

Sr. Encryption Engineer
β - Featured Role | Apply direct with Data Freelance Hub
This role is for a Sr. Encryption Engineer, a 12+ month remote contract, offering competitive pay. Candidates must have 3+ years of encryption experience, expertise in Format-preserving encryption (FPE) with Voltage, and familiarity with PKI, cryptographic platforms, and cloud environments.
π - Country
United States
π± - Currency
$ USD
-
π° - Day rate
560
-
ποΈ - Date discovered
July 26, 2025
π - Project duration
More than 6 months
-
ποΈ - Location type
Remote
-
π - Contract type
Unknown
-
π - Security clearance
Unknown
-
π - Location detailed
Chicago, IL
-
π§ - Skills detailed
#Azure Security #Documentation #Trend Analysis #Programming #AWS (Amazon Web Services) #.Net #Deployment #REST (Representational State Transfer) #API (Application Programming Interface) #Java #Classification #Leadership #Security #Cloud #GCP (Google Cloud Platform) #Scripting #PCI (Payment Card Industry) #Data Security #Azure #REST API #Jira
Role description
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
LHH is working with a Financial Services client based in the Chicago Loop that is looking to hire a Sr. Encryption Engineer to join our team for a 12+ month project. The role will be 100% remote. The ideal candidate will have 3+ years of Encryption experience, some Cryptography, and PKI.
Candidates MUST have Format-preserving encryption (FPE) with Voltage to be considered and be able to speak about it in your resume.
Brief Overview of Position
The Senior Encryption Engineer leads first line of defense Information Security services around data protection security and related matters. They review, design and develop security operational processes, standards, and procedures utilizing current and new technologies to improve security controls and business performance. The Senior Encryption Engineer will coordinate with internal teams to implement data security solutions and improve security that is aligned with corporate business objectives and regulatory requirements.
Responsibilities
β’ Subject Matter Expertise - Lead the design, implementation, and maintenance of enterprise encryption program/services solutions to business areas, project teams and vendors to apply and execute appropriate use of technology solutions and leads efforts to examine technology vision, opportunities, and challenges with regard to security standards and the impact of the technology. Create technical detailed implementation plan for desired state
β’ Security Trends - Evaluate and understand current state of enterprise encryption capabilities/services. Continually works to enhance breadth and depth of knowledge and experience. Monitors and anticipates trends and investigates organizational objectives and needs.
β’ Reporting -Create and maintain operational documentation and reports to support monthly trend analysis as well as project components
β’ Business As Usual - Implement and monitor all online PKI server components, monitor, and troubleshoot PKI logs for errors and warnings and perform daily health-checks for PKI solution platforms. Will also be responsible for the day-to-day management and oversight on all on prem and cloud key management platforms to preserve separation of duty with teams leveraging symmetric, asymmetric keys and certificates.
β’ Vendor/Tool Selection β Leads the research, evaluation, proof-of-concept, selection, and implementation of technology solutions. Provides detailed analysis of pros and cons and build vs buy options.
β’ Process Improvement - Promotes implementation of new technology, solutions and methods to improve business processes, efficiency, effectiveness and value delivered to customers. Perform gap analysis between current state and desired state of enterprise encryption program/services and document findings
β’ Incident Response β Is involved in security incident response activities and post-event reviews of security incidents.
Additional Responsibilities
β’ Lead implementation of the Voltage Data Protection Platform from design to deployment.
β’ Oversee tokenization and encryption strategies using Voltage.
β’ Evaluate and onboard 1000+ applications for sensitive data protection solutions.
β’ Conduct data security and risk assessments and contribute to data protection policies.
β’ Write, implement, and maintain data security standards aligned with regulatory and industry best practices.
β’ Collaborate cross-functionally to support REST API integrations, CI/CD pipelines, and development in Java, C, or .NET.
β’ Manage user testing workflows and tickets throughout implementation.
β’ Document technical solutions and operational processes using Confluence and JIRA.
β’ Apply expertise to secure data, manage digital certificates, and enforce cryptographic controls.
β’ Provide architectural input and technical leadership on data protection strategies.
The duties listed above are the essential functions, or fundamental duties within the job classification. The essential functions of individual positions within the classification may differ.
Qualifications
β’ 3+ years of operational experience is required; must have implemented and managed PKI, Key Management systems, Data Masking platforms, HSMs and other cryptographic technology platforms. Must possess strong technical knowledge of cryptographic platform architecture, system policies, rules, etc
β’ MUST HAVE Format-preserving encryption (FPE) with Voltage
β’ Understanding of concepts involving Hardware Security Modules (HSM), Enterprise Key Management, applying Encryption at various levels of granularity
β’ Ability to understand requirements and problem-sets and design solutions to address their PKI or encryption needs
β’ Experience with multiple CA (certificate authority) vendors and platforms
β’ Experience with installing and configuring certificates in multiple application types
β’ Familiarity with AWS, AWS Cloud HSM, AWS Certificate Manager (ACM), AWS Key Management Solution (KMS)AWS Private Certificate Authority (ACM PCA), Azure Electronic Key Management (EKM) Microsoft two or three tier PKI, managed PKI services
β’ Experience with multiple cryptographic algorithms and cipher suites as well as up to date on deprecated algorithms for decommissioning.
β’ Strong verbal and written communications skills; must be able to effectively communicate technical details and thoughts in non-technical/general terminology to various levels of the organization.
β’ Knowledge of Data Security best practices and security solutions
β’ Knowledge in a cloud-based environment (Azure, AWS, GCP)
β’ Knowledge of common technologies, enterprise and network architecture
β’ Understanding of:
β’ Modern security tools and controls
β’ Programming languages or other scripting languages
β’ Financial industry regulations such as GLBA, PCI, and SOX
β’ Knowledge of or demonstrated experience with defense in depth, trust levels, privileges and permissions
Additional Required Skills:
Deep knowledge of data security, encryption, tokenization.
Hands-on experience with Voltage or similar data protection platforms.
Strong background writing data security assessments and security standards.
Familiarity with REST APIs, CI/CD tools, and programming in Java, C, or .NET.
Experience with documentation tools like Confluence and JIRA.
Excellent cross-functional collaboration and communication skills.
Nice to Have:
Experience with Thales/Voltage data protection solutions.
Security or cloud certifications (e.g., CISSP, AWS/Azure security certs).