Jobs / Amgen / Encryption Agility Service Lead

Encryption Agility Service Lead

Amgen
India - Hyderabad Onsite Is
Apply for this position

About this role

Career Category

Information Systems

Job Description

Role Name: Senior Manager Information Security - Encryption Agility Service Lead

Job Posting Title: Sr. Manager Information Security - Encryption Agility Service Lead

Workday Job Title: Sr. Manager Information Security

Department Name: Trusted Core Technologies

Role GCF: 6A

ABOUT AMGEN

Amgen harnesses the best of biology and technology to fight the world's toughest diseases, and make people's lives easier, fuller and longer. We discover, develop, manufacture and deliver innovative medicines to help millions of patients. Amgen helped establish the biotechnology industry more than 40 years ago and remains on the cutting-edge of innovation, using technology and human genetic data to push beyond what's known today.

ABOUT THE ROLE

Role Description:

The Senior Manager Information Security - Encryption Agility Service Lead is accountable for establishing, leading, and operating Amgen's enterprise Encryption Agility Service for Post-Quantum Readiness Preparation. This role will lead the Encryption Agility Team and be considered Amgen’s Cryptographic Center of Excellence! The team will own and manage the enterprise service for encryption, cryptography, crypto agility, and post-quantum cryptography readiness across Amgen. The role combines people leadership, security architecture, program execution, and hands-on cryptographic expertise across applications, cloud, infrastructure, identity, PKI, certificates, KMS, secrets, data protection, OT coordination, and the third-party ecosystem. The role partners closely with the Principal Architect, Digital Identity Access Services (DIAS), PKI and certificate service owners, Enterprise Architecture, Application Security, Governance Risk and Compliance, Procurement, Legal, Infrastructure, Cloud, Manufacturing/OT, and vendor teams to translate Amgen's PQC roadmap into governed standards, enforceable controls, measurable inventory, and prioritized remediation. The ideal candidate has strong people leadership skills, deep technical understanding of cryptography and cybersecurity, and experience managing large-scale enterprise security programs in a global, regulated environment.

Roles & Responsibilities:

  • Establish, operate, and continuously improve the enterprise Encryption Agility Team and Service, including the service charter, governance model, operating cadence, intake process, Responsible, Accountable, Consulted, and Informed (RACI) model, roadmap, Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), executive reporting, and service improvement plan.
  • Lead, coach, mentor, and manage Encryption Agility Team members, including Amgen full-time employees (FTEs), external workers, cryptographic engineers, security architecture analysts, product ownership support, and part-time contributors from partner teams.
  • Partner with the Principal Architect to translate enterprise Post-Quantum Cryptography (PQC) strategy into standards and specifications, reference architectures, implementation patterns, practical engineering guidance, remediation backlogs, and production-ready cryptographic design decisions.
  • Own the enterprise cryptographic standards and specifications roadmap, including approved algorithms, key sizes, protocols, Transport Layer Security (TLS) and cipher policies, certificate requirements, Key Management Services (KMS) and secrets requirements, exception criteria, Rivest-Shamir-Adleman (RSA) and Elliptic Curve Cryptography (ECC) sunset planning, and annual standards refresh.
  • Lead delivery across the full PQC lifecycle, including assessment wrap-up, quick wins, discovery tooling selection, iterative discovery, vendor and third-party outreach, PQC architecture, testing and trials, production rollout, automation, monitoring, and steady-state service operations.
  • Build, govern, and mature the Amgen Cryptographic Bill of Materials (CBOM), including required fields, asset ownership, quantum-vulnerability status, remediation status, data quality controls, reporting requirements, and integration of cryptographic inventory and risk data across relevant Amgen platforms.
  • Direct enterprise cryptographic discovery across source code, binaries, cloud key services, endpoints, file systems, network traffic, Public Key Infrastructure (PKI) and certificates, KMS and secrets, vendor attestations, and Subject Matter Expert (SME) interviews to create a reliable enterprise cryptographic inventory.
  • Apply the approved PQC risk-prioritization approach to sequence discovery and remediation for business-critical applications, high-volume sensitive data flows, identity services, third-party dependencies, legacy platforms, Key Computerized Systems (KCS), and validated Good x Practice (GxP) systems.
  • Coordinate with Digital Identity Access Services (DIAS), PKI service owners, certificate management teams, cloud, infrastructure, and platform teams on certificate visibility, Certificate Lifecycle Manager (CLM) evaluation, certificate rotation policy, manual-to-automated deployment migration, post-quantum PKI readiness, hybrid certificate testing, Certificate Authority (CA) roadmap, operational change windows, enterprise KMS strategy, Hardware Security Module (HSM) and cloud KMS roadmaps, secrets management, key rotation, key retirement, and centralized or federated key management control patterns.
  • Partner with Application Security, Secure Software Development Lifecycle (SSDLC), DevOps, Artificial Intelligence (AI) Security, Enterprise Architecture, and engineering teams to publish approved cryptographic libraries, reusable patterns, Continuous Integration/Continuous Delivery (CI/CD) controls, scanning rules, secure code examples, and remediation playbooks.
  • Coordinate with Risk and Compliance, Legal, Procurement, Third-Party Risk Management (TPRM), and vendor management to implement PQC questionnaires, CBOM requests, contract language, supplier roadmap tracking, risk acceptance, and executive escalation for vendors and Software as a Service (SaaS) providers.
  • Provide senior technical escalation and hands-on leadership for cryptographic standards exceptions, scan findings, false-positive triage, certificate outages, key and secret configuration issues, tool integration blockers, design tradeoffs, Steal-Now-Decrypt-Later (SNDL) exposure, identity and certificate risks, outdated TLS and cipher configurations, legacy cryptography, untracked keys, manual certificate processes, Operational Technology (OT) and manufacturing scope definition, developer and stakeholder enablement, and changes in National Institute of Standards and Technology (NIST), Internet Engineering Task Force (IETF), National Security Agency Commercial National Security Algorithm (NSA/CNSA) Suite, International Organization for Standardization (ISO), Health Insurance Portability and Accountability Act (HIPAA), Health Information Trust Alliance (HITRUST), and industry cryptography guidance.

