Cyber Data Protection/pki Specialist Senior Consultant

This role is for a Cyber Data Protection/PKI Specialist Senior Consultant at Deloitte. The primary focus is on advising clients on data protection and encryption requirements, designing and implementing solutions for data risk reduction, and managing Public Key Infrastructure (PKI) systems. The role involves staying updated on emerging encryption technologies and recommending new security tools.

What you'd actually do

  1. Serve as a subject matter expert and trusted advisor to our clients, assisting them to evaluate strategic and practical data protection and encryption requirements based on new and emerging data risks, advising on best practices for data encryption, decryption, and secure key management
  2. Assist clients in designing, implementing and operating technology and process solutions to reduce data risks, developing and leading the implementation of encryption strategies to protect sensitive data across various environments, including cloud, on-premises, and hybrid infrastructures, to manage the deployment and lifecycle of PKI systems, ensuring robust and scalable certificate management processes, monitor and maintain the health of certificate infrastructures to prevent downtime and security breaches, and assist with developing requirements, evaluating vendor solutions, architecting, implementing and operating data protection solutions
  3. Aid in the delivery of client engagements, ensuring success by:
  4. Stay up to date on emerging encryption technologies (e.g., post-quantum cryptography, confidential computing, secure enclaves, envelope encryption) and industry trends around cyber risk, data protection and cryptography practices.
  5. Proactively evaluate and recommend new tools and solutions to enhance data security

Skills

Required

  • Bachelor’s degree in Cybersecurity, Information Security, Engineering, Computer Science, Information Technology or related field
  • 5+ years of professional experience within data protection and information security, which may include Data Discovery, Data Classification and Rights Management, Data Access Governance, Data Loss Prevention, Cloud Access Security Broker, Encryption, Certificate Lifecycle Management, Cloud Security, SaaS Security
  • 5+ years with PKI concepts: certificates, CAs, RA, CSR, OCSP, CRL, HSM, key management, trust chains
  • 2+ years of professional experience managing and implementing various encryption technologies (e.g., database encryption, file encryption, Public Key Infrastructure (PKI), certificate lifecycle management (CLM), transport layer security (TLS)) and strong understanding of Cloud encryption concepts such as client-side encryption, bring your own key (BYOK), server-side encryption.
  • 2+ years of professional experience developing data protection strategies, roadmaps and frameworks; experience may include designing, implementing and operating data protections services
  • 2+ years of total hands-on technical experience with one or more data protection technologies
  • 2+ years with CLM platforms such as AppViewX, Venafi, Keyfactor, DigiCert, or similar
  • 2+ years with cryptographic standards and protocols including TLS/SSL, SSH, S/MIME, code signing, and NIST-aligned practices
  • 2+ years certificate discovery, inventory, automation, renewal, and compliance monitoring
  • 2+ years supporting strategy, architecture, roadmap, and implementa

What the JD emphasized

  • data protection
  • encryption
  • PKI
  • certificate lifecycle management