×
Register Here to Apply for Jobs or Post Jobs. X

Encryption Engineer (DevSecOps & SDLC)

Job in Quincy, Norfolk County, Massachusetts, 02169, USA
Listing for: State Street
Full Time position
Listed on 2026-08-01
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below

Encryption Engineer (Dev Sec Ops  & SDLC)

We are seeking a highly motivated Encryption Engineer (Dev Sec Ops  & SDLC) who is passionate about building secure-by-design solutions and transforming encryption from a point-in-time security requirement into a seamlessly integrated engineering capability. This individual will play a critical role in advancing the organization's Encryption-by-Design strategy by embedding standardized encryption and key management controls directly into the Software Development Life Cycle (SDLC), Dev Sec Ops  pipelines, and enterprise platform engineering patterns.

The ideal candidate combines software engineering, automation, cloud, and cybersecurity expertise with a strong understanding of cryptography and data protection principles. They are skilled at influencing engineering practices, building reusable security capabilities, and partnering with developers, architects, and platform teams to ensure encryption is implemented consistently, efficiently, and at scale.

This role is well-suited for an individual who enjoys solving complex security challenges through automation, creating developer-friendly security solutions, and driving enterprise-wide adoption of secure design patterns. They should be comfortable operating in a fast-paced environment where security, developer experience, operational resilience, and regulatory compliance must coexist.

Responsibilities
  • Embed enterprise encryption and key management controls into SDLC processes, Dev Sec Ops  pipelines, and platform engineering patterns to ensure security is built into solutions from the start.
  • Design and implement secure-by-default encryption capabilities that enable application teams to adopt approved cryptographic controls with minimal effort.
  • Develop and maintain reusable automation, APIs, templates, Infrastructure-as-Code modules, and reference architectures that accelerate consistent encryption adoption across the enterprise.
  • Integrate enterprise key management, secrets management, certificate management, and encryption services into standard developer workflows and CI/CD tool chains.
  • Establish automated guardrails and policy-driven controls that validate encryption requirements throughout the software development lifecycle.
  • Define and implement architectural review triggers for non-conforming designs, ensuring encryption risks and standards exceptions are identified and addressed early in the design process.
  • Partner with application development, platform engineering, cloud engineering, and architecture teams to implement approved cryptographic standards, patterns, and controls across cloud and on-premises environments.
  • Create technical standards, implementation guidance, and developer enablement materials that simplify the adoption of encryption and key management capabilities.
  • Continuously improve the organization's Encryption-by-Design program by increasing automation, reducing manual security reviews, and driving greater self-service adoption.
  • Monitor and assess encryption implementations to identify control gaps, inconsistent practices, and opportunities for standardization and remediation.
  • Support regulatory, audit, and risk management initiatives by ensuring encryption controls are consistently deployed, measurable, and supported by automated compliance evidence.
  • Drive adoption of enterprise encryption services by working closely with engineering teams to modernize legacy implementations and align new solutions with approved standards.
  • Reduce the risk of inconsistent, fragmented, or non-compliant encryption implementations through standardized patterns, automated enforcement, and scalable engineering controls.
  • Minimize design exceptions, audit findings, and operational risks by embedding cryptographic controls directly into development processes rather than relying on manual reviews and remediation activities.
  • Accelerate compliant application onboarding and delivery by providing reusable security capabilities that improve both developer experience and regulatory compliance outcomes.
What We Value

These skills will help you succeed in this role:

  • A security-first mindset with a passion for building secure, resilient, and scalable technology solutions.
  • Strong engineering discipline and a commitment to automation, standardization, and continuous improvement.
  • The ability to translate security requirements into practical engineering solutions that improve both security and developer experience.
  • A collaborative approach to working across cybersecurity, architecture, engineering, infrastructure, and product teams.
  • A proactive and innovative mindset focused on eliminating friction through reusable solutions, self-service capabilities, and policy-driven automation.
  • Strong analytical and problem-solving skills with the ability to identify root causes and design sustainable solutions.
  • Effective communication skills and the ability to explain complex technical concepts to both technical and non-technical stakeholders.
  • An ownership mentality that…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary