Required Skills: PKI, Venafi, vCert, PowerShell, Ansible, Azure DevOps, CI/CD, Apache, Kafka, Governance, X.509
Job Description
Must Have Technical/Functional Skills
PKI & Security Architecture
· Design and maintain enterprise PKI architecture, including Root CA, Issuing CA, CRL, OCSP, HSM, and trust frameworks.
· Develop certificate governance standards, policies, and cryptographic control frameworks.
· Architect highly available and resilient PKI and CLM platforms.
· Drive enterprise machine identity and certificate management strategy.
Venafi Platform Architecture
· Design and administer Venafi Trust Protection Platform (TPP).
· Define onboarding standards, workflows, policies, reporting, discovery jobs, and access models.
· Architect integrations between Venafi and enterprise applications, cloud services, and security platforms.
· Lead Venafi platform upgrades, enhancements, and optimization initiatives.
Roles & Responsibilities
Certificate Lifecycle Automation
· Architect automated certificate provisioning and renewal solutions.
· Design automation frameworks using:
o Venafi APIs
o vCert
o PowerShell
o Python
o Ansible
o GitHub Actions
o Azure DevOps o CI/CD pipelines
· Drive adoption of certificate automation across enterprise application portfolios. Application & Cloud Integration
· Lead application onboarding into CLM services.
· Support certificate deployment and automation across:
o Windows Server
o Linux/Unix
o IIS
o Apache o Tomcat o WebLogic
o Kubernetes
o Azure
o AWS
o F5 Load Balancers
o Kafka
o Solace
o PingFederate
· Provide architecture guidance and troubleshooting support for complex trust and certificate-related issues.
Governance & Compliance
· Ensure compliance with NIST, PCI-DSS, SOX, ISO 27001, FedRAMP, and enterprise security standards.
· Conduct cryptographic risk assessments and certificate posture reviews.
· Define certificate ownership models and governance processes.
· Support audits and regulatory compliance activities
Required Qualifications
· Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related discipline.
· 10+ years of Information Security experience.
· 5+ years of hands-on PKI architecture experience.
· 5+ years of Venafi Trust Protection Platform experience.
· Strong expertise in:
o X.509 Certificates
o TLS/SSL
o PKI
o CLM o CRL/OCSP
o HSM Technologies
o Digital Signatures
o Cryptographic Key Management
· Experience designing PKI solutions in Azure and AWS environments.
· Strong scripting skills using PowerShell and Python.
Preferred Qualifications
· CISSP, CISM, CCSP, or equivalent certification.
· Venafi Certified Professional/Architect certification.
·Experience with:
o Keyfactor
o DigiCert
o Entrust
o Microsoft ADCS
o HashiCorp Vault
o Azure Key Vault
o AWS Certificate Manager
· Experience operating in BFSI or other highly regulated environments.
Technical Skills PKI & Cryptography
· PKI Architecture
· X.509 Certificates
· TLS/SSL
· PKCS Standards
· Digital Signatures
· HSM Integration
· CRL / OCSP Venafi
· Venafi TPP
· Venafi TLS Protect
· Certificate Discovery
· Policy Management
· Workflow Automation
· Reporting & Governance Cloud & DevOps
· Azure
· AWS
· Kubernetes
· GitHub Actions
· Azure DevOps
· CI/CD Pipelines
· Infrastructure as Code Programming & Automation
· PowerShell · Python
· REST APIs
· Ansible Leadership Expectations
· Serve as the PKI and Machine Identity SME.
· Provide technical leadership to engineering and operations teams.
· Develop enterprise PKI roadmaps and modernization strategies.
· Mentor engineers and establish best practices for certificate lifecycle management.
· Drive Zero Trust and identity-centric security initiatives.