Amgen Technology Pvt Ltd. Posted July 21, 2026

Encryption Agility Analyst

Hyderabad, India Full time
Information Technology

Amgen Technology Pvt Ltd. is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

Career Category

Information Systems

Job Description

Role Name: Senior Associate Information Security - Encryption Agility Analyst

Job Posting Title: Senior Associate Information Security - Encryption Agility Analyst

Workday Job Title: Senior Associate Information Security

Department Name: Trusted Core Technologies

Role Global Career Framework (GCF): 4A

ABOUT AMGEN

Amgen harnesses the best of biology and technology to fight the world's toughest diseases, and make people's lives easier, fuller and longer. We discover, develop, manufacture and deliver innovative medicines to help millions of patients. Amgen helped establish the biotechnology industry more than 40 years ago and remains on the cutting-edge of innovation, using technology and human genetic data to push beyond what's known today.

ABOUT THE ROLE

Role Description:

The Senior Associate Information Security - Encryption Agility Analyst will support Amgen's enterprise Encryption Agility Service for Post-Quantum Cryptography (PQC) Readiness Preparation. This role supports the Senior Manager Information Security - Encryption Agility Service Lead, the Senior Specialist Information Security - Encryption Agility Team Architect, and Global Career Framework level 5 (L5) engineers by helping collect, validate, document, and report cryptographic inventory and remediation data across Amgen. The role contributes to the Cryptographic Bill of Materials (CBOM), discovery workflows, data quality controls, ticket tracking, dashboards, and operational documentation that enable Amgen to manage encryption, cryptography, crypto agility, and post-quantum readiness across applications, cloud, infrastructure, identity, Public Key Infrastructure (PKI), certificates, Key Management Services (KMS), secrets, data protection, Software as a Service (SaaS), and third-party ecosystems.

This position is hands-on and detail-oriented. The analyst will review tool outputs, support evidence collection, maintain inventory records, assist with false-positive triage, prepare reporting views, document remediation status, and coordinate with service owners. The role will work with Digital Identity Access Service (DIAS), PKI and certificate service owners, Application Security, Artificial Intelligence (AI) Security, Enterprise Architecture, cloud, infrastructure, platform, Risk and Compliance, Procurement, Legal, Third Party Risk Management (TPRM), Operational Technology (OT), and vendor teams while escalating complex cryptographic design or exception decisions to the L5 engineer, Principal Architect, or Senior Manager.

Roles & Responsibilities:

Support Encryption Agility Service operations, including intake processing, work tracking, dashboard updates, meeting notes, service documentation, Standard Operating Procedures (SOPs) maintenance, reporting inputs, and service improvement actions.

Collect and validate cryptographic inventory data from source code, binaries, cloud key services, endpoints, file systems, network traffic, PKI and certificates, KMS and secrets, vendor attestations, Software Bill of Materials (SBOM) inputs, and Subject Matter Expert (SME) interviews.

Maintain CBOM records using CycloneDX 1.6+ as the target format, including required fields, source systems, asset ownership, quantum-vulnerability status, remediation status, data quality checks, reporting views, and ServiceNow asset correlation.

Review cryptographic scan outputs, certificate records, certificate chains, cipher suite configurations, Transport Layer Security (TLS) settings, Secure Shell (SSH) settings, Open Authorization (OAuth), Security Assertion Markup Language (SAML), JSON Web Token (JWT) patterns, cloud key records, and key or secret storage evidence under L5 engineer or Principal Architect guidance.

Support data ingestion, tool integration, and evidence management across Amgen Enterprise systems and cryptographic discovery platforms.

Assist DIAS, PKI service owners, certificate management teams, and identity teams with certificate visibility, certificate ownership, expiration tracking, Certificate Lifecycle Manager (CLM) data needs, manual-to-automated deployment candidates, Certificate Authority (CA) roadmap inputs, and operational change window planning.

Assist cloud, infrastructure, and platform teams with KMS and secrets inventory, Hardware Security Module (HSM) evidence, key ownership records, key rotation status, key retirement tracking, storage standards, and reporting needed for centralized or federated key management controls.

