About Amgen :
Amgen harnesses the best of biology and technology to fight the world's toughest diseases, and make people's lives easier, fuller and longer. We discover, develop, manufacture and deliver innovative medicines to help millions of patients. Amgen helped establish the biotechnology industry more than 40 years ago and remains on the cutting-edge of innovation, using technology and human genetic data to push beyond what's known today.
Role Description :
The Senior Manager Information Security - Encryption Agility Service Lead is accountable for establishing, leading, and operating Amgen's enterprise Encryption Agility Service for Post-Quantum Readiness Preparation. This role will lead the Encryption Agility Team and be considered Amgens Cryptographic Center of Excellence! The team will own and manage the enterprise service for encryption, cryptography, crypto agility, and post-quantum cryptography readiness across Amgen.
Roles & Responsibilities :
- Establish, operate, and continuously improve the enterprise Encryption Agility Team and Service, including the service charter, governance model, operating cadence, intake process, RACI model, roadmap, KPIs, KRIs, executive reporting, and service improvement plan.
- Lead, coach, mentor, and manage Encryption Agility Team members, including FTEs, external workers, cryptographic engineers, security architecture analysts, product ownership support, and part-time contributors from partner teams.
- Partner with the Principal Architect to translate enterprise Post-Quantum Cryptography (PQC) strategy into standards and specifications, reference architectures, implementation patterns, practical engineering guidance, remediation backlogs, and production-ready cryptographic design decisions.
- Own the enterprise cryptographic standards and specifications roadmap, including approved algorithms, key sizes, protocols, TLS and cipher policies, certificate requirements, KMS and secrets requirements, exception criteria, RSA and ECC sunset planning, and annual standards refresh.
- Lead delivery across the full PQC lifecycle, including assessment wrap-up, quick wins, discovery tooling selection, iterative discovery, vendor and third-party outreach, PQC architecture, testing and trials, production rollout, automation, monitoring, and steady-state service operations.
- Build, govern, and mature the Amgen Cryptographic Bill of Materials (CBOM), including required fields, asset ownership, quantum-vulnerability status, remediation status, data quality controls, reporting requirements, and integration of cryptographic inventory and risk data across relevant Amgen platforms.
- Direct enterprise cryptographic discovery across source code, binaries, cloud key services, endpoints, file systems, network traffic, PKI and certificates, KMS and secrets, vendor attestations, and SME interviews to create a reliable enterprise cryptographic inventory.
- Apply the approved PQC risk-prioritization approach to sequence discovery and remediation for business-critical applications, high-volume sensitive data flows, identity services, third-party dependencies, legacy platforms, KCS, and validated GxP systems.
- Coordinate with DIAS, PKI service owners, certificate management teams, cloud, infrastructure, and platform teams on certificate visibility, CLM evaluation, certificate rotation policy, manual-to-automated deployment migration, post-quantum PKI readiness, hybrid certificate testing, CA roadmap, operational change windows, enterprise KMS strategy, HSM and cloud KMS roadmaps, secrets management, key rotation, key retirement, and centralized or federated key management control patterns.
- Partner with Application Security, SSDLC, DevOps, AI Security, Enterprise Architecture, and engineering teams to publish approved cryptographic libraries, reusable patterns, CI/CD controls, scanning rules, secure code examples, and remediation playbooks.
- Coordinate with Risk and Compliance, Legal, Procurement, TPRM, and vendor management to implement PQC questionnaires, CBOM requests, contract language, supplier roadmap tracking, risk acceptance, and executive escalation for vendors and SaaS providers.
- Provide senior technical escalation and hands-on leadership for cryptographic standards exceptions, scan findings, false-positive triage, certificate outages, key and secret configuration issues, tool integration blockers, design tradeoffs, SNDL exposure, identity and certificate risks, outdated TLS and cipher configurations, legacy cryptography, untracked keys, manual certificate processes, OT and manufacturing scope definition, developer and stakeholder enablement, and changes in NIST, IETF, NSA/CNSA Suite, ISO, HIPAA, HITRUST, and industry cryptography guidance.
Basic Qualifications and Experience :
- Doctorate degree and 2 years of relevant experience.
- Master's degree with 8 - 10 years of relevant experience.
- Bachelor's degree with 10 - 14 years of relevant experience.
- Diploma with 14 - 18 years of relevant experience.
Must-Have Skills :
- Expert knowledge of enterprise cryptography, including PKI, X.509 certificates, TLS, cipher suites, KMS/HSM, secrets management, key lifecycle, encryption at rest and in transit, and cloud key services.
- Proven experience leading global information security, security architecture, or cryptography programs, including roadmap ownership, team management, resource planning, metrics, reporting, and executive stakeholder management.
- Practical knowledge of post-quantum cryptography, crypto agility, NIST-approved algorithms and standards, hybrid/PQC transition patterns, cryptographic discovery, and CBOM-driven remediation.
- Ability to translate security policy into enforceable controls across CI/CD, cloud platforms, identity, PKI/certificates, infrastructure, applications, third-party governance, and risk management.
Professional Certifications :
- CISSP (required).
- CISM, CISA, or CRISC (preferred).
- CCSP or cloud security certification (preferred).
- TOGAF or SABSA (preferred).
- ITIL, SAFe, product management, or program management certification (preferred).
Soft Skills :
- Excellent people leadership, coaching, mentoring, and performance management skills.
- Strong executive presence and ability to translate complex cryptographic risk into clear business impact and action plans.
- Strong verbal and written communication skills for technical, business, legal, procurement, compliance, and executive audiences.
- Ability to influence without direct authority across global security, DTI, DIAS, procurement, legal, compliance, OT, infrastructure, and application teams.
- High degree of initiative, accountability, judgment, and self-motivation in ambiguous or evolving technical domains.
- Ability to manage multiple priorities, competing stakeholder needs, and long-running transformation roadmaps successfully.
- Team oriented, with a focus on shared outcomes, practical implementation, and service maturity.
- Ability to balance hands-on technical analysis with service ownership, people leadership, and enterprise change management.
Equal Opportunity Statement :
- Amgen is an Equal Chance employer and will consider you without regard to your race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.
Note : For your candidature to be considered on this job, you need to apply necessarily on the company's redirected page of this job. Please make sure you apply on the redirected page as well.
📌 Amgen - Senior Manager - Information Security (India)
🏢 AMGEN
📍 India