Protect personal information without making a lost device the end of a person's digital life. You will design key custody and recovery.
Not open yet: Pilot expansion
This work starts when that stage arrives, so there is no application to submit today and we will not pretend otherwise. What is written below is what the role is for and what would make somebody right for it, published early on purpose so you can decide whether it is worth watching.
The work
Use established cryptographic libraries and protocols for encryption, key hierarchy, rotation and secure sharing. Work with platform hardware protections where available. Model recovery contacts, service compromise and malicious insiders, and document exactly who can decrypt which data.
The milestone
In your first 90 days, deliver a reviewed key-management design and a tested recovery prototype with explicit security assumptions.
Evidence
Bring applied cryptography and secure implementation experience. Be able to reason about entropy, authentication, protocol composition and the limits of cryptographic erasure.
Evidence, not credentials. We are describing work you can point at, in whatever form it exists.
The exercise
Explain how a user can recover after losing every device without introducing an undisclosed service-side master key.