About the Role
The Managing Director, Head of Cryptography is a senior leadership role responsible for defining, governing, and advancing the firm's enterprise cryptography, key management, secrets management, and cryptographic modernization strategy. This leader will ensure the confidentiality, integrity, authenticity, and resilience of critical systems, applications, data, and digital transactions through industry-leading cryptographic controls and services. The role requires a forward-thinking technical executive capable of driving enterprise-scale transformation across cloud, hybrid, and emerging technology environments, evolving cryptographic capabilities to support modern architectures, AI-enabled platforms, cloud-native services, machine identities, and future threats, including quantum computing risks. This executive will partner closely with Infrastructure, Cloud Engineering, Application Development, Data, Security Architecture, IAM, and Enterprise Architecture teams to ensure cryptography is embedded by design across the organization's technology ecosystem.
Responsibilities
- Define and execute the firm's comprehensive cryptography strategy, roadmap, and governance framework.
- Establish enterprise standards and policies covering encryption at rest, encryption in transit, key management, secrets management, certificate management, digital signatures, tokenization, Hardware Security Modules (HSMs), and cryptographic agility.
- Ensure cryptographic capabilities support business growth, regulatory expectations, cloud transformation, and emerging technology adoption.
- Develop executive-level metrics and reporting for cryptographic maturity, risk exposure, and modernization progress.
- Lead enterprise initiatives to modernize the firm's cryptographic infrastructure and services.
- Drive programs focused on cryptographic inventory and visibility, legacy algorithm remediation, deprecation of weak cryptographic standards, secure migration strategies, cryptographic agility, and automated cryptographic lifecycle management.
- Develop a roadmap to reduce operational complexity while improving security resilience.
- Partner with engineering teams to ensure cryptographic controls remain scalable, performant, and developer-friendly.
- Establish and operate enterprise-class key management services supporting the firm's most critical systems and data.
- Lead strategy and execution across Enterprise Key Management Systems (KMS), HSMs, secrets vaults, machine identity management, certificate lifecycle management, and service-to-service authentication.
- Drive adoption of automated key lifecycle capabilities, including automated provisioning, rotation, revocation, expiration management, and recovery procedures.
- Reduce operational risk through consistent, centralized, and automated cryptographic controls.
- Partner with Cloud Engineering, Infrastructure, and Application teams to embed cryptographic controls into enterprise platforms.
- Establish secure-by-default cryptographic services supporting multi-cloud environments, SaaS platforms, containerized workloads, Kubernetes environments, modern application architectures, data platforms, and AI/ML environments.
- Enable engineering teams through reusable services, APIs, automation, and paved-road security patterns.
- Develop and modernize the firm's machine identity strategy.
- Lead efforts to secure and manage certificates, APIs, service accounts, workload identities, non-human identities, and infrastructure identities.
- Improve visibility and governance across machine identity ecosystems while reducing risks associated with expired, misconfigured, or unmanaged credentials.
- Drive automation to eliminate manual certificate and identity management processes.
- Lead the firm's post-quantum cryptography strategy.
- Develop capabilities to inventory cryptographic dependencies, assess quantum risk exposure, prioritize remediation efforts, establish migration roadmaps, and implement cryptographic agility standards.
- Partner with Enterprise Architecture and Technology leadership to ensure long-term resilience against emerging cryptographic threats.
- Provide executive guidance on evolving industry standards and regulatory expectations related to quantum readiness.
- Establish enterprise-wide processes for assessing cryptographic risks and control effectiveness.
- Drive initiatives to identify cryptographic gaps, evaluate implementation quality, assess key management maturity, measure cryptographic coverage, and prioritize remediation by risk.
- Develop governance mechanisms to ensure adherence to enterprise cryptographic standards across all technology domains.
- Ensure cryptographic controls align with regulatory, client, and industry expectations.
- Support compliance with frameworks including FFIEC, NIST, ISO 27001, PCI DSS, NYDFS, GDPR, and SEC requirements.
- Serve as the senior cryptography subject matter expert during regulatory examinations, internal audits, client assessments, and control reviews.
- Provide clear and defensible narratives regarding cryptographic controls, key management practices, and risk mitigation strategies.
- Serve as a trusted advisor to the CISO, CIO, CTO, Chief Data Officer, and senior technology leadership.
- Translate highly technical cryptographic concepts into practical business decisions and investment priorities.
- Influence enterprise architecture, platform strategy, cloud adoption, and modernization efforts through cryptographic expertise.
- Build strong partnerships across Security, Technology, Infrastructure, Data, Risk, and Compliance organizations.
- Build and lead a world-class Cryptography organization responsible for Cryptography Engineering, Key Management Services, Secrets Management, PKI Operations, Machine Identity Security, Cryptographic Modernization, and Post-Quantum Readiness.
- Develop technical talent and create a culture focused on engineering excellence, automation, innovation, and operational resilience.
- Act as the firm's senior cryptographic authority and mentor for engineering and security leaders.
Requirements
- 15+ years of experience in cybersecurity, cryptography, security engineering, or infrastructure security leadership roles.
- Demonstrated success leading enterprise cryptography or key management programs within large, highly regulated organizations.
- Deep expertise in applied cryptography, PKI, key management, HSM technologies, secrets management, and certificate lifecycle management.
- Experience designing cryptographic controls across cloud-native, hybrid, and distributed environments.
- Strong understanding of post-quantum cryptography strategies and emerging cryptographic standards.
- Proven track record leading large-scale modernization and transformation initiatives.
- Experience engaging with executive leadership, regulators, auditors, and major clients.
- Recognized industry expert in cryptography and cryptographic security services.
- Strong technical depth combined with executive-level communication skills.
- Strategic thinker capable of balancing innovation, resilience, and operational effectiveness.
- Passion for automation, simplification, and engineering excellence.
- Strong understanding of cloud, identity, infrastructure, and modern application architectures.
- Ability to influence enterprise-wide technology decisions.
- Risk-focused mindset with strong governance and control discipline.
- Trusted leader with a track record of building and scaling high-performing technical organizations.
Skills
- Cybersecurity
- Cryptography
- Security Engineering
- Infrastructure Security
- Enterprise Cryptography
- Key Management
- Secrets Management
- Cryptographic Modernization
- Applied Cryptography
- PKI
- HSM Technologies
- Certificate Lifecycle Management
- Cloud Security Architectures
- Post-Quantum Cryptography
- Risk Management
- Governance
- Automation
- Cloud
- Identity
- Infrastructure
- Modern Application Architectures
Location
- Primary location specified
Work Type
- Full-time
Experience Level
- Senior leadership
- 15+ years of experience
Education Level
- Bachelor's degree in Computer Science, Engineering, Information Security, Mathematics, or related discipline
- Advanced degree preferred
- Relevant certifications such as CISSP, CCSP, CISM, GCFA, or specialized cryptography/security certifications are highly desirable
Salary/Compensations
- $175,000 - $287,500 Annual
Benefits
- Competitive compensation
- Comprehensive benefits
- Retirement savings plan (401K) with company match
- Insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages
- Paid-time off including vacation, sick leave, short term disability, and family care responsibilities
- Access to Employee Assistance Program
- Incentive compensation including eligibility for annual performance-based awards
- Eligibility for certain tax advantaged savings plans
- Inclusive development opportunities
- Flexible work-life support
- Paid volunteer days
- Vibrant employee networks
About the Company
- Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability.
- We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
- We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential.
- As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most.
- Join us in shaping the future.
- Discover more information on jobs at StateStreet.com/careers
- Read our CEO Statement
Equal Opportunity
- As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
- It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