Basic Qualifications and Experience:

  • Doctorate degree and 2 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience OR
  • Master's degree with 8 to 10 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience OR
  • Bachelor's degree with 10 to 14 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience OR
  • Diploma with 14 to 18 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience

Functional Skills:

Must-Have Skills:

  • Expert knowledge of enterprise cryptography, including PKI, X.509 certificates, TLS, cipher suites, KMS/HSM, secrets management, key lifecycle, encryption at rest and in transit, and cloud key services.
  • Proven experience leading global information security, security architecture, or cryptography programs, including roadmap ownership, team management, resource planning, metrics, reporting, and executive stakeholder management.
  • Practical knowledge of post-quantum cryptography, crypto agility, NIST-approved algorithms and standards, hybrid/PQC transition patterns, cryptographic discovery, and CBOM-driven remediation.
  • Ability to translate security policy into enforceable controls across CI/CD, cloud platforms, identity, PKI/certificates, infrastructure, applications, third-party governance, and risk management.

Good-to-Have Skills:

  • Hands-on experience with ServiceNow CMDB/GRC, Guard, Wiz, Qualys, Fortinet, Netskope, CrowdStrike, GitLab, Veracode, AWS KMS/ACM/Secrets Manager, Microsoft PKI, Sectigo, HashiCorp Vault, HSMs, CLM, and SIEM/data lake integrations.
  • Experience designing or operating CBOM/SBOM data models using CycloneDX 1.6+, APIs, CSV/JSON exports, dashboards, and data quality controls.
  • Experience coordinating PKI and certificate operations with DIAS or equivalent infrastructure and certificate service owners.
  • Experience in validated/GxP, manufacturing, OT, KCS, or highly regulated environments, including change control and revalidation impacts.
  • Experience with vendor and third-party risk management, supplier cryptographic questionnaires, contract requirements, and vendor roadmap tracking.
  • Scripting and automation experience with Python, PowerShell, Bash, REST APIs, or data pipeline tooling.

Professional Certifications:

  • CISSP (required)
  • CISM, CISA, or CRISC (preferred)
  • CCSP or cloud security certification such as AWS Certified Security - Specialty or Azure Security Engineer (preferred)
  • TOGAF or SABSA (preferred)
  • ITIL, SAFe, product management, or program management certification (preferred)
  • Relevant PKI, KMS, HSM, cryptographic discovery, or certificate lifecycle management vendor certifications (preferred)

Soft Skills:

  • Excellent people leadership, coaching, mentoring, and performance management skills.
  • Strong executive presence and ability to translate complex cryptographic risk into clear business impact and action plans.
  • Strong verbal and written communication skills for technical, business, legal, procurement, compliance, and executive audiences.
  • Ability to influence without direct authority across global security, DTI, DIAS, procurement, legal, compliance, OT, infrastructure, and application teams.
  • High degree of initiative, accountability, judgment, and self-motivation in ambiguous or evolving technical domains.
  • Ability to manage multiple priorities, competing stakeholder needs, and long-running transformation roadmaps successfully.
  • Team oriented, with a focus on shared outcomes, practical implementation, and service maturity.
  • Ability to balance hands-on technical analysis with service ownership, people leadership, and enterprise change management.

EQUAL OPPORTUNITY STATEMENT

Amgen is an Equal Opportunity employer and will consider you without regard to your race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.

We will ensure that individuals with disabilities are provided with reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request an accommodation.

.

About Amgen

Leading biotechnology company focused on oncology, cardiovascular, bone health, and inflammation therapies. Based in Thousand Oaks, CA.

amgen.com

Job Details
LocationIndia - Hyderabad
Work typeOnsite
DepartmentIs
SenioritySenior
CountryIndia
About the company
Amgen
Leading biotechnology company focused on oncology, cardiovascular, bone health, and inflammation therapies. Based in Thousand Oaks, CA.
View all 1657 open jobs at Amgen
BioHired Insights
Hiring locations: India (904), United States (452), Portugal (46)