×
Register Here to Apply for Jobs or Post Jobs. X

Cryptography Solutions Architect

Job in City Of London, Central London, Greater London, England, UK
Listing for: Lorien
Full Time position
Listed on 2026-07-21
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations
Salary/Wage Range or Industry Benchmark: 90000 - 135000 GBP Yearly GBP 90000.00 135000.00 YEAR
Job Description & How to Apply Below
Location: City Of London

Cryptography Solutions Architect

We are currently recruiting for a Cryptography Solutions Architect with Venafi experience to join one of our Insurance clients on a 6-month contract.

Inside IR35

Hybrid

Key Responsibilities
  • Design and implement cryptographic key management solutions, ensuring key ownership (HYOK, BYOK) is aligned to risk appetite, covering HSMs, cloud key services (Azure Key Vault, AWS KMS, GCP Cloud KMS), KMaaS, and on-premises key stores.
  • Shape the key sovereignty and crypto‑agility and post‑quantum readiness strategies for algorithm deprecation and PQC adoption.
  • Align cryptographic controls with regulatory requirements, data sovereignty, data classification & Zero Trust principles, and key sovereignty (BYOK/HYOK/DKE patterns).
  • Produce high‑quality architecture artefacts: HLDs, LLDs, reference architecture, architecture decision records (ADRs), design patterns, standards, key hierarchy models, TIME models, technology radars to support engineering and platform teams.
  • Provide SME leadership to support vendor engagement, RFP and technical evaluations, proof‑of‑value, and architecture assessment for new products and services.
  • Assess the architectural implications of emerging cryptographic technologies and standards (e.g. NIST PQC outputs, homomorphic encryption, MPC), providing informed recommendations on adoption and transition pathways.
  • Collaborate with Engineering, Platform & Operations teams to ensure architectural patterns are translated into practical, operable implementations, consistently embedded into development pipelines, CI/CD workflows, and infrastructure‑as‑code, promoting a secure‑by‑design and automation‑first culture.
  • Embed cryptography governance and controls in designs, adhering to Cryptography Standards and aligning with NIST, FIPS, ISO
    27001/2, SOC2, DORA, HIPAA, PCI DSS, and relevant financial services and privacy regulations.
Experience
  • Advanced knowledge of applied cryptography, encryption technologies (including PGP/GPG), key management including cloud‑native KMS (Azure/AWS/OCI/GCP), Hashi Corp, KMaaS , HSMs, certificates and security protocols.
  • Thorough knowledge and implementation experience automating key lifecycle management, deploying key ownership models (i.e. BYOK/HYOK), key‑sovereignty, and key governance tools across hybrid environments (including Azure, AWS, OCI, GCP).
  • Experience with encryption‑in‑use models and key management specifics.
  • Proven experience building crypto‑agility (library baselines, cipher suite standards, algorithm rollout/deprecation) and PQC awareness with pragmatic migration planning.
  • Experience working with cloud infrastructure and microservices (Azure, AWS, OCI), and networking services.
  • Deep understanding of cryptographic algorithms, protocols, and standards, including symmetric and asymmetric cryptography, hashing, digital signatures, and key exchange mechanisms.
  • Broad knowledge of regulatory and controls/frameworks in industry (NIST, FIPS, ISO, IETF, PCI, SOC, CSF, ISO
    27001, DORA, GDPR, SABSA/TOGAF)
  • Ability to translate cryptographic policy and standards into practical, secure‑by‑design architecture patterns and engineering‑ready solution designs.
  • Experience engaging with engineering, platform, security, and risk teams to embed cryptographic best practices across the technology delivery lifecycle.
Desirable Experience
  • Familiarity with post‑quantum cryptographic algorithms and enterprise hybrid transition approaches.
  • Experience with emerging cryptographic techniques i.e. homomorphic encryption, multi‑party computation (MPC), threshold cryptography, trusted execution environments (TEEs).
  • Familiarity with cryptographic considerations in Dev Sec Ops  pipelines, including secrets management, certificate automation, and policy‑as‑code.
  • Thorough knowledge of traditional platform delivery approaches, technologies and op models, and a thorough appreciation of the capabilities of the major cloud platforms (Azure, AWS, GCP and OCI).
#J-18808-Ljbffr
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary