Key management is the interesting part, although it's possible to screw up just in the crypto part as well. Encryption is just a way of substituting the trouble of keeping the key secret vs keeping the data secret.
You're going to match your key management to your threat model.
What are you going to do to keep the key safe in the scenarios of your threat model where an adversary can access the DB contents?