Principal Enterprise Architect
Summary
Technical Lead / Enterprise Architect focused on assessing, enhancing and maturing a federal department's cryptographic services capability, including PKI, HSMs, and related trust services.
The Cyber Security, Cloud and Networks Branch (CRB) within major federal client's Information Management and Technology Division (IMD), is seeking a Technical Lead to support a program of work focused on the assessment, enhancement and maturation of the Department's cryptographic services capability, including Public Key Infrastructure (PKI), Hardware Security Modules (HSMs) and related trust services.
The role will contribute to capability assessment, architecture development, documentation uplift, operational process improvement, transition planning and future-state service design. Working across business, project, engineering and operational teams, the successful candidate will provide technical leadership to identify capability gaps, develop practical and sustainable solutions, and improve the maturity and long-term sustainability of the Department's cryptographic services capability.
In addition to technical architecture responsibilities, the role will support the development and enhancement of PKI governance frameworks, certificate management policies, operational procedures, security controls and risk management processes. The successful candidate will work collaboratively with business analysts, project resources and operational teams to establish sustainable governance, procedural and assurance practices that support the secure operation of cryptographic services.
Given the specialised nature of the domain, client is seeking candidates with strong experience in cryptographic services, PKI governance, security architecture, infrastructure security, risk management or related technical leadership disciplines. Candidates should demonstrate the ability to balance technical solution design with the development of governance, policy and procedural controls required to operate cryptographic services within a regulated and security-sensitive environment.
Requirements
Key duties and responsibilities
1. The Department is seeking a Technical Lead to provide architectural leadership for the delivery, governance and ongoing evolution of enterprise cryptographic services, including Public Key Infrastructure (PKI), Hardware Security Modules (HSMs), certificate management, key management and related security capabilities. The role will be responsible for supporting both the technical and governance aspects of cryptographic capability uplift across the Department.
2. The role will work across business, architecture, engineering and operational teams to assess current capabilities, identify improvement opportunities, develop future-state architectures, establish governance frameworks and support delivery outcomes. The successful candidate will provide technical leadership across multiple initiatives, balancing strategic planning, security risk management, policy development with practical implementation activities within a complex and highly regulated environment.
3. In addition to technical architecture responsibilities, the role will support the development and maintenance of governance artefacts including standards, policies, procedures, operating models and assurance processes required for the effective management of cryptographic services. This includes working collaboratively with business analysts, project resources and operational teams to define sustainable processes, controls and service management practices that underpin the secure operation of PKI and related trust services.
4. client recognises that deep PKI expertise is a specialised capability. As such, applications are encouraged from candidates with strong experience in cryptographic services, PKI governance, security architecture, infrastructure architecture, cryptography or related technical leadership disciplines. Candidates should be able to demonstrate experience balancing technical solution design with governance, policy and procedural requirements in security-sensitive or regulated environments.
Key responsibilities and duties:
• Provide technical leadership for the design, delivery and ongoing operation of enterprise PKI, HSM and cryptographic services.
• Lead the development and maintenance of cryptographic governance artefacts, including policies, standards, procedures, operating models and security risk management processes to support the secure operation of PKI and related trust services.
• Define, govern and maintain target cryptographic architectures, including trust models, key management approaches, availability requirements and security standards.
• Assess current capabilities and conduct gap analysis activities to support roadmap development, business cases and future-state planning.
• Act as a senior technical authority for cryptographic and security architecture decisions, engaging with stakeholders across business, project and operational teams.
• Lead solution architecture and detailed technical design activities, ensuring secure implementation, deployment and operational practices.
• Identify and manage cryptographic risks, platform dependencies and operational resilience requirements.
• Support engineering teams through design, build, testing, release and transition-to-operations activities.
• Produce and maintain architectural artefacts, technical designs, operational documentation and implementation guidance.
• Support the ongoing operation and improvement of cryptographic services, including upgrades, maintenance, testing and issue resolution.
• Ensure services align with organisational security policies, government standards and industry best practice.
• Provide technical mentoring, knowledge transfer and capability uplift across engineering and operational teams.