ORB-REC-0031
Design the end‑to‑end encryption solution for sensitive workloads on AWS (technical architecture, operating model, governance framework). Integrate AWS KMS, XKS, CloudHSM with Thales HSMs and SG’s security ecosystem. Ensure solution alignment with SG’s cloud, cybersecurity, and compliance standards. Define dependency mapping, lifecycle management, and disaster recovery/BCP for key‑management services. Good-to-Have Validation & Cross‑Team Alignment Present and validate the solution with Architecture teams, Security teams, and Cloud Governance. Facilitate design reviews, architecture boards, risk assessments, and cryptographic compliance checks. Ensure full traceability of decisions, risks, and technical controls.