Amgen Technology Pvt Ltd. Posted July 21, 2026

Encryption Agility Service Lead

Hyderabad, India Full time
Information Technology

Amgen Technology Pvt Ltd. is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

Career Category

Information Systems

Job Description

Role Name: Senior Manager Information Security - Encryption Agility Service Lead

Job Posting Title: Sr. Manager Information Security - Encryption Agility Service Lead

Workday Job Title: Sr. Manager Information Security

Department Name: Trusted Core Technologies

Role GCF: 6A

ABOUT AMGEN

Amgen harnesses the best of biology and technology to fight the world's toughest diseases, and make people's lives easier, fuller and longer. We discover, develop, manufacture and deliver innovative medicines to help millions of patients. Amgen helped establish the biotechnology industry more than 40 years ago and remains on the cutting-edge of innovation, using technology and human genetic data to push beyond what's known today.

ABOUT THE ROLE

Role Description:

The Senior Manager Information Security - Encryption Agility Service Lead is accountable for establishing, leading, and operating Amgen's enterprise Encryption Agility Service for Post-Quantum Readiness Preparation. This role will lead the Encryption Agility Team and be considered Amgen’s Cryptographic Center of Excellence! The team will own and manage the enterprise service for encryption, cryptography, crypto agility, and post-quantum cryptography readiness across Amgen. The role combines people leadership, security architecture, program execution, and hands-on cryptographic expertise across applications, cloud, infrastructure, identity, PKI, certificates, KMS, secrets, data protection, OT coordination, and the third-party ecosystem. The role partners closely with the Principal Architect, Digital Identity Access Services (DIAS), PKI and certificate service owners, Enterprise Architecture, Application Security, Governance Risk and Compliance, Procurement, Legal, Infrastructure, Cloud, Manufacturing/OT, and vendor teams to translate Amgen's PQC roadmap into governed standards, enforceable controls, measurable inventory, and prioritized remediation. The ideal candidate has strong people leadership skills, deep technical understanding of cryptography and cybersecurity, and experience managing large-scale enterprise security programs in a global, regulated environment.

Roles & Responsibilities:

Establish, operate, and continuously improve the enterprise Encryption Agility Team and Service, including the service charter, governance model, operating cadence, intake process, Responsible, Accountable, Consulted, and Informed (RACI) model, roadmap, Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), executive reporting, and service improvement plan.

Lead, coach, mentor, and manage Encryption Agility Team members, including Amgen full-time employees (FTEs), external workers, cryptographic engineers, security architecture analysts, product ownership support, and part-time contributors from partner teams.

Partner with the Principal Architect to translate enterprise Post-Quantum Cryptography (PQC) strategy into standards and specifications, reference architectures, implementation patterns, practical engineering guidance, remediation backlogs, and production-ready cryptographic design decisions.

Own the enterprise cryptographic standards and specifications roadmap, including approved algorithms, key sizes, protocols, Transport Layer Security (TLS) and cipher policies, certificate requirements, Key Management Services (KMS) and secrets requirements, exception criteria, Rivest-Shamir-Adleman (RSA) and Elliptic Curve Cryptography (ECC) sunset planning, and annual standards refresh.

Lead delivery across the full PQC lifecycle, including assessment wrap-up, quick wins, discovery tooling selection, iterative discovery, vendor and third-party outreach, PQC architecture, testing and trials, production rollout, automation, monitoring, and steady-state service operations.

Build, govern, and mature the Amgen Cryptographic Bill of Materials (CBOM), including required fields, asset ownership, quantum-vulnerability status, remediation status, data quality controls, reporting requirements, and integration of cryptographic inventory and risk data across relevant Amgen platforms.

Direct enterprise cryptographic discovery across source code, binaries, cloud key services, endpoints, file systems, network traffic, Public Key Infrastructure (PKI) and certificates, KMS and secrets, vendor attestations, and Subject Matter Expert (SME) interviews to create a reliable enterprise cryptographic inventory.

