Job Description
Job Summary
Key Responsibilities 1. Solution Architecture & Design - Design the end to end encryption solution for sensitive workloads on AWS (technical architecture, operating model, governance framework). - Integrate AWS KMS, XKS, CloudHSM with Thales HSMs and SG’s security ecosystem. - Ensure solution alignment with SG’s cloud, cybersecurity, and compliance standards. - Define dependency mapping, lifecycle management, and disaster recovery/BCP for key management services. 2. Validation & Cross Team Alignment - Present and validate the solution with Architecture teams, Security teams, and Cloud Governance. - Facilitate design reviews, architecture boards, risk assessments, and cryptographic compliance checks. - Ensure full traceability of decisions, risks, and technical controls. 3. Deployment, Automation & Documentation - Deploy and configure AWS KMS, XKS, CloudHSM environments and Thales integrations. - Automate deployment pipelines using CI/CD, infrastructure-as-code, and DevOps tooling. - Produce complete documentation (HLD, LLD, runbooks, standard operating procedures, security controls). - Build dashboards and monitoring for service health, key usage, and compliance adherence. 4. Proof of Concept (POC) & Scalability Validation - Execute a POC using a real-use case. - Evaluate performance, scalability, operational flows, and integration reliability. - Provide recommendations for optimization, security hardening, and operational efficiency. 5. Production Rollout & Service Enablement - Lead the service transition from POC to production-ready state. - Ensure the solution meets internal cloud platform criteria:- operational readiness - monitoring/alerting - secure CI/CD pipelines - service governance requirements - Build operational workflows with OSM, Operations, Cloud, and Security teams. - Drive incident response readiness, DR testing, and change control processes. 6. Knowledge Transfer & Team Upskilling - Educate and mentor team members on AWS HSM, KMS, XKS, encryption models, and cloud security. - Conduct training workshops, technical deep-dives, and documentation walkthroughs. - Help establish an internal competency framework for AWS-based key management systems Profile We are seeking an AWS Architecture & Key Management expert to design, validate, and deliver the next generation C3 encryption solution on AWS, equivalent to SG’s existing Azure based service. This role is critical to enabling regulated workloads for platforms in public cloud. The specialist will be the subject-matter expert (SME) for AWS Key Management Services, XKS (External Key Store), HSM (CloudHSM/Thales), and cloud encryption architectures. They will lead solution design, deployment, automation, validation, and production readiness—while also upskilling team members and ensuring alignment with SG’s internal cloud and security standards. You will work closely with Cloud, OSM, Architecture, and Security Governance teams across Paris, Bangalore, and Bucharest. Specific Context Required Skills & Technical Expertise Core AWS Cryptography Expertise - AWS KMS, External Key Store (XKS), CloudHSM, key lifecycle management. - Integration with Thales HSMs and enterprise-grade encryption architectures. Cloud Architecture & Security - Strong cloud architecture knowledge (AWS, Azure concepts an advantage). - Experience designing secure cloud services for regulated workloads. - Strong understanding of IAM, VPC security, encryption-in-transit/at-rest, and compliance frameworks. DevOps & Automation - Experience with IaC and CI/CD pipelines (Terraform, CloudFormation, GitHub Actions, or Azure DevOps). - Background in automation for deployment, monitoring, and configuration at scale. Cross-Team Collaboration - Ability to work with Architecture, Cloud, OSM, Governance, and Security Compliance teams. - Strong experience leading POCs, pilots, and service transition activities. Governance & Operating Model - Experience defining operational models, service governance, risk assessmen
Key Responsibilities
Key Responsibilities 1. Solution Architecture & Design - Design the end to end encryption solution for sensitive workloads on AWS (technical architecture, operating model, governance framework). - Integrate AWS KMS, XKS, CloudHSM with Thales HSMs and SG’s security ecosystem. - Ensure solution alignment with SG’s cloud, cybersecurity, and compliance standards. - Define dependency mapping, lifecycle management, and disaster recovery/BCP for key management services. 2. Validation & Cross Team Alignment - Present and validate the solution with Architecture teams, Security teams, and Cloud Governance. - Facilitate design reviews, architecture boards, risk assessments, and cryptographic compliance checks. - Ensure full traceability of decisions, risks, and technical controls. 3. Deployment, Automation & Documentation - Deploy and configure AWS KMS, XKS, CloudHSM environments and Thales integrations. - Automate deployment pipelines using CI/CD, infrastructure-as-code, and DevOps tooling. - Produce complete documentation (HLD, LLD, runbooks, standard operating procedures, security controls). - Build dashboards and monitoring for service health, key usage, and compliance adherence. 4. Proof of Concept (POC) & Scalability Validation - Execute a POC using a real-use case. - Evaluate performance, scalability, operational flows, and integration reliability. - Provide recommendations for optimization, security hardening, and operational efficiency. 