At a Glance
- Tasks: Join us to embed encryption into software development and enhance security practices.
- Company: Be part of a leading firm focused on secure technology solutions.
- Benefits: Enjoy competitive salary, flexible work options, and comprehensive benefits.
- Other info: Collaborative environment with opportunities for growth and learning.
- Why this job: Make a real impact by driving secure design in innovative projects.
- Qualifications: Experience in software engineering and a passion for cybersecurity is essential.
The predicted salary is between 63000 - 77000 £ per year.
We are seeking a highly motivated Encryption Engineer (DevSecOps & SDLC) who is passionate about building secure-by-design solutions and transforming encryption from a point-in-time security requirement into a seamlessly integrated engineering capability. This individual will play a critical role in advancing the organization's Encryption-by-Design strategy by embedding standardized encryption and key management controls directly into the Software Development Life Cycle (SDLC), DevSecOps pipelines, and enterprise platform engineering patterns.
The ideal candidate combines software engineering, automation, cloud, and cybersecurity expertise with a strong understanding of cryptography and data protection principles. They are skilled at influencing engineering practices, building reusable security capabilities, and partnering with developers, architects, and platform teams to ensure encryption is implemented consistently, efficiently, and at scale.
This role is well-suited for an individual who enjoys solving complex security challenges through automation, creating developer-friendly security solutions, and driving enterprise-wide adoption of secure design patterns. They should be comfortable operating in a fast-paced environment where security, developer experience, operational resilience, and regulatory compliance must coexist.
What You Will Be Responsible For
- Embed enterprise encryption and key management controls into SDLC processes, DevSecOps pipelines, and platform engineering patterns to ensure security is built into solutions from the start.
- Design and implement secure-by-default encryption capabilities that enable application teams to adopt approved cryptographic controls with minimal effort.
- Develop and maintain reusable automation, APIs, templates, Infrastructure-as-Code modules, and reference architectures that accelerate consistent encryption adoption across the enterprise.
- Integrate enterprise key management, secrets management, certificate management, and encryption services into standard developer workflows and CI/CD toolchains.
- Establish automated guardrails and policy-driven controls that validate encryption requirements throughout the software development lifecycle.
- Define and implement architectural review triggers for non-conforming designs, ensuring encryption risks and standards exceptions are identified and addressed early in the design process.
- Partner with application development, platform engineering, cloud engineering, and architecture teams to implement approved cryptographic standards, patterns, and controls across cloud and on-premises environments.
- Create technical standards, implementation guidance, and developer enablement materials that simplify the adoption of encryption and key management capabilities.
- Continuously improve the organization's Encryption-by-Design program by increasing automation, reducing manual security reviews, and driving greater self-service adoption.
- Monitor and assess encryption implementations to identify control gaps, inconsistent practices, and opportunities for standardization and remediation.
- Support regulatory, audit, and risk management initiatives by ensuring encryption controls are consistently deployed, measurable, and supported by automated compliance evidence.
- Drive adoption of enterprise encryption services by working closely with engineering teams to modernize legacy implementations and align new solutions with approved standards.
- Reduce the risk of inconsistent, fragmented, or non-compliant encryption implementations through standardized patterns, automated enforcement, and scalable engineering controls.
- Minimize design exceptions, audit findings, and operational risks by embedding cryptographic controls directly into development processes rather than relying on manual reviews and remediation activities.
- Accelerate compliant application onboarding and delivery by providing reusable security capabilities that improve both developer experience and regulatory compliance outcomes.
What We Value
- A security-first mindset with a passion for building secure, resilient, and scalable technology solutions.
- Strong engineering discipline and a commitment to automation, standardization, and continuous improvement.
- The ability to translate security requirements into practical engineering solutions that improve both security and developer experience.
- A collaborative approach to working across cybersecurity, architecture, engineering, infrastructure, and product teams.
