Who We Are Looking For
State Street is seeking a Cryptographic Key Management Operations Engineer to support the end-to-end lifecycle management of cryptographic keys across cloud, on-premises, infrastructure, and IoT environments. This role is responsible for ensuring the secure generation, distribution, rotation, revocation, and retirement of encryption keys while maintaining compliance with regulatory requirements, industry standards, and enterprise security policies.
The ideal candidate combines strong technical expertise in cryptography and key management operations with a mindset focused on operational excellence, automation, and continuous improvement. You will work closely with cybersecurity, cloud, infrastructure, and application teams to maintain the availability, reliability, and security of enterprise key management services that support critical financial systems and business operations.
What You Will Be Responsible For
- Support the day-to-day operation and security of enterprise cryptographic key management services, ensuring compliance with financial industry regulations and standards, including PCI DSS, GDPR, FIPS 140-3, and NIST guidance.
- Manage the complete cryptographic key lifecycle, including secure key generation, storage, distribution, rotation, revocation, escrow, and retirement across cloud, on-premises, and IoT environments.
- Monitor, investigate, and respond to key management incidents, including key compromise, expiration, policy violations, and operational failures, ensuring timely remediation and risk mitigation.
- Maintain the availability, integrity, and security of key management infrastructure, troubleshooting issues and ensuring adherence to service level objectives.
- Partner with cybersecurity, cloud, infrastructure, engineering, and DevSecOps teams to integrate cryptographic services into enterprise applications, platforms, and security frameworks.
- Automate and optimize key management processes using APIs, Key Management Systems (KMS), infrastructure-as-code (IaC), and security orchestration technologies.
- Support secure transaction processing and data protection by ensuring highly available and resilient key management services.
- Develop and maintain operational procedures, standards, runbooks, and technical documentation related to key management services.
- Produce operational, compliance, and risk reporting related to key usage, lifecycle events, service performance, and audit requirements.
- Stay current with emerging cryptographic technologies, evolving threat landscapes, post-quantum cryptography developments, and regulatory requirements to continuously improve key management practices.
What We Value
- Strong analytical and problem-solving skills with the ability to troubleshoot complex cryptographic and infrastructure-related issues.
- A proactive approach to operational excellence, automation, and continuous service improvement.
- The ability to work effectively across multiple teams and disciplines in a highly regulated and security-focused environment.
- Strong communication skills, with the ability to translate technical concepts into clear operational and business outcomes.
- A risk-focused mindset with a commitment to maintaining the confidentiality, integrity, and availability of sensitive data and cryptographic assets.
- A passion for staying current with advances in cryptography, cloud security, emerging technologies, and industry best practices.
- Attention to detail and a commitment to maintaining high standards of security, governance, and operational discipline.
Education & Preferred Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Engineering, or a related field; equivalent practical experience will also be considered.
- 3+ years of experience supporting cryptographic operations, key management platforms, information security, or cybersecurity services within a financial services organization or other regulated industry.
- Strong understanding of cryptographic key lifecycle management, including symmetric and asymmetric encryption, Public Key Infrastructure (PKI), certificate management, and Hardware Security Modules (HSMs).
- Hands-on experience with enterprise key management solutions such as AWS KMS, Azure Key Vault, OCI Vault, and Fortanix DSM.
- Knowledge of security and compliance standards including PCI DSS, FIPS 140-3, NIST, ISO 27001, and related regulatory requirements.
- Experience supporting cloud-native security services and enterprise encryption implementations.
- Familiarity with IoT security, embedded cryptography, and device identity management.
- Experience leveraging SIEM and monitoring platforms to support security operations and key access monitoring.
- Experience with automation and scripting technologies such as Python, PowerShell, Terraform, or similar tools.
- Familiarity with Agile delivery methodologies and collaboration tools such as Jira and Confluence.
- Security certifications such as CISSP, CISM, CCSP, AWS Security Specialty, or equivalent certifications are preferred.
- Exposure to post-quantum cryptography (PQC), cryptographic agility programs, and emerging cryptographic frameworks is highly desirable.
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
Skills Required
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Engineering, or related (or equivalent experience)
- 3+ years supporting cryptographic operations, key management platforms, or cybersecurity services in financial or regulated industries
- Strong understanding of cryptographic key lifecycle, symmetric/asymmetric encryption, PKI, certificate management, and HSMs
- Hands-on experience with enterprise key management solutions such as AWS KMS, Azure Key Vault, OCI Vault, and Fortanix DSM
- Knowledge of security and compliance standards including PCI DSS, FIPS 140-3, NIST guidance, and ISO 27001
- Experience supporting cloud-native security services and enterprise encryption implementations
- Experience leveraging SIEM and monitoring platforms for security operations and key access monitoring
- Experience with automation and scripting technologies such as Python, PowerShell, and Terraform
- Familiarity with IoT security, embedded cryptography, and device identity management
- Familiarity with Agile delivery methodologies and collaboration tools such as Jira and Confluence
- Security certifications such as CISSP, CISM, CCSP, or AWS Security Specialty
- Exposure to post-quantum cryptography (PQC) and cryptographic agility programs
State Street Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about State Street and has not been reviewed or approved by State Street.
-
Retirement Support — Retirement support is framed as a standout component, highlighted by a 401(k) match described as 100% on the first 6% of base salary. This is positioned as a meaningful offset to less competitive cash compensation for some roles.
-
Leave & Time Off Breadth — Leave and time off are portrayed as relatively robust, with references to multi-week vacation, paid holidays, sick time, and additional days tied to wellness or volunteering. This breadth is repeatedly treated as a tangible part of total rewards beyond base pay.
-
Wellbeing & Lifestyle Benefits — Wellbeing and lifestyle benefits are presented as extensive, including the BeWell program, fitness discounts, onsite or supported health resources, and financial counseling. These offerings are depicted as strengthening the overall benefits proposition even when pay satisfaction is tepid.
State Street Insights
What We Do
At State Street, we partner with institutional investors all over the world to provide comprehensive financial services, including investment management, investment research and trading, and investment servicing. Whether you are an asset manager, asset owner, alternative asset manager, insurance company, pension fund or official institution, you can rely on us to be focused on your challenges. We are committed to doing what it takes to help you perform better — now and in the future

.jpeg)