5. Production Rollout & Service Enablement - Lead the service transition from POC to production-ready state. - Ensure the solution meets internal cloud platform criteria:- operational readiness - monitoring/alerting - secure CI/CD pipelines - service governance requirements - Build operational workflows with OSM, Operations, Cloud, and Security teams. - Drive incident response readiness, DR testing, and change control processes. 6. Knowledge Transfer & Team Upskilling - Educate and mentor team members on AWS HSM, KMS, XKS, encryption models, and cloud security. - Conduct training workshops, technical deep-dives, and documentation walkthroughs. - Help establish an internal competency framework for AWS-based key management systems Profile We are seeking an AWS Architecture & Key Management expert to design, validate, and deliver the next generation C3 encryption solution on AWS, equivalent to SG’s existing Azure based service. This role is critical to enabling regulated workloads for platforms in public cloud. The specialist will be the subject-matter expert (SME) for AWS Key Management Services, XKS (External Key Store), HSM (CloudHSM/Thales), and cloud encryption architectures. They will lead solution design, deployment, automation, validation, and production readiness—while also upskilling team members and ensuring alignment with SG’s internal cloud and security standards. You will work closely with Cloud, OSM, Architecture, and Security Governance teams across Paris, Bangalore, and Bucharest. Specific Context Required Skills & Technical Expertise Core AWS Cryptography Expertise - AWS KMS, External Key Store (XKS), CloudHSM, key lifecycle management. - Integration with Thales HSMs and enterprise-grade encryption architectures. Cloud Architecture & Security - Strong cloud architecture knowledge (AWS, Azure concepts an advantage). - Experience designing secure cloud services for regulated workloads. - Strong understanding of IAM, VPC security, encryption-in-transit/at-rest, and compliance frameworks. DevOps & Automation - Experience with IaC and CI/CD pipelines (Terraform, CloudFormation, GitHub Actions, or Azure DevOps). - Background in automation for deployment, monitoring, and configuration at scale. Cross-Team Collaboration - Ability to work with Architecture, Cloud, OSM, Governance, and Security Compliance teams. - Strong experience leading POCs, pilots, and service transition activities. Governance & Operating Model - Experience defining operational models, service governance, risk assessmen
Skill Requirements
Key Responsibilities 1. Solution Architecture & Design - Design the end to end encryption solution for sensitive workloads on AWS (technical architecture, operating model, governance framework). - Integrate AWS KMS, XKS, CloudHSM with Thales HSMs and SG’s security ecosystem. - Ensure solution alignment with SG’s cloud, cybersecurity, and compliance standards. - Define dependency mapping, lifecycle management, and disaster recovery/BCP for key management services. 2. Validation & Cross Team Alignment - Present and validate the solution with Architecture teams, Security teams, and Cloud Governance. - Facilitate design reviews, architecture boards, risk assessments, and cryptographic compliance checks. - Ensure full traceability of decisions, risks, and technical controls. 3. Deployment, Automation & Documentation - Deploy and configure AWS KMS, XKS, CloudHSM environments and Thales integrations. - Automate deployment pipelines using CI/CD, infrastructure-as-code, and DevOps tooling. - Produce complete documentation (HLD, LLD, runbooks, standard operating procedures, security controls). - Build dashboards and monitoring for service health, key usage, and compliance adherence. 4. Proof of Concept (POC) & Scalability Validation - Execute a POC using a real-use case. - Evaluate performance, scalability, operational flows, and integration reliability. - Provide recommendations for optimization, security hardening, and operational efficiency. 5. Production Rollout & Service Enablement - Lead the service transition from POC to production-ready state. - Ensure the solution meets internal cloud platform criteria:- operational readiness - monitoring/alerting - secure CI/CD pipelines - service governance requirements - Build operational workflows with OSM, Operations, Cloud, and Security teams. - Drive incident response readiness, DR testing, and change control processes. 6. Knowledge Transfer & Team Upskilling - Educate and mentor team members on AWS HSM, KMS, XKS, encryption models, and cloud security. - Conduct training workshops, technical deep-dives, and documentation walkthroughs. - Help establish an internal competency framework for AWS-based key management systems Profile We are seeking an AWS Architecture & Key Management expert to design, validate, and deliver the next generation C3 encryption solution on AWS, equivalent to SG’s existing Azure based service. This role is critical to enabling regulated workloads for platforms in public cloud. The specialist will be the subject-matter expert (SME) for AWS Key Management Services, XKS (External Key Store), HSM (CloudHSM/Thales), and cloud encryption architectures. They will lead solution design, deployment, automation, validation, and production readiness—while also upskilling team members and ensuring alignment with SG’s internal cloud and security standards. You will work closely with Cloud, OSM, Architecture, and Security Governance teams across Paris, Bangalore, and Bucharest. Specific Context Required Skills & Technical Expertise Core AWS Cryptography