CYBERSECURITY EXPERT – CRYPTOGRAPHY (HYBRID)

Publicado 30-07-2026

iTRTech Group

Lisboa Lisboa (Informática)


CYBERSECURITY EXPERT – CRYPTOGRAPHY (HYBRID LISBON OR PORTO)

Portuguese company hires for hybrid position

Location: Lisbon or Porto, Portugal

  • ️ Only candidates already based in Portugal will be considered

Work Model: Hybrid

️ Language Requirements: English B2+ — mandatory

Seniority: Senior (6+ years)

Sector: Banking

Rate Between €3300 - 4100 RV / €2360 - 2880 CTI

  • ️ Instructions: Please send your CV in English and make sure to include all skills and experience that match the requirements of the opportunity. This will significantly increase your chances of success

About the Opportunity

We are looking for a Senior Cybersecurity Expert specialising in cryptography and data protection to join an international Cybersecurity and Digital Fraud department.

You will contribute to enterprise-level security activities covering approximately 30 entities, helping define the organisation’s cryptography strategy, security requirements, data-protection mechanisms, cryptographic asset management, and crypto-agility approach.

Based in Lisbon or Porto, you will work as part of the Portuguese cybersecurity delivery team, collaborating closely with a central European team, subsidiaries, IT teams, security specialists, architects, and project stakeholders.

Key Responsibilities

Cryptography Strategy and Governance

  • Define enterprise-level security requirements, standards, and strategies for cryptography and data security.
  • Contribute to the development and evolution of the organisation’s cryptographic governance framework.
  • Define approaches for identifying and inventorying cryptographic assets across multiple entities.
  • Support the development of crypto-agility strategies and cryptographic lifecycle-management practices.
  • Anticipate changes in cryptographic technologies, standards, vulnerabilities, and regulatory expectations.
  • Contribute to the preparation for cryptographic transitions and emerging threats.

Security Risk Assessment

  • Analyse and evaluate cybersecurity risks associated with cryptographic solutions and data-protection mechanisms.
  • Assess the potential business and technical impact of identified risks.
  • Prepare or validate security risk analyses.
  • Recommend countermeasures and complementary security controls.
  • Evaluate whether security designs and implementations provide adequate protection.
  • Support informed risk decisions across business and IT teams.

Architecture and Data Protection

  • Assess the robustness of security designs, cryptographic mechanisms, data-protection controls, and key-management solutions.
  • Guide projects towards appropriate data-security techniques according to each use case.
  • Recommend the use of cryptography, anonymisation, pseudonymisation, tokenisation, or data masking when appropriate.
  • Define security requirements for data at rest, data in transit, and potentially data in use.
  • Evaluate cryptographic architectures, algorithms, protocols, key lifecycles, and protection mechanisms.
  • Help projects embed cryptography and data security from the design stage.

Technical Support and Proofs of Concept

  • Support subsidiaries and project teams in implementing required cryptographic security measures.
  • Participate in technical proofs of concept involving security and cryptography solutions.
  • Evaluate potential technologies and assess their suitability for enterprise use.
  • Collaborate with technical teams to validate the implementation of cryptographic requirements.
  • Provide expert guidance on complex cryptography and data-protection questions.

Knowledge Development and Security Community

  • Conduct continuous technological and cybersecurity monitoring.
  • Track developments in cryptographic standards, threats, vulnerabilities, and solutions.
  • Share relevant findings and recommendations with the wider cybersecurity team.
  • Contribute to internal security communities and knowledge-sharing initiatives.
  • Lead meetings, workshops, seminars, and committees.
  • Produce clear technical documentation, security requirements, and guidance.

Mandatory Requirements

  • Senior-level professional experience in cybersecurity, information security, or IT risk.
  • Strong knowledge of cryptography and data-protection principles.
  • Experience defining security requirements for cryptographic solutions.
  • Ability to assess the robustness of cryptographic designs and data-protection mechanisms.
  • Knowledge of encryption, hashing, digital signatures, certificates, and key-management concepts.
  • Experience conducting or validating cybersecurity risk assessments.
  • Ability to identify security risks, evaluate their impact, and propose effective countermeasures.
  • Strong general understanding of IT environments and enterprise-security practices.
  • Ability to work effectively across business, IT, architecture, and cybersecurity teams.
  • Mastery-level English.
  • Strong written and verbal communication skills.