Support Application Security, AI Security, Enterprise Architecture, Development and Operations (DevOps), and engineering teams with approved cryptographic library adoption, Continuous Integration/Continuous Delivery (CI/CD) scan data, Secure Software Development Life Cycle (SSDLC) requirements, scanning rules, secure code examples, and developer remediation playbooks.

Track remediation and risk prioritization data for business-critical applications, high-volume sensitive data flows, third-party dependencies, identity services, legacy platforms, Key Computerized Systems (KCS), validated Good x Practice (GxP) systems, and OT scope.

Support vendor and third-party governance activities with Procurement, Legal, Risk and Compliance, TPRM, and business owners by collecting technical questionnaire responses, CBOM requests, cryptographic evidence, roadmap updates, and supplier follow-up actions.

Maintain knowledge articles, implementation guides, training material, exception records, and escalation summaries while monitoring relevant updates from National Institute of Standards and Technology (NIST), Internet Engineering Task Force (IETF), National Security Agency Commercial National Security Algorithm Suite 2.0 (NSA CNSA 2.0), International Organization for Standardization (ISO), Health Insurance Portability and Accountability Act (HIPAA), Health Information Trust Alliance (HITRUST), and broader industry cryptography guidance.

Basic Qualifications and Experience:

Master's degree with 1 to 3 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field OR

Bachelor's degree with 3 to 5 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field OR

Diploma with 7 to 9 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field

Functional Skills:

Must-Have Skills:

Working knowledge of information security and foundational enterprise cryptography, including PKI, X.509 certificates, TLS, cipher suites, KMS, secrets management, key lifecycle, encryption at rest, encryption in transit, cloud key services, and identity protocols.

Experience reviewing security tool outputs, maintaining inventory records, validating data quality, documenting findings, updating tickets, and supporting dashboards or operational reports.

Basic understanding of post-quantum cryptography, crypto agility, cryptographic discovery, CBOM/SBOM concepts, risk-based remediation, and Steal-Now-Decrypt-Later (SNDL) risk.

Ability to follow technical guidance, document evidence clearly, coordinate with service owners, and escalate complex cryptographic findings or exceptions appropriately.

Good-to-Have Skills:

Experience with ServiceNow CMDB/GRC, Guard, Wiz, Qualys, Fortinet, Netskope, CrowdStrike, GitLab, Veracode, GitGuardian, Amazon Web Services (AWS) KMS, AWS Certificate Manager, AWS Secrets Manager, Microsoft PKI, Sectigo, HashiCorp Vault, HSMs, CLM platforms, or SIEM/data lake tools.

Experience supporting CBOM/SBOM data management using CycloneDX 1.6+, Application Programming Interfaces (APIs), Comma-Separated Values (CSV), JavaScript Object Notation (JSON), spreadsheets, dashboards, data quality checks, and audit-ready reporting.

Experience supporting certificate lifecycle activities, certificate expiration tracking, certificate ownership updates, certificate rotation evidence, or PKI operational reporting.

Experience supporting cloud security, application security, DevOps, SSDLC governance, CI/CD quality gates, static analysis, dynamic analysis, composition analysis, or developer remediation tracking.

Experience in pharmaceutical, life sciences, regulated, validated, GxP, KCS, manufacturing, OT, or other change-controlled environments.

Experience supporting vendor or third-party risk activities, supplier questionnaires, roadmap tracking, evidence collection, or Software as a Service platform dependency analysis.

Foundational scripting or data handling experience with Python, PowerShell, Bash, Representational State Transfer Application Programming Interfaces (REST APIs), CSV files, JSON files, or lightweight reporting automation.

