Sr Specialist Cybersecurity - Encryption Solutions / PKI / Digital Certificates / Cryptographic operations / Key and Secrets Management (Venafi/KeyFactor, Vormetric/Cipher Trust, Voltage, HashiCorp Vault)
Att
·Today
- Location
- IND:AP:Hyderabad / Argus Bldg 4f & 5f, Sattva, Knowledge City- Adm: Argus Building, Sattva, Knowledge City, India · Bangalore, India
- Workplace
- Remote
- Type
- Full-time
- Department
- IT
- Experience
- 8+ years
- Education
- Master
- Closing date
- Today
- Source
- Workday
Description
Senior Specialist – Encryption Solutions
Job Description:
About the Company:
Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won’t just imagine the future-you’ll create it.
About the Job:
We are seeking a highly experienced Senior Specialist to join our Cybersecurity team, responsible for digital certificate management and enterprise encryption solutions. The role requires strong expertise in PKI, cryptography, certificate lifecycle management, and encryption services to ensure secure communications and data protection across the enterprise. This position partners closely with application, infrastructure, and security teams to operate, scale, and improve certificate, key, and encryption services in a compliant and resilient manner, with hands‑on involvement in tooling, automation, and regulatory alignment.
Experience Level: 8+ years.
Location: Hyderabad / Bengaluru
Responsibilities Include:
Manage and operate enterprise digital certificate and PKI services, managing the full certificate lifecycle including provisioning, renewal, revocation, cross‑certification, and proactive expiration management across complex environments.
Support enterprise encryption solutions to ensure strong data protection for applications, platforms, and infrastructure, covering data‑at‑rest, data‑in‑transit, and data‑in‑use.
Manage cryptographic keys and secrets across their lifecycle, including secure generation, storage, rotation, access controls, backup, recovery, and secure retirement.
Ensure cryptographic governance and compliance, aligning PKI, encryption, and key management practices with internal security policies, industry standards, and regulatory requirements.
Partner with engineering and platform teams to enable secure integration of certificates, encryption, and key management into applications, cloud services, and automated delivery pipelines.
Design and implement automation, monitoring, and alerting to improve the reliability, scalability, and operational efficiency of certificate and encryption services.
Provide advanced operational support and incident response, troubleshooting complex certificate, encryption, or key‑management issues and supporting investigations involving compromise or cryptographic failures.
Leverage data analytics and AI‑driven capabilities to enhance visibility, predict risks (such as certificate expirations or misconfigurations), and drive operational efficiencies across PKI and encryption services.
Stay current with emerging cryptographic technologies, threats, and AI advancements, and apply relevant innovations to strengthen security posture and reduce manual effort.
Contribute to documentation, standards, and knowledge sharing, providing technical guidance, mentoring peers, and collaborating across security, infrastructure, and DevOps teams.
Demonstrate flexibility in operational support, including providing coverage during U.S. morning hours and participating in shift‑based and weekend support rotations as needed.
Required skills:
Overall : 8+ years of experience supporting enterprise PKI, digital certificates, encryption, and cryptographic operations, including key and secrets management.
1) Core PKI, Cryptography & Security
Strong expertise in X.509 certificates, chains, CRLs, OCSP, and complex CA hierarchies.
Proven experience managing certificate lifecycles at scale, including renewal, revocation, replacement, and trust models.
Solid foundation in cryptography: symmetric/asymmetric encryption, hashing, digital signatures, and key exchange.
Hands-on experience with key management controls, including generation, protection, rotation, backup/recovery, and secure destruction.
Working knowledge of enterprise encryption patterns (data at rest/in transit, tokenization/FPE) and application/infrastructure integration.
Ability to lead operations, mentor team members, and collaborate across security, DevOps, infrastructure, and application teams.
Experience integrating crypto services with IAM/SSO/MFA and aligning to NIST, FIPS, ISO 27001, and internal security policies.
Strong understanding of security protocols such as TLS/SSL, HTTPS, SSH, S/MIME, IPsec/VPN, DNS, and LDAP.
2) Encryption, Key & Secrets Enablement
Experience supporting enterprise encryption services across applications, servers, databases, and cloud platforms.
Strong understanding of secrets management principles, including access controls, rotation, auditing, and break‑glass procedures.
Ability to define secure integration patterns for engineering teams using least privilege and secure‑by‑design principles.
3) Tools & Technologies
Hands-on experience with PKI and crypto utilities (e.g., OpenSSL, keytool, certutil) and certificate troubleshooting.
Familiarity with enterprise certificate and CA platforms and certificate automation frameworks.
Working knowledge of enterprise data encryption technologies, including data at rest encryption and advanced encryption techniques such as tokenization and format preserving encryption.
Experience operating HSMs or hardware backed key protection, including HA and backup/restore concepts.
Knowledge of ACME-based certificate automation and renewal models.
4) Monitoring, Incident Response & Compliance
Experience implementing certificate expiration and crypto service monitoring to prevent outages.
Strong skills in logging, auditing, and compliance evidence for PKI, encryption, and key operations.
Proven ability to troubleshoot complex crypto issues and support incident response and root‑cause analysis.
Clear documentation skills for audits, runbooks, and operational knowledge bases.
5) Automation & AI‑Enabled Efficiency
Hands-on automation experience using Python, PowerShell, and/or Bash, including API integrations.
Familiarity with infrastructure automation and CI/CD tools (e.g., Ansible, Terraform, Jenkins, GitHub Actions).
Experience integrating REST APIs for certificate, key, and encryption services.
Exposure to prompt engineering concepts to design clear, secure, and context-aware prompts for improving AI-assisted troubleshooting, documentation, analysis, and operational decision-making.
Familiarity with large language models (LLMs) such as GPT, Claude, Gemini, or similar GenAI platforms, with the ability to evaluate practical use cases for cybersecurity and encryption operations.
Ability to leverage LLM-assisted workflows for summarizing logs, generating runbooks, drafting technical documentation, identifying patterns, and accelerating knowledge retrieval.
Understanding of responsible and secure GenAI usage, including data sensitivity, prompt hygiene, validation of AI-generated outputs, and alignment with enterprise security policies.
Ability to explore and implement AI-enabled productivity improvements that reduce manual effort, improve response time, and enhance operational consistency across PKI and encryption services.
Desirable skills:
Bachelor's or master's degree in computer science, mathematics, information systems, engineering, or cybersecurity.
Industry certifications such as CEH, CISSP, SANS and/or other relevant certifications.
Ability to prioritize individual/group work in a high-stress and time-bound environment
Excellent communication, problem-solving, and analytical skills.
Ability to work independently and as part of a team.
Additional information (if any):
Should be flexible to provide coverage in US morning hours
Should be flexible with shifts and supporting on weekends
#Cybersecurity
Weekly Hours:
40Time Type:
RegularLocation:
Bangalore, India, Hyderabad, IndiaIt is the policy of AT&T to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, AT&T will provide reasonable accommodations for qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made.