VP, Staff Cryptography Engineer
Stamford Site, United States
Applications have closed
Synchrony
Find great deals, promotional offers, credit cards, savings products, payment solutions, and more. See how Synchrony can help you today!Job Description:
Role Summary/Purpose:
TheâŻVP, Staff Cryptography Engineer willâŻserve as aâŻkey role in safeguarding enterprise multi-cloud systems, networks, and data.âŻThe positionâŻis responsibleâŻfor designing, developing, driving, implementing, leading and managing multi-cloud Information Security Engineering activities for the Cryptography program, including the underlying capabilities/technologies. In addition, this role will be responsible for acting as aâŻtrusted peer and stakeholder advisor within the organization, working closely with Information Security Engineering leadership to ensure delivery of the overall program roadmap against the Cryptography strategy and vision.Â
Â
The VP, Staff Cryptography Engineer is part of the Synchrony Information Security Cryptography Team, serving as a Cloud Security, Cryptography, Information Security, Key/Secrets Management, Privacy, Public Key Infrastructure, and Tokenization subject matter expert responsible for advancing Cryptography, Data Privacy/Protection, Key/Secrets Management multi-cloud platforms, services, systems, and best practices at Synchrony. The candidate would have an engineering position focused on delivering critical/key enterprise data protection controls, efficient supporting processes, & comprehensive automation capabilities to protect & enable Synchronyâs Information Security Engineering strategy at scale. The candidate is expected to have a strong understanding and technical work experience with Cloud Security, Cryptography, DevSecOps, Information Security, Key/Secrets Management, PKI (competency skills/work experience domains include automation, controls, governance, lifecycle management, operations, process engineering, and security standards development).Â
Our Way of Working
Weâre proud to offer you choice and flexibility. At Synchrony, our way of working allows you to have the option to work from home, near one of our Hubs or come into one of our offices. Occasionally you may be required to commute to our nearest office for in person engagement activities such as business or team meetings, training and culture events.
Essential Responsibilities:
Adopting and promoting engineering excellence by identifying efficiencies and synergies through means of automation, collaboration, and orchestrationÂ
Collaborates with architecture to identify capability gaps, develop requirements, identify solutions to address, assist with proof of concepts and testing of solutionsÂ
Implementation and technical lead responsibilities that include ongoing DevSecOps/Engineering support for a global cryptography program that leverages a portfolio of multi-cloud data protection capabilitiesÂ
Managing technology from the ground up and understanding gaps within the tech stack, including overlap with other technology and/or coverage, capability gapsâŻÂ
Maintaining technology from a business as usual (BAU) aspect by ensuring the proper change management, disasterâŻrecover, incident managementâŻprocesses are occurring and currentâŻÂ
Participate as one of several technical leads on team of Information Security engineersÂ
Participate in authoring, editing, providing, or reviewing documentation (procedures, standards) to ensure a well-managed and mature security infrastructureÂ
Partners with peers withinâŻtheâŻorganization toâŻeffectively prioritize work by using Agile processesâŻand ensuring risks, impediments, and asks are brought to leadership in a timely fashionâŻÂ
Plays a hands-on role in the engineering and implementation of multi-cloud security measures that protect enterprise applications, computer systems, information, infrastructure, and networksÂ
Plays a key role in designing and building multi-cloud solutions that safeguard the organizationsâŻplatforms and systemsâŻÂ
Provide day-to-day administration and support for multi-cloud infrastructure related to API, application security, firewalls, encryption, intrusion detection systems, PKI, secrets management, vulnerability scanning, security monitoring tools, penetration testing, authentication, web filtering, identity management, or access control systems, and their associated logs and processesÂ
Serving as a leader, mentor, and subject-matter expert (SME) to other Information Security team members and/or stakeholders throughout the organizationÂ
Serving as a SAFe Product Owner for cryptographic technologies, accountable for defining/leading/maintaining the team backlog and product roadmapÂ
Supporting a âyou build it you own itâ modelâŻâ meaning the technology built by Engineering is also supported from a wing-to-wing operations aspectÂ
Works closely with Information Security program manager, scrum master, and architects to convey technical impacts to development/engineering timeline and risksÂ
Perform other duties and/or special projects as assignedÂ
Qualifications/Requirements:
Bachelor degree with a minimum of 5 years experience in Application Development, Information Security, Systems Engineering or related field; in lieu of a degree, a High School Diploma/GED and minimum 7 years equivalent work experienceÂ
Minimum 3+ years of experience in Cloud, Cryptography, and DevSecOpsÂ
