PKI Certificate Management - Security Identity Engineer
Core
Engineering, operating, and improving Public Key Infrastructure (PKI) and Certificate Lifecycle Management (CLM) to ensure trusted identity, authentication, and encryption services across enterprise and cloud environments.
Role type
Senior IC Security PKI Engineer
Builds
Production PKI and CLM services, automation scripts, and monitoring systems for certificate operations.
Domain
Cyber Security / Identity & Access Management / PKI
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
PKI architecture design, X.509 certificate management, Certificate Authority operations, certificate lifecycle management, HSM management, cloud security, SRE practices, automation scripting, incident response, crypto agility, Post-Quantum Cryptography readiness
Preferred skills
PKI/CLM platform training, public CA program familiarity, security certifications
Technologies
Microsoft AD CS, CyberArk Certificate Manager, Venafi, DigiCert, Keyfactor, Entrust, Sectigo, EJBCA, Azure, AWS, GCP, PowerShell, Python, Bash, Kubernetes, Active Directory, Entra ID, Kerberos, NTLM, SAML, OAuth, OIDC
Responsibilities
Engineer, administer, and maintain PKI components including Root, Intermediate, and Issuing Certificate Authorities; Operate and support certificate validation and distribution services including CRLs, OCSP, AIA, and CDP; Execute end-to-end certificate lifecycle processes; Maintain certificate inventory hygiene and address crypto compliance gaps; Build automation to prevent problem recurrence; Improve monitoring and alerting for certificate expiry and CA health; Provide mentorship and advice to team members on improving availability and performance of critical services
Seniority
Manager, hands-on IC