Sign Up Sign Up Log In Sign Up

Cloud Encryption Engineer, Senior

Job Number: R0061145

Cloud Encryption Engineer, Senior

The Challenge:

Everyone knows security needs to be “baked in” to a system architecture, but you actually know how to bake it in. You can identify and implement Cybersecurity solutions to protect the confidentiality, integrity, and availability of information with encryption solutions in leading commercial Clouds like Amazon Web Services (AWS), Salesforce, and Office 365. What if you could use your Cyber engineering skills to design and build Cybersecurity solutions in the Cloud to protect personal, financial, health, and other sensitive information for government agencies and global enterprises? We’re looking for an experienced engineer who can create advanced encryption solutions in the Cloud that will stand up to even the most advanced cyber threats.

As a Senior Cloud Encryption Engineer at Booz Allen, you’ll research, design, and implement Public Key Infrastructure (PKI), data at-rest, and data in-transit encryption solutions to protect our client's most sensitive information in commercial Infrastructure, Platform, and Software as a Service clouds. You’ll coordinate with investment teams, executives, clients, and industry leading vendors to identify the right mix of tools and techniques to translate your customer’s goals into a plan that will enable secure and effective Cloud hosted solutions. We need to come up with the best solution, so you’ll investigate new techniques, break free from the legacy model, and go where the industry is going. You’ll lead the team through a critical approach to design, providing alternatives and customizing solutions to maintain a balance of security and mission needs. This is a chance to make a difference in the security of our country's financial markets, warfighters, citizen services, and healthcare. Your technical expertise will be vital as you help customers overcome their most difficult challenges by integrating security best practices like end-to-end encryption, PKI, Key Management Systems, and Hardware Security Modules (HSM). You’ll be able to broaden your skillset into modern areas of cryptography like homomorphic encryption, tokenization, and automated key management to support dynamic and immutable Cloud infrastructure. Join our team as we deliver innovative Cybersecurity solutions to protect our client's information in the Cloud.

Empower change with us.

Build Your Career:

Rewarding work, fun challenges, and a ton of investment in our people—that’s Booz Allen Cyber. When you join Booz Allen, we’ll help you develop the career you want.

Competitions — From programming competitions at our PyNights (Python competition and learning events) to competing in CTFs, we’ve got plenty of chances for you to show off your skills.

Paid Research — Have an innovative idea to explore or hypothesis to test? You can participate in challenges via our crowdsourcing platform, the Garage, and other programs to be awarded dedicated time and/or funding to advance your skills.

Cyber University — CyberU has more than 5,000 instructor-led and self-paced Cyber courses, a free online library that you can access from just about anywhere—including your phone—and certification exam prep guides that include practical assessments to prepare you for your exam.

Academic Partnerships — In addition to our tuition reimbursement benefit, we’ve partnered with University of Maryland University College to offer two graduate certificate programs in Cybersecurity—fully funded without a tuition cap.

Maker/Hackerspaces — Race drones, print 3D gadgets, drink coffee from our Wi-Fi coffee maker, and get hands-on training on tools and tech from in-house experts in our dedicated maker and hackerspaces.

You Have:

-5+ years of experience with the industry or government

-Experience with a wide range of cryptography solutions to secure data at rest and in transit in IT systems

-Experience with applying Cloud-native and 3rd party encryption solutions to protect information hosted in Cloud providers, including AWS, Microsoft Azure, and Google Cloud Platform (GCP)

-Experience with PKI solutions for user and system encryption and authentication, Microsoft Windows Server, and Linux operating systems

-Knowledge of NIST cryptographic standards and FIPS-validated and DoD-approved cryptography, FISMA, FedRAMP, PCI, RMF and DoD Cybersecurity policies and control frameworks, and modern encryption algorithms such as IPSec and TLS

-Ability to analyze requirements, design, implement, and operate modern encryption solutions to protect the confidentiality and integrity of information, including PKI and KMS

-Ability to educate and inform clients on cryptography concepts, including symmetric and asymmetric encryption, PKI, authentication, TLS, perfect forward secrecy, and break-and-inspect and how they can be applied to protect information, communicate and convey complex cryptographic solutions and concepts to a wide range of stakeholder audiences, and create technical artifacts, including logical and physical network diagrams, technical specifications, system installation procedures, and bills of materials

-Secret clearance

-BA or BS degree

-Security+ Certification

Nice If You Have:

-Experience with Gemalto SafeNet, Entrust Datacard, Vormetric, and Thales cryptography solutions

-Experience with implementing AWS Cloud native encryption solutions, including CloudHSM, KMS, and Certificate Manager

-Experience with containerization technologies and platforms, including Docker, Kubernetes, and OpenShift

-Experience with writing proposals, whitepapers, and other technical marketing materials to compete for and win new business

-Experience with applying automation techniques to the management of keys and encryption of data

-Knowledge of tokenization technologies and approaches to protect sensitive information hosted in Cloud environments and in financial transactions

-Ability to develop code or scripts using Python, JavaScript, or other programming languages

-Ability to lead a team of engineers in the development of complex integrated solutions

-BA or BS degree in a Math, Science, or Engineering field

-CISSP Certification

-Cloud Certifications for AWS, GCP, or Microsoft Azure


Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required.

We’re an EOE that empowers our people—no matter their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, veteran status, or other protected characteristic—to fearlessly drive change.

Company Name:
Security Clearance:
McLean, Virginia
United States
Not Specified
Job Number:

Send me email alerts for similar jobs