EngineerJobs.io
← Back to all jobs

Job Description

Lead PKI and cryptography trust services in a global, hybrid organization at Goldman Sachs. This Vice President role in the Identity Security (IAM) team blends enterprise strategy with hands-on engineering to deliver compliant, highly available digital certificate lifecycle management across multi-cloud, on-premises, and IoT environments.

Work with modern PKI tooling, security standards, and cloud-native architectures while guiding a team responsible for enterprise trust services. You will help steer roadmap execution, automate certificate lifecycle processes to reduce operational risk, and represent the organization in industry consortiums as cryptography evolves.

Responsibilities

  • Own global strategy, engineering, deployment, and operations for the enterprise Public Key Infrastructure (PKI), cryptography, and digital certificate lifecycle management.
  • Deliver trust services that are robust, compliant, and highly available, aligned with industry guidance such as the NIST Computer Security Resource Center and the CA/Browser Forum.
  • Define and execute the global enterprise roadmap for PKI, certificate management, and cryptographic services, ensuring alignment with cybersecurity and business objectives.
  • Oversee design, implementation, and ongoing maintenance of internal and external Certificate Authorities (CAs), Registration Authorities (RAs), Hardware Security Modules (HSMs), and Key Management Systems (KMS).
  • Drive adoption of automated certificate lifecycle management (CLM) tools and protocols such as ACME, EST, and SCEP to reduce manual effort and prevent outages tied to expired certificates.
  • Ensure strict adherence to cryptographic standards, regulations, and audit requirements including WebTrust, SOC2, and ISO 27001. Establish and maintain the enterprise Certificate Policy (CP) and Certification Practice Statement (CPS).
  • Architect scalable PKI solutions for modern environments, including Kubernetes, service meshes, and hybrid-cloud deployments on AWS, Azure, and GCP.
  • Act as the escalation point for cryptographic vulnerabilities, certificate-related outages, and emergency key rotations.
  • Manage relationships with external Certificate Authorities and security vendors.
  • Represent the organization in industry consortiums to stay ahead of emerging cryptographic trends, including Post-Quantum Cryptography (PQC).

Requirements

  • Ability to thrive in a global, fast-paced, hybrid workplace.
  • Team-focused mindset with enthusiasm for working in a global organization.
  • Experience working in an Agile environment.
  • Strong emphasis on personal initiative and ownership.
  • Customer focus and attention to good developer experience.
  • Passion for learning new technologies.
  • 8+ years of experience.
  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Cryptography, or a related field.

Core Skills and Experience

  • Define and execute the global enterprise roadmap for PKI, certificate management, and cryptographic services.
  • Oversee the design, implementation, and maintenance of CAs, RAs, HSMs, and KMS.
  • Drive automated CLM adoption using ACME, EST, and SCEP to reduce manual processes and prevent expired-certificate outages.
  • Ensure audit and compliance alignment with WebTrust, SOC2, and ISO 27001, including ownership of CP/CPS.
  • Architect scalable PKI for Kubernetes, service meshes, and hybrid-cloud environments on AWS, Azure, and GCP.
  • Escalate and lead responses for cryptographic vulnerabilities, certificate-related outages, and emergency key rotations.
  • Manage relationships with external Certificate Authorities and security vendors.
  • Stay current with cryptographic direction by participating in industry consortiums, including PQC awareness.

Technologies

  • ACME, EST, SCEP
  • NIST Computer Security Resource Center, CA/Browser Forum
  • Kubernetes, service meshes
  • AWS, Azure, GCP
  • Post-Quantum Cryptography (PQC)
  • WebTrust, SOC2, ISO 27001
  • CP/CPS, TLS/SSL, SSH

Benefits

  • Healthcare & Medical Insurance
  • Holiday & Vacation Policies
  • Financial Wellness & Retirement
  • Health Services
  • Fitness
  • Child Care & Family Care

Preferred Qualifications

  • 10+ years of experience in cybersecurity and information technology, with at least 8+ years in dedicated leadership experience in PKI, cryptography, and data protection.
  • Deep understanding of asymmetric/symmetric cryptography, TLS/SSL protocols, SSH key management, code signing, and HSM management.
  • Preferred certifications include CISSP, CISM, or specialized cryptographic credentials.

Location: Jersey City, NJ (hybrid). Compensation: USD 130,000 - 250,000 per year.

Similar Jobs