryption, and secure key management * Design and implement encryption strategies across cloud, on-premises, and hybrid environments * Oversee PKI deployment, certificate lifecycle management, health monitoring, and vendor evaluations * Lead client engagements, drive day-to-day execution, and communicate progress to clients and leadership * Develop data protection strategies, roadmaps, and governance frameworks * Stay current on encryption tech trends (post-quantum, confidential computing, secure enclaves) and advise on tool adoption * Collaborate with delivery teams to ensure high-quality client deliverables and on-time, on-budget results * Support architecture and implementation workstreams, including CLM platforms and TLS/SSL practices * Coordinate with IT, security, and business stakeholders; lead workshops and executive communications * Travel 25-50% as required by client assignments Tasks * Bachelor’s degree in a related field * 5+ years in data protection and information security with relevant domains * 5+ years PKI concepts including certificates, CAs, RA, CSR, OCSP, CRL, HSM, key management * 2+ years experience with encryption technologies and cloud encryption concepts (BYOK, client/server-side) * 2+ years developing data protection strategies and roadmaps * 2+ years hands-on with one or more data protection technologies and CLM platforms (AppViewX, Venafi, Keyfactor, DigiCert) * 2+ years experience with cryptographic standards and protocols (TLS/SSL, SSH, S/MIME, code signing) * 2+ years certificate discovery, automation, renewal and compliance monitoring * 2+ years working across F5, load balancers, WAFs, Kubernetes, API gateways, and cloud platforms * 2+ years client-facing skills and leading small teams/workstreams * Ability to travel 25-50% * Professional certifications such as CISSP, CISM or similar Key requirements *

Requirements

vendor and communicate progress to clients and leadership * Develop data protection strategies, roadmaps, and governance frameworks * Stay current on encryption tech trends (post-quantum, confidential computing, secure enclaves) and advise on tool adoption * Collaborate with delivery teams to ensure high-quality client deliverables and on-time, on-budget results * Support architecture and implementation workstreams, including CLM platforms and TLS/SSL practices * Coordinate with IT, security, and business stakeholders; lead workshops and executive communications * Travel 25-50% as required by client assignments Tasks * Bachelor’s degree in a related field * 5+ years in data protection and information security with relevant domains * 5+ years PKI concepts including certificates, CAs, RA, CSR, OCSP, CRL, HSM, key management * 2+ years experience with encryption technologies and cloud encryption concepts (BYOK, client/server-side) * 2+ years developing data protection strategies and aaaaaas _ * 2+ years hands-on with one or more data protection technologies and CLM platforms (AppViewX, Venafi, Keyfactor, DigiCert) * 2+ years experience with cryptographic standards and protocols (TLS/SSL, SSH, S/MIME, code signing) * 2+ years certificate discovery, automation, renewal and compliance monitoring * 2+ years working across F5, load balancers, WAFs, Kubernetes, API gateways, and cloud platforms * 2+ years client-facing skills and leading small teams/workstreams * Ability to travel 25-50% * Professional certifications such as CISSP, CISM or similar Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

1:32 min

Designing a centralized API gateway and identity provider

Axel Barbier · World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

4:04 min

Overview of Kubernetes operators and custom resource definitions

Philipp Krenn · World Congress 2022

Videos

See all

Related articles

See all