Cyber Data Protection/PKI Manager

Deloitte T.T.L.
Stamford, CT, United States
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Cloud Computing Cloud Computing Security Cyber Security Data Discovery Hardware Security Module Key Management Public Key Infrastructure Load Balancing Kubernetes Api Gateway Network Server

Job description

Experteer Overview In this role you guide clients through data protection and encryption strategies as part of Deloitte’s Cyber Strategy & Transformation team. You help design and operate solutions that reduce data risk across cloud, on-premises, and hybrid environments, while ensuring delivery stays on time and on budget. You will work with cross-functional teams to advance clients’ cyber posture, staying ahead of emerging encryption trends. This role offers impact by shaping enterprise-grade security programs and governance. Compensation / Benefits * Serve as SME and trusted advisor on data protection and encryption requirements * Advise on encryption, decryption, secure key management, and PKI strategies across environments * Design and implement data protection solutions including certificate lifecycle management and monitoring * Drive day-to-day engagement execution, communicating with clients and Deloitte leadership * Stay current on encryption technologies and industry trends; evaluate and recommend tools Tasks * 7+ years in data protection and information security (data discovery, classification, DLP, cloud security, encryption, CLM, etc.) * 7+ years with PKI concepts and enterprise trust models * 5+ years leading CLM strategy, design, and implementation (AppViewX, Venafi, Keyfactor, DigiCert or similar) * Advanced knowledge of cryptography, certificate lifecycles, key management, HSM, policy enforcement * Ability to define target-state architecture and operating models for large-scale environments * Hands-on certificate automation across load balancers, WAFs, API gateways, Kubernetes, cloud and servers * Experience leading discovery, inventory rationalization, remediation, automation, and compliance programs * Strong client leadership, stakeholder management, workshop facilitation, and roadmapping * Ability to lead technical workstreams, architects, engineers, and offshore/onshore teams * Translation of business and security requirements into architecture and implementation plans * Delivery governance, risk management, dependencies, and QA for enterprise security transformations * Willingness to travel 25-50% Key requirements *

Requirements

evaluate and recommend tools Tasks * 7+ years in data protection and information security (data discovery, classification, DLP, cloud security, encryption, CLM, etc.) * 7+ years with PKI concepts and enterprise trust models * 5+ years leading CLM strategy, design, and implementation (AppViewX, Venafi, Keyfactor, DigiCert or similar) * Advanced knowledge of cryptography, certificate lifecycles, key management, HSM, policy enforcement * Ability to define target-state architecture and operating models for large-scale environments * Hands-on certificate automation across load balancers, WAFs, API gateways, Kubernetes, cloud and servers * Experience leading discovery, inventory rationalization, remediation, automation, and compliance programs * Strong client leadership, stakeholder management, workshop facilitation, and roadmapping * Ability to lead technical workstreams, architects, engineers, and offshore/onshore teams * Translation of business and security requirements into architecture and implementation plans * Delivery governance, risk management, dependencies, and QA for enterprise security transformations * Willingness to travel 25-50% Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · WWC 2022

1:32 min

Designing a centralized API gateway and identity provider

Axel Barbier · WWC 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

4:04 min

Overview of Kubernetes operators and custom resource definitions

Philipp Krenn · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all