Someone like that who suddenly starts using encryption is a major red flag. Fundamentalism, tactical training and a keep interest in prior attacks aren't enough to single out someone who's preparing an attack, but someone like that who went off the grid, started using encryption and just maxed out his credit card needs far more attention than someone spreading have from their basement.
Encryption suggests active planning. Using encryption is what you do when you are actively trying to hide your activity. The others are indicators of susceptible traits - but encryption suggests imminence and active involvement. If you have gone beyond just developing radical beliefs and start actually planning an attack, that's when you're likely to start using encryption and taking operational security seriously.
Has the subject engaged in or discussed tradecraft to hide their online activities contextually different from previous activity?
The relevant part isn't the encryption, but the context. If you have two email accounts, one for general usage, unencrypted, and one encrypted that you rarely use, but suddenly see a spike in usage, that's a red flag.
It isn't if you use encryption, but how you use it.