Corporate Vice President - Enterprise PKI & Cryptographic Engineering

🏢 New York Life Insurance Co · all New York Life Insurance Co jobs
📍 United States
💰 USD 147,500 - 211,000 / annual
📅 Posted 2026-09-04 · via Himalayas
🏷 PKI-Engineering,Cryptographic-Engineering,Security-Engineering,Identity-Engineering,Certificate-Authority-Management,Corporate-Vice-President-Identity-And-Access-Management,Vice-President-of-Security-Engineering,PKI-Architect,Cryptography-and-PKI-Engineering,Cryptography-Architect
Apply on original site ↗

Location Designation: Hybrid - 3 days per quarter
Technology, Data, AI and Ventures:

Within the Tech, Data, AI, Ventures (TDAV) organization, our work is guided by a shared vision: deploying the power of technology, data, AI and ventures to accelerate sustainable competitive advantage for New York Life's businesses. We build solutions that power how we serve policy owners, agents, advisors and employees while delivering measurable business outcomes.

Across technology, data, AI, cyber, product, digital experience, architecture and infrastructure, TDAV combines the scale and investment of an industry leader, access to leading-edge technologies and the opportunity to help shape how a world-class financial services company competes in the AI era - all backed by the stability and purpose of a mutual company built to last.

The Corporate Vice President – Enterprise PKI & Cryptographic Engineering is a senior, hands-on technical leader accountable for the architecture, engineering, and modernization of New York Life's enterprise Public Key Infrastructure, certificate lifecycle, and cryptographic services across data center, cloud (AWS, Azure, and GCP), applications, devices, workloads, and non-human identities. This is a builder role, not a purely advisory one: you'll move from architecture into hands-on design, automation, and production delivery.

You'll own PKI and certificate lifecycle automation end to end, serve as the CISO organization's PKI and cryptographic subject matter expert for the Security Review Board and IS Exception process, and help position NYL for cryptographic agility and post-quantum readiness.
What You'll Do:

- Design, engineer, and modernize enterprise PKI services and trust hierarchies — offline root CAs, issuing/subordinate CAs, and cloud-native issuance — spanning users, applications, devices, workloads, APIs, and non-human identities.

- Engineer and administer Microsoft AD CS, including CA configuration, certificate templates, auto-enrollment, trust chains, CRLs, OCSP, and recovery capabilities.

- Own Certificate Lifecycle Management (CLM): drive discovery, inventory, issuance, renewal, revocation, and reporting from fragmented manual processes toward centralized, policy-driven automation.

- Build automation and reusable, self-service certificate APIs using ACME, SCEP, EST, REST, PowerShell, and Python; integrate with ServiceNow, CI/CD, Kubernetes, and DevOps tooling.

- Engineer HSM/KMS backed CA and signing services, including key ceremonies, backup, rotation, access control, and disaster recovery, across on-prem and cloud (AWS, Azure, GCP).

- Serve as the PKI and cryptographic engineering subject-matter expert for the Security Review Board and Architecture Review Board, and provide authoritative technical risk recommendations on IS Exception requests.

- Maintain strong knowledge of Active Directory and Microsoft Entra ID where they intersect with certificate services, certificate-based authentication, device identity, Conditional Access, and Privileged Identity Management.

- Maintain the enterprise cryptographic inventory and drive cryptographic agility, short-lived certificates, and post-quantum migration readiness.

- Treat PKI as business critical infrastructure: define resiliency, monitoring, and recovery procedures, and lead incident response and root-cause analysis for certificate, key, and trust failures.

- Serve as the senior technical authority for complex production certificate, trust, and cryptographic issues, translating decisions into reusable enterprise patterns.

What You'll Bring:

- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or equivalent practical experience.

- 8+ years of progressive, hands-on experience in PKI, cryptographic engineering, identity engineering, or security engineering, with significant responsibility for enterprise PKI environments.

- Deep hands-on experience engineering or operating enterprise certificate au

← All remote jobs

Similar for you