Expertise - AWS KMS, External Key Store (XKS), CloudHSM, key lifecycle management. - Integration with Thales HSMs and enterprise-grade encryption architectures. Cloud Architecture & Security - Strong cloud architecture knowledge (AWS, Azure concepts an advantage). - Experience designing secure cloud services for regulated workloads. - Strong understanding of IAM, VPC security, encryption-in-transit/at-rest, and compliance frameworks. DevOps & Automation - Experience with IaC and CI/CD pipelines (Terraform, CloudFormation, GitHub Actions, or Azure DevOps). - Background in automation for deployment, monitoring, and configuration at scale. Cross-Team Collaboration - Ability to work with Architecture, Cloud, OSM, Governance, and Security Compliance teams. - Strong experience leading POCs, pilots, and service transition activities. Governance & Operating Model - Experience defining operational models, service governance, risk assessmen
Looking to get Placed? Try our Placement Guarantee Plan
Other Requirements
Key Responsibilities 1. Solution Architecture & Design - Design the end to end encryption solution for sensitive workloads on AWS (technical architecture, operating model, governance framework). - Integrate AWS KMS, XKS, CloudHSM with Thales HSMs and SG’s security ecosystem. - Ensure solution alignment with SG’s cloud, cybersecurity, and compliance standards. - Define dependency mapping, lifecycle management, and disaster recovery/BCP for key management services. 2. Validation & Cross Team Alignment - Present and validate the solution with Architecture teams, Security teams, and Cloud Governance. - Facilitate design reviews, architecture boards, risk assessments, and cryptographic compliance checks. - Ensure full traceability of decisions, risks, and technical controls. 3. Deployment, Automation & Documentation - Deploy and configure AWS KMS, XKS, CloudHSM environments and Thales integrations. - Automate deployment pipelines using CI/CD, infrastructure-as-code, and DevOps tooling. - Produce complete documentation (HLD, LLD, runbooks, standard operating procedures, security controls). - Build dashboards and monitoring for service health, key usage, and compliance adherence. 4. Proof of Concept (POC) & Scalability Validation - Execute a POC using a real-use case. - Evaluate performance, scalability, operational flows, and integration reliability. - Provide recommendations for optimization, security hardening, and operational efficiency. 5. Production Rollout & Service Enablement - Lead the service transition from POC to production-ready state. - Ensure the solution meets internal cloud platform criteria:- operational readiness - monitoring/alerting - secure CI/CD pipelines - service governance requirements - Build operational workflows with OSM, Operations, Cloud, and Security teams. - Drive incident response readiness, DR testing, and change control processes. 6. Knowledge Transfer & Team Upskilling - Educate and mentor team members on AWS HSM, KMS, XKS, encryption models, and cloud security. - Conduct training workshops, technical deep-dives, and documentation walkthroughs. - Help establish an internal competency framework for AWS-based key management systems Profile We are seeking an AWS Architecture & Key Management expert to design, validate, and deliver the next generation C3 encryption solution on AWS, equivalent to SG’s existing Azure based service. This role is critical to enabling regulated workloads for platforms in public cloud. The specialist will be the subject-matter expert (SME) for AWS Key Management Services, XKS (External Key Store), HSM (CloudHSM/Thales), and cloud encryption architectures. They will lead solution design, deployment, automation, validation, and production readiness—while also upskilling team members and ensuring alignment with SG’s internal cloud and security standards. You will work closely with Cloud, OSM, Architecture, and Security Governance teams across Paris, Bangalore, and Bucharest. Specific Context Required Skills & Technical Expertise Core AWS Cryptography Expertise - AWS KMS, External Key Store (XKS), CloudHSM, key lifecycle management. - Integration with Thales HSMs and enterprise-grade encryption architectures. Cloud Architecture & Security - Strong cloud architecture knowledge (AWS, Azure concepts an advantage). - Experience designing secure cloud services for regulated workloads. - Strong understanding of IAM, VPC security, encryption-in-transit/at-rest, and compliance frameworks. DevOps & Automation - Experience with IaC and CI/CD pipelines (Terraform, CloudFormation, GitHub Actions, or Azure DevOps). - Background in automation for deployment, monitoring, and configuration at scale. Cross-Team Collaboration - Ability to work with Architecture, Cloud, OSM, Governance, and Security Compliance teams. - Strong experience leading POCs, pilots, and service transition activities. Governance & Operating Model - Experience defining operational models, service governance, risk assessmen
Skills
AWSAzureTerraformGitHub ActionsCI/CDCloudFormationDevOpsCybersecurityIAMEncryptionGitHubComplianceTeamsIf a job posting appears fraudulent, asks for payment, contains misleading information, or violates our guidelines, please report it immediately. Our team will review it promptly, Jobaaj does not charge any fee from the applicants.
About Company
Important dates & deadlines?
Application Deadline
30 Nov 26, 11:55 PM IST
Similar Jobs
View AllDon't Miss out any Updates
Subscribe now for the latest job alerts
and never miss an update