Apply the approved PQC risk-prioritization approach to sequence discovery and remediation for business-critical applications, high-volume sensitive data flows, identity services, third-party dependencies, legacy platforms, Key Computerized Systems (KCS), and validated Good x Practice (GxP) systems.

Coordinate with Digital Identity Access Services (DIAS), PKI service owners, certificate management teams, cloud, infrastructure, and platform teams on certificate visibility, Certificate Lifecycle Manager (CLM) evaluation, certificate rotation policy, manual-to-automated deployment migration, post-quantum PKI readiness, hybrid certificate testing, Certificate Authority (CA) roadmap, operational change windows, enterprise KMS strategy, Hardware Security Module (HSM) and cloud KMS roadmaps, secrets management, key rotation, key retirement, and centralized or federated key management control patterns.

Partner with Application Security, Secure Software Development Lifecycle (SSDLC), DevOps, Artificial Intelligence (AI) Security, Enterprise Architecture, and engineering teams to publish approved cryptographic libraries, reusable patterns, Continuous Integration/Continuous Delivery (CI/CD) controls, scanning rules, secure code examples, and remediation playbooks.

Coordinate with Risk and Compliance, Legal, Procurement, Third-Party Risk Management (TPRM), and vendor management to implement PQC questionnaires, CBOM requests, contract language, supplier roadmap tracking, risk acceptance, and executive escalation for vendors and Software as a Service (SaaS) providers.

Provide senior technical escalation and hands-on leadership for cryptographic standards exceptions, scan findings, false-positive triage, certificate outages, key and secret configuration issues, tool integration blockers, design tradeoffs, Steal-Now-Decrypt-Later (SNDL) exposure, identity and certificate risks, outdated TLS and cipher configurations, legacy cryptography, untracked keys, manual certificate processes, Operational Technology (OT) and manufacturing scope definition, developer and stakeholder enablement, and changes in National Institute of Standards and Technology (NIST), Internet Engineering Task Force (IETF), National Security Agency Commercial National Security Algorithm (NSA/CNSA) Suite, International Organization for Standardization (ISO), Health Insurance Portability and Accountability Act (HIPAA), Health Information Trust Alliance (HITRUST), and industry cryptography guidance.

Basic Qualifications and Experience:

Doctorate degree and 2 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience OR

Master's degree with 8 to 10 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience OR

Bachelor's degree with 10 to 14 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience OR

Diploma with 14 to 18 years of Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related experience

Functional Skills:

Must-Have Skills:

Expert knowledge of enterprise cryptography, including PKI, X.509 certificates, TLS, cipher suites, KMS/HSM, secrets management, key lifecycle, encryption at rest and in transit, and cloud key services.

Proven experience leading global information security, security architecture, or cryptography programs, including roadmap ownership, team management, resource planning, metrics, reporting, and executive stakeholder management.

Practical knowledge of post-quantum cryptography, crypto agility, NIST-approved algorithms and standards, hybrid/PQC transition patterns, cryptographic discovery, and CBOM-driven remediation.

Ability to translate security policy into enforceable controls across CI/CD, cloud platforms, identity, PKI/certificates, infrastructure, applications, third-party governance, and risk management.

Good-to-Have Skills:

Hands-on experience with ServiceNow CMDB/GRC, Guard, Wiz, Qualys, Fortinet, Netskope, CrowdStrike, GitLab, Veracode, AWS KMS/ACM/Secrets Manager, Microsoft PKI, Sectigo, HashiCorp Vault, HSMs, CLM, and SIEM/data lake integrations.

Experience designing or operating CBOM/SBOM data models using CycloneDX 1.6+, APIs, CSV/JSON exports, dashboards, and data quality controls.

Experience coordinating PKI and certificate operations with DIAS or equivalent infrastructure and certificate service owners.

Experience in validated/GxP, manufacturing, OT, KCS, or highly regulated environments, including change control and revalidation impacts.

Experience with vendor and third-party risk management, supplier cryptographic questionnaires, contract requirements, and vendor roadmap tracking.

Scripting and automation experience with Python, PowerShell, Bash, REST APIs, or data pipeline tooling.

