- Company Name
- Anaplan
- Job Title
- Data Encryption Security Operations Engineer
- Job Description
-
**Job Title**
Data Encryption Security Operations Engineer
**Role Summary**
Lead the design, implementation, and operational management of the organization's data encryption infrastructure. Ensure secure onboarding of new customers with Bring Your Own Key (BYOK) solutions, optimize provisioning processes, and maintain comprehensive monitoring and observability of encryption services across hybrid cloud environments.
**Expectations**
- Deliver end‑to‑end encryption solutions for high‑scale B2B/B2C platforms.
- Demonstrate strong full‑stack system design skills in hybrid cloud with hands‑on experience in Java, Rust, and Linux internals.
- Collaborate cross‑functionally, provide constructive feedback, and drive continuous improvement in security processes.
- Maintain a proactive stance on compliance, threat intelligence, and incident response.
**Key Responsibilities**
- Own and evolve the data encryption infrastructure (Thales Cloud, CipherTrust, Vormetric).
- Provision secure environments for new customers using BYOK Thales solutions.
- Reduce time‑to‑value through process optimization and automation.
- Design, deploy, and maintain monitoring, logging, and observability stack (Prometheus, Grafana, Loki, Grahana).
- Manage Public Key Infrastructure (PKI) including certificates, key vaults, HSMs (Thales Luna, AWS CloudHSM), and lifecycle tools (Venafi, AppviewX, DigiCert CertCentral).
- Configure and enforce TLS/SSL, X.509 certificates, CRL/OCSP, key usage policies, and certificate pinning.
- Assess and mitigate compliance risks related to encryption (GDPR, PCI‑DSS, ISO 27001, etc.).
- Conduct threat analysis, incident investigation, and digital forensics related to encryption failures or breaches.
- Influence infrastructure architecture by sharing expertise on encryption and security best practices.
**Required Skills**
- Deep knowledge of cryptographic primitives (symmetric/asymmetric, hashing, key exchange protocols).
- Proficient in TLS/SSL configuration, certificate management, and HSM integration.
- Experience with public cloud (AWS, Azure, GCP) and hybrid cloud orchestration (Kubernetes, Docker).
- Strong Linux/Windows internals, network protocols, and infrastructure fundamentals.
- Familiarity with monitoring/metrics tools (Prometheus, Grafana, Loki).
- Programming proficiency in Java, Rust, and scripting (Python/Bash).
- Ability to analyze malware, perform digital forensics, and respond to security incidents.
- Excellent written and verbal communication, analytical reasoning, and collaborative mindset.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related technical field, or equivalent professional experience.
- Relevant certifications (CompTIA Security+, Certified Ethical Hacker (CEH), or equivalent) are a plus.
- Minimum 3–5 years of experience as a Platform Engineer or security engineer focused on data encryption and PKI.
Manchester, United kingdom
On site
11-01-2026