- A proactive and innovative mindset focused on eliminating friction through reusable solutions, self-service capabilities, and policy-driven automation.
- Strong analytical and problem-solving skills with the ability to identify root causes and design sustainable solutions.
- Effective communication skills and the ability to explain complex technical concepts to both technical and non-technical stakeholders.
- An ownership mentality that prioritises measurable outcomes, operational excellence, and long-term sustainability.
- Curiosity and a passion for learning in evolving areas such as cloud security, cryptography, platform engineering, DevSecOps, and software security.
- A commitment to reducing operational risk by replacing fragmented manual processes with scalable, automated security controls.
Education & Preferred Qualifications
- Bachelor's degree in Computer Science, Information Security, Software Engineering, Information Technology, Cybersecurity, or a related discipline, or equivalent practical experience.
- 8+ years of experience in software engineering, DevSecOps, platform engineering, cloud engineering, cybersecurity engineering, or a related technical field.
- Experience integrating security controls into SDLC processes, CI/CD pipelines, and modern software delivery platforms.
- Working knowledge of encryption technologies, cryptographic key management, secrets management, certificate lifecycle management, and enterprise data protection controls.
- Experience implementing security automation within development pipelines using tools such as Harness, Jenkins, or similar platforms.
- Hands-on experience with Infrastructure-as-Code technologies, including Terraform, CloudFormation, or equivalent automation frameworks.
- Proficiency in one or more programming or scripting languages such as Python, Java, Go, C#, JavaScript, TypeScript, PowerShell, or Bash.
- Experience with cloud platforms including Microsoft Azure, Amazon Web Services (AWS), OCI, or Google Cloud Platform (GCP).
- Familiarity with containerization and modern platform technologies including Kubernetes, OpenShift, and cloud-native application architectures.
- Understanding of software architecture principles, secure coding practices, application security testing, and developer enablement methodologies.
- Knowledge of industry security and compliance frameworks such as NIST, PCI DSS, ISO 27001, or equivalent regulatory standards.
- Experience with enterprise key management platforms, Hardware Security Modules (HSMs), cloud KMS services, secrets management platforms, or certificate management solutions is highly desirable.
- Relevant certifications such as CISSP, CCSP, Azure Security Engineer Associate, AWS Security Specialty, Certified Kubernetes Security Specialist (CKS), or similar certifications are a plus.
Salary Range: $120,000 - $202,500 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit .
About State Street
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
Job Application Disclosure: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Summary
Location: Quincy, Massachusetts; London, England; Princeton, New Jersey; Austin, Texas; Berwyn, Pennsylvania; Clifton, New Jersey
Type: Full time
Encryption Engineer (DevSecOps & SDLC) in London employer: State Street Bank
At State Street, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation. As a Principal Threat Modeling Architect, you will have access to inclusive development opportunities, flexible work-life support, and the chance to lead a high-performing team in a hybrid work environment. Our commitment to employee growth and community engagement, alongside our focus on security excellence, makes us an attractive choice for professionals seeking meaningful and rewarding careers in the financial services sector.
StudySmarter Expert Advice🤫
We think this is how you could land Encryption Engineer (DevSecOps & SDLC) in London
✨Join Local Tech Meetups
Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at State Street Bank or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!
✨Contribute to Open Source Projects
Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to State Street Bank.
✨Tap into Online Developer Communities
Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like State Street Bank.
✨Explore Job Boards Specifically for Tech Roles
Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like State Street Bank that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!
We think you need these skills to ace Encryption Engineer (DevSecOps & SDLC) in London
Some tips for your application 🫡
Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.
Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at State Street Bank.
Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at State Street Bank and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!
Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!
How to prepare for a job interview at State Street Bank
✨Brush Up on Your Coding Skills
For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.
✨Know Your Tools and Frameworks
Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If State Street Bank uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.
✨Showcase Your Projects
Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.
✨Prepare for Behavioural Questions
While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.