PKI Venafi Architect
  • Clifyx Inc.
1 Hours Ago
NA
Yearly
Remote
7-30 Years
Required Skills: PKI, Venafi, vCert, PowerShell, Ansible, Azure DevOps, CI/CD, Apache, Kafka, Governance, X.509
Job Description
Must Have Technical/Functional Skills
PKI & Security Architecture
· Design and maintain enterprise PKI architecture, including Root CA, Issuing CA, CRL, OCSP, HSM, and trust frameworks.
· Develop certificate governance standards, policies, and cryptographic control frameworks.
· Architect highly available and resilient PKI and CLM platforms.
· Drive enterprise machine identity and certificate management strategy. 
 
Venafi Platform Architecture
· Design and administer Venafi Trust Protection Platform (TPP).
· Define onboarding standards, workflows, policies, reporting, discovery jobs, and access models.
· Architect integrations between Venafi and enterprise applications, cloud services, and security platforms.
· Lead Venafi platform upgrades, enhancements, and optimization initiatives.
 
Roles & Responsibilities
Certificate Lifecycle Automation
· Architect automated certificate provisioning and renewal solutions.
· Design automation frameworks using:
o Venafi APIs
o vCert
o PowerShell
o Python
o Ansible
o GitHub Actions
o Azure DevOps o CI/CD pipelines 
· Drive adoption of certificate automation across enterprise application portfolios. Application & Cloud Integration 
· Lead application onboarding into CLM services. 
· Support certificate deployment and automation across: 
o Windows Server 
o Linux/Unix 
o IIS 
o Apache o Tomcat o WebLogic 
o Kubernetes 
o Azure 
o AWS 
o F5 Load Balancers 
o Kafka 
o Solace 
o PingFederate 
· Provide architecture guidance and troubleshooting support for complex trust and certificate-related issues. 
 
Governance & Compliance 
· Ensure compliance with NIST, PCI-DSS, SOX, ISO 27001, FedRAMP, and enterprise security standards. 
· Conduct cryptographic risk assessments and certificate posture reviews. 
· Define certificate ownership models and governance processes. 
· Support audits and regulatory compliance activities 
 
Required Qualifications 
· Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related discipline. 
· 10+ years of Information Security experience. 
· 5+ years of hands-on PKI architecture experience. 
· 5+ years of Venafi Trust Protection Platform experience. 
· Strong expertise in: 
o X.509 Certificates 
o TLS/SSL 
o PKI 
o CLM o CRL/OCSP 
o HSM Technologies 
o Digital Signatures 
o Cryptographic Key Management 
· Experience designing PKI solutions in Azure and AWS environments. 
· Strong scripting skills using PowerShell and Python. 
 
Preferred Qualifications 
· CISSP, CISM, CCSP, or equivalent certification. 
· Venafi Certified Professional/Architect certification. 
 
·Experience with:
o Keyfactor 
o DigiCert 
o Entrust 
o Microsoft ADCS 
o HashiCorp Vault 
o Azure Key Vault 
o AWS Certificate Manager 
· Experience operating in BFSI or other highly regulated environments. 
 
Technical Skills PKI & Cryptography 
· PKI Architecture 
· X.509 Certificates 
· TLS/SSL 
· PKCS Standards 
· Digital Signatures 
· HSM Integration 
· CRL / OCSP Venafi 
· Venafi TPP 
· Venafi TLS Protect 
· Certificate Discovery 
· Policy Management 
· Workflow Automation 
· Reporting & Governance Cloud & DevOps 
· Azure 
· AWS 
· Kubernetes 
· GitHub Actions 
· Azure DevOps 
· CI/CD Pipelines 
· Infrastructure as Code Programming & Automation 
· PowerShell · Python 
· REST APIs 
· Ansible Leadership Expectations 
· Serve as the PKI and Machine Identity SME. 
· Provide technical leadership to engineering and operations teams. 
· Develop enterprise PKI roadmaps and modernization strategies. 
· Mentor engineers and establish best practices for certificate lifecycle management. 
· Drive Zero Trust and identity-centric security initiatives.

Jobseeker

Looking For Job?
Search Jobs

Recruiter

Are You Recruiting?
Search Candidates