Certificate Lifecycle, PKI Engineer
  • ClifyX Inc.
3 Hours Ago
NA
Yearly
Remote
8-10 Years
Required Skills: PKI & Cryptography, Public Key Infrastructure, PKI, X.509 Certificates, TLS, SSL, Certificate Authorities, CA, Certificate Revocation Lists, CRL, OCSP, Key Management, Hardware Security Modules, HSM
Job Description
Certificate Lifecycle/ PKI Engineer with Venafi Expertise
Must Have Technical/Functional Skills
· PKI & Cryptography
o Public Key Infrastructure (PKI)
o X.509 Certificates
o TLS/SSL
o Certificate Authorities (CA)
o Certificate Revocation Lists (CRL)
o OCSP
o Key Management
o Hardware Security Modules (HSM)
o Code Signing Certificates
o Root and Intermediate CA Management

· Venafi Expertise
o Venafi Trust Protection Platform (TPP)
o Venafi SaaS
o Certificate Discovery 
o Certificate Automation o Venafi APIs 
o Adaptable Apps 
o Native Drivers 
o Reporting and Governance 
o Certificate Lifecycle Workflows 

· Platforms & Integrations 
o Windows IIS 
o Linux/Unix 
o Microsoft Azure 
o Azure Key Vault 
o Kubernetes 
o F5 Load Balancers 
o Apache 
o Tomcat 
o WebLogic 
o Kafka 
o Solace 
o Ping Federate 
o ServiceNow Integrations 

· DevOps & Automation 
o GitHub Actions 
o Azure DevOps 
o CI/CD Pipelines 
o PowerShell 
o Python 
o REST APIs 
o Ansible 
o Infrastructure Automation 

· Security Domains 
o Authentication 
o Authorization 
o Identity & Access Management 
o Secrets Management 
o Zero Trust Principles 
o Cloud Security 
o Security Monitoring 
· Strong understanding of PKI architecture and certificate lifecycle processes. 
· Experience implementing certificate automation patterns and DevSecOps integrations. 
· Experience supporting enterprise-scale certificate environments. 
· Strong troubleshooting, analytical, and problem-solving skills. 
· Excellent communication and stakeholder management skills.

Roles & Responsibilities
• Lead Identity centric Workforce Security team to develop authentication and access management solutions 
• Drive the development of identity solutions, access patterns, modern security protocols, practicing Zero trust, least privileged, defense in depth principles 
• Good understanding of AI concepts, Patterns and impact on identity and access management domain 
• Participate and engage in AI adoption with Identity focus, knowledge and understanding of Entra ID agentic Identity, authentication flows and Patterns 
• Review and provide feedback on Identity and access management related security solutions proposed by stakeholders and can provide consultation to the partners and IT Management 
• In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, AWS Security 
• Knowledge on Okta, PingFederate, Entitlement management solutions 
• Strong knowledge on Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, Conditional access policies, MFA, Kerberos, LDAP, Identity Federations etc. 
• Experience in providing security solutions for Java based Micro services, React based frontends and Android/iOS based mobile applications on the Azure 
• Hands-of experience in JWT, session handling, Code signing, Certificate authentication, TLS/SSL, API Security, Application registration, application integration scenarios etc. 
• Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc. 
• Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure smooth remediation of toxic combinations, high risk entitlements etc. 
• Understanding and application of threat modeling concepts and methodologies 
• Understanding of Applications security, OWASP standards, security best practices, browser compatibilities/storages/cookies 
• Acts as Workforce cybersecurity expert to in solutions spanning end user computing, proxy solutions, MFA, SSO, conditional accesses, Passwordless, Yubikey, bio-metric solutions, identity and governance scenarios, Secrets Management, automation, role based access control, Privileged identity management, Just in time accesses etc. 
• Participates in solutions to support- token handling, OIDC/ OAuth flows, authorization patterns, identity federation, cloud architectures, cryptography, cloud native services, cloud security etc. 
• Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, privileged access management etc. 
• Ability to support operations in troubleshooting complex identity scenarios with hands-on experience on Sentinel/KQL/Audit logs etc. 
• Good understanding of concepts related to docker Security, container orchestrations/Kubernetes

Jobseeker

Looking For Job?
Search Jobs

Recruiter

Are You Recruiting?
Search Candidates