IT & Software

Encryption Engineer (DevSecOps & SDLC)

State Street Bank

London · Greater London · United Kingdom

Overview

In this role, you drive Encryption-by-Design across the SDLC and DevSecOps pipelines, embedding key management and encryption controls into platforms and workflows. You will partner with engineering, architecture, and platform teams to scale secure-by-default cryptography practices and reusable automation. You tackle complex security challenges through automation, elevating developer experience while meeting regulatory requirements. This position offers meaningful impact by standardizing encryption patterns across cloud and on-prem environments.

Pay / Benefits
  • 401K with company match
  • comprehensive insurance (medical, dental, vision, life, disability)
  • paid time off and sick leave
  • Employee Assistance Program
  • incentive compensation
  • tax-advantaged savings plans
Responsibilities
  • Embed encryption and key management controls into SDLC, DevSecOps, and platform engineering patterns
  • Design and implement secure-by-default encryption capabilities for seamless adoption
  • Build reusable automation, APIs, IaC modules, and reference architectures for enterprise-wide encryption
  • Integrate key management, secrets, certificate management, and encryption services into CI/CD workflows
  • Establish automated guardrails and policy-driven controls for encryption in the software lifecycle
  • Define architectural review triggers for non-conforming designs and address risks early
  • Collaborate with development, platform, cloud, and architecture teams to standardize cryptographic practices
  • Produce standards, guidance, and developer enablement materials to simplify adoption
  • Improve Encryption-by-Design program through automation and self-service
  • Monitor encryption implementations to identify gaps and drive remediation
  • Support regulatory, audit, and risk management with automated evidence of compliance
  • Drive modernization of legacy encryption and promote standardization across solutions
  • Reduce design exceptions and manual reviews by embedding controls into development processes
  • Accelerate compliant onboarding and delivery through reusable security capabilities
Key requirements
  • 8+ years in software engineering, DevSecOps, platform/cloud engineering or related field
  • Experience integrating security controls into SDLC and CI/CD
  • Knowledge of encryption technologies, key management, secrets management, and certificate lifecycle
  • Automation in development pipelines with tools like Harness, Jenkins
  • Hands-on with Infrastructure-as-Code (Terraform, CloudFormation)
  • Proficiency in Python, Java, Go, C#, JavaScript, TypeScript, PowerShell, or Bash
  • Experience with cloud platforms (Azure, AWS, OCI, GCP)
  • Familiarity with Kubernetes/OpenShift and cloud-native architectures
  • Understanding of secure coding, software architecture, and developer enablement
  • Knowledge of security/compliance frameworks (NIST, PCI DSS, ISO 27001)
  • Experience with enterprise key management, HSMs, cloud KMS, secrets/certificate management is a plus
  • Certifications such as CISSP, CCSP, Azure Security Engineer Associate, AWS Security Specialty, CKS are a plus
  • Security-first mindset
  • Strong collaboration across cybersecurity, architecture, engineering, and product teams
  • Proactive and innovative mindset for reusable solutions and automation
  • Encryption technologies
  • Key management
  • Secrets management

Reference: WJ-747_30200987

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.