Dell
Round Rock or Hopkinton

Consultant, Cryptography Security Architect

Onsite$176,800 - $228,800/yrPosted today

We tailor your resume to this role and apply for you in seconds.

Apply to Consultant, Cryptography Security Architect at Dell

Job details

Location
Round Rock or Hopkinton
Work type
Onsite
Compensation
$176,800 - $228,800/yr
Posted
today
Apply on
iawmqy.fa.ocs.oraclecloud.com

About this role

Cryptography Security Architect Consultant

 

The Dell Security & Resiliency organization manages the security risk across all aspects of Dell’s business. You will have an excellent opportunity to influence the security culture at Dell and further develop your career. 

Join us as a Cryptography Security Architect on our Enterprise Security Architecture team in Round Rock, Texas or Hopkinton, Massachusetts to do the best work of your career and make a profound social impact.

What you’ll achieve

As a Cryptography Security Architectyou will be responsible for setting the architectural vision for Dell’s enterprise cryptographic infrastructure. You will work across Dell’s Cybersecurity, IT and Business Units to develop buy-in and partnerships for large strategic initiatives that will drive Dell’s evolution into the next generation of cryptography.  You will develop and lead methods and techniques for identifying and advocating effective security solutions and own thought leadership and coordination of reviews of available tools, technologies, and processes to secure all aspects of the enterprise.

 

 

Responsibilities

You will:

  • Design, govern, and evolve the enterprise cryptographic infrastructure: including HSM platforms, certificate authorities, certificate lifecycle management systems, and enterprise key management services - across on-premises, cloud, and customer-facing environments, ensuring operational resilience through a deliberate multi-vendor strategy that balances risk mitigation, procurement agility, and technology portability.
  • Serve as the enterprise lead for Post-Quantum Cryptography (PQC) readiness: driving cross-business-unit awareness, requirements documentation, crypto-agility planning, and global enablement by tracking emerging PQC standards, evaluating hybrid cryptographic approaches, assessing PQC-native hardware, and translating evolving mandates into actionable migration roadmaps.
  • Author, maintain, and enforce enterprise cryptographic standards and governance frameworks: covering algorithms, protocols, PKI trust models, and key management practices - while translating complex regulatory and technical requirements (including FIPS, FedRAMP, PCI DSS, and NFI PKI) into clear, actionable guidance that diverse engineering teams can confidently implement.
  • Lead multi-year cryptographic transformation programs: managing distributed execution across business units and technology teams, owning delivery accountability, conducting quantified cost/effort analysis for build-vs-buy and vendor consolidation decisions, managing strategic vendor relationships, and providing executive-level reporting on program progress and risk posture.
  • Architect abstracted, API-first cryptographic services: designing certificate and key management capabilities that enable seamless backend technology portability without consumer disruption, leveraging protocols such as KMIP, PKCS#11, EST, and ACME to eliminate vendor lock-in and provide scalable, self-service cryptographic operations for enterprise consumption.

Qualifications

  • Design, govern, and evolve the enterprise cryptographic infrastructure: including HSM platforms, certificate authorities, certificate lifecycle management systems, and enterprise key management services - across on-premises, cloud, and customer-facing environments, ensuring operational resilience through a deliberate multi-vendor strategy that balances risk mitigation, procurement agility, and technology portability.
  • Serve as the enterprise lead for Post-Quantum Cryptography (PQC) readiness: driving cross-business-unit awareness, requirements documentation, crypto-agility planning, and global enablement by tracking emerging PQC standards, evaluating hybrid cryptographic approaches, assessing PQC-native hardware, and translating evolving mandates into actionable migration roadmaps.
  • Author, maintain, and enforce enterprise cryptographic standards and governance frameworks: covering algorithms, protocols, PKI trust models, and key management practices - while translating complex regulatory and technical requirements (including FIPS, FedRAMP, PCI DSS, and NFI PKI) into clear, actionable guidance that diverse engineering teams can confidently implement.
  • Lead multi-year cryptographic transformation programs: managing distributed execution across business units and technology teams, owning delivery accountability, conducting quantified cost/effort analysis for build-vs-buy and vendor consolidation decisions, managing strategic vendor relationships, and providing executive-level reporting on program progress and risk posture.
  • Architect abstracted, API-first cryptographic services: designing certificate and key management capabilities that enable seamless backend technology portability without consumer disruption, leveraging protocols such as KMIP, PKCS#11, EST, and ACME to eliminate vendor lock-in and provide scalable, self-service cryptographic operations for enterprise consumption.

 

Take the first step towards your dream career - Every Dell team member brings something unique to the table.  Here's what we are looking for with this role:

Essential Requirement:

 

  • HSM Architecture & Strategy: Deep expertise in enterprise HSM platforms with the ability to design and maintain a multi-vendor strategy that balances risk mitigation, procurement agility, and operational readiness.
  • Enterprise Certificate Management: Proven ability to architect and govern large-scale certificate ecosystems spanning public CAs, private CAs, CLM platforms, and API abstraction layers across on-premises, cloud, and customer-facing environments.
  • Enterprise Key Management: Strong knowledge of EKM platforms, cloud key management, database encryption methodologies, with the ability to design key management services for enterprise consumption.
  • Post-Quantum Cryptography (PQC): Working understanding of current and emerging PQC standards, hybrid approaches, and PQC-native hardware, with the ability to serve as the dedicated enterprise lead driving cross-business-unit PQC readiness, crypto agility, requirements documentation, and global enablement.
  • Cryptographic Standards & Governance: Broad foundational mastery of cryptographic primitives, algorithms, protocols, and PKI trust models, with the ability to author and enforce enterprise cryptographic standards and translate complex requirements into actionable guidance for diverse engineering teams.
  • Enterprise Cryptographic Operations: 7+ years of experience operating and governing large-scale cryptographic infrastructure (HSMs, CAs, key managers) supporting millions of cryptographic objects across complex hybrid multi-cloud enterprise environments.

  • Multi-Stakeholder Program Execution: Demonstrated success leading multi-year, large enterprise security transformation programs, particularly cryptographic migrations, with accountability for delivery, distributed execution management, and executive-level reporting.

  • Cryptographic Vendor Management: Direct experience evaluating, deploying, and managing relationships with HSM manufacturers, CA/CLM providers, and key management vendors, including making strategic consolidation, migration, and build-vs-buy decisions with quantified cost/effort analysis.

 

Desired Requirement:

  • Regulated Environment Experience (Preferred): Familiarity with federal, FedRAMP, FIPS, and PCI DSS cryptographic requirements, including NFI PKI and the constraints of regulated cryptographic deployments.

  • API-Driven Security Services Design (Preferred): Experience architecting abstracted, API-first security services (certificate and key management) that enable backend technology portability without consumer disruption, avoiding vendor lock-in, with familiarity in protocols such as KMIP, PKCS#11, EST, and ACME.

 

Ready to apply to Dell?
We tailor your resume to this role and apply for you.

About Dell

Dell
Round Rock or Hopkinton