Minimum 3+ years of experience in leadership roles (as Cryptography Engineer is preferred)Â
Minimum 4+ years of experience with regulatory compliance and information security management frameworks (e.g., COBIT, ISO27001, NIST, etc.)Â
Proficient hands-on technical/working expertise with API development, API security, AWS (Certificate Manager, KMS, Private CA, Secrets Manager), Azure (Key Vault), big data, CI/CD pipelines, Cloudbees/Jenkins, Cloudera, containers, cryptography methodologies, data encryption, databases, GCP (Cloud KMS, Secret Manager) Git/Github, Go, HashiCorp Vault, Java, key/secrets management, Linux, Perl, PKI, Python, storage security, Terraform, tokenizationÂ
Desired Characteristics:
Ability to work under pressure and sustain productivity with multiple simultaneous projects across cross-functional engineering and operational information security teamsÂ
Certifications in audit, big data, cloud, cybersecurity, governance, information security, PCI, privacy, risk; AWS, Azure, CSA, GCP, GIAC, IAPP, ISC2, ISACA, PCIÂ
Cloud Security experience, especially around designing, building, managing solutions with the following vendors: AWS (Primary), Azure, GCPÂ
Cyber Security experience, especially around designing, building, managing solutionsâŻÂ
Demonstrate an understanding of business needs and commitment to delivering consistent, efficient, high quality, reliable and responsive service to the businessÂ
Demonstrated experience communicating complex and technical issues to diverse audiences (verbally and in writing), in an actionable and easy to understand manner Â
Demonstrated team focused mentality with proven experience to work effectively with diverse stakeholdersÂ
Experience with Agile, Scaled Agile (SAFe), ScrumÂ
Familiarity with problem and incident management, change management, notifications, and basic operational understanding of running and maintaining infrastructureâŻÂ
Strong interpersonal skills with an emphasis on demonstrating previous experience at effectively influencing others, cross functionally at all levels within the organizationÂ
Grade/Level: 12
The salary range for this position is 135,000.00 - 230,000.00 USD Annual and is eligible for an annual bonus based on individual and company performance.
Actual compensation offered within the posted salary range will be based upon work experience, skill level or knowledge.
Salaries are adjusted according to market in CA, NY Metro and Seattle.
Eligibility Requirements:
You must be 18 years or older
You must have a high school diploma or equivalent
You must be willing to take a drug test, submit to a background investigation and submit fingerprints as part of the onboarding process
You must be able to satisfy the requirements of Section 19 of the Federal Deposit Insurance Act.
New hires (Level 4-7) must have 9 months of continuous service with the company before they are eligible to post on other roles. Once this new hire time in position requirement is met, the associate will have a minimum 6 monthsâ time in position before they can post for future non-exempt roles. Employees, level 8 or greater, must have at least 18 monthsâ time in position before they can post. All internal employees must consistently meet performance expectations and have approval from your manager to post (or the approval of your manager and HR if you donât meet the time in position or performance expectations).
Legal authorization to work in the U.S. is required. We will not sponsor individuals for employment visas, now or in the future, for this job opening. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.Â
Our Commitment:
When you join us, youâll be part of a diverse, inclusive culture where your skills, experience, and voice are not only heardâbut valued. We celebrate the differences in all of us and believe that our individual, unique perspectives is what makes Synchrony truly a great place to work. Together, weâre building a future where we can all belong, connect and turn ideals into action. Through the power of our 8Â Diversity Networks+, with more than 60% of our workforce engaged, youâll find community to connect with an opportunity to go beyond your passions.
This starts when you choose to apply for a role at Synchrony. We ensure all qualified applicants will receive consideration for employment without regard to age, race, color, religion, gender, sexual orientation, gender identity, national origin, disability, or veteran status.
Reasonable Accommodation Notice:
Federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job or to perform your job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.
If you need special accommodations, please call our Career Support Line so that we can discuss your specific situation. We can be reached at 1-866-301-5627.  Representatives are available from 8am â 5pm Monday to Friday, Central Standard Time
Job Family Group:
Information TechnologyTags: Agile APIs Application security Automation AWS Azure Big Data CI/CD Cloud COBIT Compliance Cryptography DevSecOps Encryption Firewalls GCP GIAC GitHub Governance Intrusion detection ISACA ISO 27001 Java Jenkins Linux Monitoring NIST Pentesting Perl PKI Privacy Python Scrum Strategy Terraform
Perks/benefits: Career development Gear Insurance Salary bonus Signing bonus Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.