PKI Venafi Architect
  • ClifyX Inc.
1 Hours Ago
NA
Yearly
Tempe-AZ, Chicago-IL
8-10 Years
Required Skills: X.509 Certificates ,TLS, SSL, PKI, CLM,CRL, OCSP, HSM Technologies, Digital Signatures, Cryptographic Key Management, PowerShell, Python scripting, Keyfactor, DigiCert, Entrust, Microsoft ADCS, HashiCorp Vault, Azure Key Vault, WS Certificate Manager, BFSI
Job Description
Must Have Technical/Functional Skills
PKI & Security Architecture
· Design and maintain enterprise PKI architecture, including Root CA, Issuing CA, CRL, OCSP, HSM, and trust frameworks.
· Develop certificate governance standards, policies, and cryptographic control frameworks.
· Architect highly available and resilient PKI and CLM platforms.
· Drive enterprise machine identity and certificate management strategy. 

Venafi Platform Architecture
· Design and administer Venafi Trust Protection Platform (TPP).
· Define onboarding standards, workflows, policies, reporting, discovery jobs, and access models.
· Architect integrations between Venafi and enterprise applications, cloud services, and security platforms.
· Lead Venafi platform upgrades, enhancements, and optimization initiatives.

Roles & Responsibilities
Certificate Lifecycle Automation
· Architect automated certificate provisioning and renewal solutions.
· Design automation frameworks using:
o Venafi APIs
o vCert
o PowerShell
o Python
o Ansible
o GitHub Actions
o Azure DevOps o CI/CD pipelines 
· Drive adoption of certificate automation across enterprise application portfolios. Application & Cloud Integration 
· Lead application onboarding into CLM services. 
· Support certificate deployment and automation across: 
o Windows Server 
o Linux/Unix 
o IIS 
o Apache o Tomcat o WebLogic 
o Kubernetes 
o Azure 
o AWS 
o F5 Load Balancers 
o Kafka 
o Solace 
o PingFederate 
· Provide architecture guidance and troubleshooting support for complex trust and certificate-related issues. 

Governance & Compliance 
· Ensure compliance with NIST, PCI-DSS, SOX, ISO 27001, FedRAMP, and enterprise security standards. 
· Conduct cryptographic risk assessments and certificate posture reviews. 
· Define certificate ownership models and governance processes. 
· Support audits and regulatory compliance activities 

Required Qualifications 
· Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related discipline. 
· 10+ years of Information Security experience. 
· 5+ years of hands-on PKI architecture experience. 
· 5+ years of Venafi Trust Protection Platform experience. 

Technical Skills PKI & Cryptography 
· PKI Architecture 
· X.509 Certificates 
· TLS/SSL 
· PKCS Standards 
· Digital Signatures 
· HSM Integration 
· CRL / OCSP Venafi 
· Venafi TPP 
· Venafi TLS Protect 
· Certificate Discovery 
· Policy Management 
· Workflow Automation 
· Reporting & Governance Cloud & DevOps 
· Azure 
· AWS 
· Kubernetes 
· GitHub Actions 
· Azure DevOps 
· CI/CD Pipelines 
· Infrastructure as Code Programming & Automation 
· PowerShell · Python 
· REST APIs 
· Ansible Leadership Expectations 
· Serve as the PKI and Machine Identity SME. 
· Provide technical leadership to engineering and operations teams. 
· Develop enterprise PKI roadmaps and modernization strategies. 
· Mentor engineers and establish best practices for certificate lifecycle management. 
· Drive Zero Trust and identity-centric security initiatives.

Jobseeker

Looking For Job?
Search Jobs

Recruiter

Are You Recruiting?
Search Candidates