Professional Certifications:

CISSP (required)

CISM, CISA, or CRISC (preferred)

CCSP or cloud security certification such as AWS Certified Security - Specialty or Azure Security Engineer (preferred)

TOGAF or SABSA (preferred)

ITIL, SAFe, product management, or program management certification (preferred)

Relevant PKI, KMS, HSM, cryptographic discovery, or certificate lifecycle management vendor certifications (preferred)

Soft Skills:

Excellent people leadership, coaching, mentoring, and performance management skills.

Strong executive presence and ability to translate complex cryptographic risk into clear business impact and action plans.

Strong verbal and written communication skills for technical, business, legal, procurement, compliance, and executive audiences.

Ability to influence without direct authority across global security, DTI, DIAS, procurement, legal, compliance, OT, infrastructure, and application teams.

High degree of initiative, accountability, judgment, and self-motivation in ambiguous or evolving technical domains.

Ability to manage multiple priorities, competing stakeholder needs, and long-running transformation roadmaps successfully.

Team oriented, with a focus on shared outcomes, practical implementation, and service maturity.

Ability to balance hands-on technical analysis with service ownership, people leadership, and enterprise change management.

EQUAL OPPORTUNITY STATEMENT

Amgen is an Equal Opportunity employer and will consider you without regard to your race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.

We will ensure that individuals with disabilities are provided with reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request an accommodation.

.

Job details

Seniority
Not listed
Function
Information Technology
Therapeutic area
Not listed
Location
Hyderabad, India
Employment type
Full time

How this role compares

Computed from every other active Information Technology role in our database, not just this employer's listings.

We currently track 1097 comparable Information Technology roles across 55 biopharma companies.

1097Comparable roles tracked
1035Currently active
55Companies hiring similar roles
29Countries represented

Salary context

143 of 1097 peers report a salary range (USD, annualized)

Peers share this role's job function. This posting doesn't list a seniority level, so peers aren't narrowed by seniority either -- the range below may span more levels than usual.

This roleSubject Not listed on this posting
Lowest disclosed · Senior Data Security Engineer (Insider Risk Management – Engineering) · AbbVie $0/hr – $0/hr (≈ $0–$0/yr)
Highest disclosed · Senior Director, Targets and Mechanisms Solutions · Pfizer $230,900/yr – $384,800/yr
Peer group range $0 – $307,850 (median $165,900)

Where these roles are based

Top locations among the 1097 comparable roles

India506
United States241
Spain106
Poland72
Portugal32
China13

+ 23 more countries

Seniority mix

612 of 1097 peers have a known seniority level

Senior290
Manager135
Associate52
Principal50
Associate Director39
Director28
Senior Director13
Intern/Fellow/Postdoc4
Executive/VP1

Therapeutic area mix

1 of 1097 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden

Oncology1

Similar opportunities

The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.

40%similar
Novartis Hyderabad (Office), India Associate Director
Same function Same country
40%similar
Novartis Hyderabad (Office), India Associate Director
Same function Same country
40%similar
Novartis Hyderabad (Office), India Director
Same function Same country
40%similar
Novartis Hyderabad (Office), India Director
Same function Same country
40%similar
Regeneron India Private Limited Hyderabad, India Senior Director
Same function Same country
40%similar
Regeneron India Private Limited Hyderabad, India Director
Same function Same country

How we calculate "similar"

No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.

Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.

40%
Associate Director, Technical Project Management & Digital Enablement(Sharepoint)
Novartis · Hyderabad (Office), India · Associate Director
Function Therapeutic area Seniority Country
40%
Director - Data & Analytics Integration & Eventing Platforms
Novartis · Hyderabad (Office), India · Director
Function Therapeutic area Seniority Country
40%
Director Information Security - GCC India & JAPAC
Regeneron India Private Limited · Hyderabad, India · Director
Function Therapeutic area Seniority Country
40%
Software Engineer II Workday Integrations
Bristol-Myers Squibb Business Services India Private Limited · Hyderabad, India · Seniority not listed
Function Therapeutic area Seniority Country
Unmatched or unknown dimensions score exactly the same: 0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.