Professional Certifications:

Security+, Systems Security Certified Practitioner (SSCP), or equivalent foundational security certification (preferred)

Certified Information Systems Security Professional (CISSP) Associate, CISSP, Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or Certified in Risk and Information Systems Control (CRISC) (preferred)

Certified Cloud Security Professional (CCSP), AWS Certified Security - Specialty, Microsoft Azure Security Engineer, or equivalent cloud security certification (preferred)

Information Technology Infrastructure Library (ITIL), Scaled Agile Framework (SAFe), product management, or equivalent delivery certification (preferred)

Relevant PKI, KMS, HSM, cryptographic discovery, certificate lifecycle management, cloud key management, or post-quantum cryptography training/certification (preferred)

Soft Skills:

Excellent analytical, troubleshooting, and problem-solving skills.

Strong attention to detail and commitment to accurate inventory, evidence, and reporting data.

Strong verbal and written communication skills for technical and non-technical stakeholders.

Ability to translate findings into clear documentation, tickets, summaries, and escalation notes.

Ability to work effectively with global, virtual teams across security, Digital, Technology and Innovation (DTI), DIAS, procurement, legal, compliance, OT, infrastructure, cloud, and application teams.

High degree of initiative, accountability, and self-motivation while working under technical direction.

Ability to manage multiple work items, evidence requests, and remediation tracking activities successfully.

Team oriented, with a focus on shared outcomes, practical execution, and service maturity.

Comfort learning an emerging technical domain and helping mature a new enterprise capability from the ground up.

EQUAL OPPORTUNITY STATEMENT

Amgen is an Equal Opportunity employer and will consider you without regard to your race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.

We will ensure that individuals with disabilities are provided with reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request an accommodation.

.

Job details

Seniority
Not listed
Function
Information Technology
Therapeutic area
Not listed
Location
Hyderabad, India
Employment type
Full time

How this role compares

Computed from every other active Information Technology role in our database, not just this employer's listings.

We currently track 1097 comparable Information Technology roles across 55 biopharma companies.

1097Comparable roles tracked
1035Currently active
55Companies hiring similar roles
29Countries represented

Salary context

143 of 1097 peers report a salary range (USD, annualized)

Peers share this role's job function. This posting doesn't list a seniority level, so peers aren't narrowed by seniority either -- the range below may span more levels than usual.

This roleSubject Not listed on this posting
Lowest disclosed · Senior Data Security Engineer (Insider Risk Management – Engineering) · AbbVie $0/hr – $0/hr (≈ $0–$0/yr)
Highest disclosed · Senior Director, Targets and Mechanisms Solutions · Pfizer $230,900/yr – $384,800/yr
Peer group range $0 – $307,850 (median $165,900)

Where these roles are based

Top locations among the 1097 comparable roles

India506
United States241
Spain106
Poland72
Portugal32
China13

+ 23 more countries

Seniority mix

612 of 1097 peers have a known seniority level

Senior290
Manager135
Associate52
Principal50
Associate Director39
Director28
Senior Director13
Intern/Fellow/Postdoc4
Executive/VP1

Therapeutic area mix

1 of 1097 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden

Oncology1

Similar opportunities

The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.

40%similar
Novartis Hyderabad (Office), India Associate Director
Same function Same country
40%similar
Novartis Hyderabad (Office), India Associate Director
Same function Same country
40%similar
Novartis Hyderabad (Office), India Director
Same function Same country
40%similar
Novartis Hyderabad (Office), India Director
Same function Same country
40%similar
Regeneron India Private Limited Hyderabad, India Senior Director
Same function Same country
40%similar
Regeneron India Private Limited Hyderabad, India Director
Same function Same country

How we calculate "similar"

No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.

Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.

40%
Associate Director, Technical Project Management & Digital Enablement(Sharepoint)
Novartis · Hyderabad (Office), India · Associate Director
Function Therapeutic area Seniority Country
40%
Director - Data & Analytics Integration & Eventing Platforms
Novartis · Hyderabad (Office), India · Director
Function Therapeutic area Seniority Country
40%
Director Information Security - GCC India & JAPAC
Regeneron India Private Limited · Hyderabad, India · Director
Function Therapeutic area Seniority Country
40%
Software Engineer II Workday Integrations
Bristol-Myers Squibb Business Services India Private Limited · Hyderabad, India · Seniority not listed
Function Therapeutic area Seniority Country
Unmatched or unknown dimensions score exactly the same: 0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.