Highly Valued Qualifications

  • Experience defining enterprise cryptography strategies or governance frameworks.
  • Knowledge of Cryptographic Key Management Systems and Public Key Infrastructure.
  • Experience with Hardware Security Modules.
  • Knowledge of cryptographic asset discovery and inventory management.
  • Understanding of crypto-agility and cryptographic lifecycle management.
  • Knowledge of post-quantum cryptography and migration-readiness principles.
  • Experience with data anonymisation, pseudonymisation, tokenisation, and masking.
  • Practical experience participating in technical proofs of concept.
  • Experience supporting geographically distributed subsidiaries or business entities.
  • Knowledge of cybersecurity and IT risk within banking or financial services.
  • Familiarity with data-protection regulations and security standards.
  • Experience facilitating technical meetings, workshops, seminars, or governance committees.

The Ideal Candidate

The ideal candidate is a senior cybersecurity specialist with deep knowledge of cryptography, key management, and data-protection techniques.

You can assess complex security designs, explain cryptographic risks clearly, and recommend practical controls according to the technical and business context. You are equally comfortable defining enterprise-level requirements, reviewing risk analyses, supporting projects, and participating in technical proofs of concept.

You demonstrate strong critical thinking, active listening, and communication skills. You also enjoy sharing knowledge, building professional networks, monitoring emerging technologies, and contributing to an international cybersecurity community.

Questions for Candidates

  • How many years of professional experience do you have in cybersecurity, cryptography, data security, or IT risk?
  • What experience do you have defining cryptography strategies, standards, or security requirements?
  • Have you assessed the robustness of cryptographic designs, key-protection mechanisms, or data-security architectures?
  • Which cryptographic technologies have you worked with, such as encryption, hashing, digital signatures, certificates, PKI, HSM, or CKMS?
  • Do you have experience with key generation, storage, rotation, revocation, recovery, and destruction?
  • Have you conducted or validated security risk assessments and proposed countermeasures?
  • Have you worked with data anonymisation, pseudonymisation, tokenisation, or masking?
  • Do you have experience creating an inventory of cryptographic assets?
  • Are you familiar with crypto-agility and cryptographic lifecycle management?
  • Do you have knowledge of post-quantum cryptography or cryptographic migration strategies?
  • Have you participated in technical proofs of concept involving cybersecurity solutions?
  • Do you have experience supporting multiple subsidiaries, entities, or international teams?
  • Have you worked in banking, financial services, or another regulated industry?
  • Have you led technical meetings, workshops, seminars, or security committees?
  • Is your English level mastery or fully proficient?
  • Are you currently based in Portugal?
  • Would you prefer to work in Lisbon or Porto?
  • What is your availability to start?
  • What are your salary expectations under RV or CTI?

Keywords to Include in Your CV

Cybersecurity, Cyber Security, Cryptography, Cryptographic Security, Data Security, Data Protection, Information Security, IT Risk, Cyber Risk, Encryption, Data Encryption, Encryption at Rest, Encryption in Transit, Key Management, Cryptographic Key Management, CKMS, Public Key Infrastructure, PKI, Hardware Security Module, HSM, Digital Certificates, Certificate Management, Digital Signatures, Hashing, Cryptographic Algorithms, Cryptographic Protocols, Cryptographic Keys, Key Rotation, Key Lifecycle Management, Cryptographic Asset Inventory, Crypto-Agility, Post-Quantum Cryptography, PQC, Quantum Readiness, Data Anonymisation, Data Anonymization, Pseudonymisation, Pseudonymization, Tokenisation, Tokenization, Data Masking, Security Requirements, Security Strategy, Security Architecture, Security by Design, Risk Assessment, Risk Analysis, Risk Anticipation, Countermeasures, Security Controls, Data Privacy, Proof of Concept, POC, Technology Watch, Enterprise Security, Cybersecurity Governance, IT Security, Financial Services, Banking, Digital Fraud, Operational Resilience, Stakeholder Management, Knowledge Sharing, Technical Workshops, Security Committee, Critical Thinking, English Fluent

#CI - PROC26489