Location Designation: Hybrid - 3 days per quarter
Technology, Data, AI and Ventures:
The Corporate Vice President - Enterprise PKI & Cryptographic Engineering is a senior, hands-on technical leader accountable for the architecture, engineering, and modernization of New York Life's enterprise Public Key Infrastructure, certificate lifecycle, and cryptographic services across data center, cloud (AWS, Azure, and GCP), applications, devices, workloads, and non-human identities. This is a builder role, not a purely advisory one: you'll move from architecture into hands-on design, automation, and production delivery.
You'll own PKI and certificate lifecycle automation end to end, serve as the CISO organization's PKI and cryptographic subject matter expert for the Security Review Board and IS Exception process, and help position NYL for cryptographic agility and post-quantum readiness.
What You'll Do:
• Design, engineer, and modernize enterprise PKI services and trust hierarchies - offline root CAs, issuing/subordinate CAs, and cloud-native issuance - spanning users, applications, devices, workloads, APIs, and non-human identities.
• Engineer and administer Microsoft AD CS, including CA configuration, certificate templates, auto-enrollment, trust chains, CRLs, OCSP, and recovery capabilities.
• Own Certificate Lifecycle Management (CLM): drive discovery, inventory, issuance, renewal, revocation, and reporting from fragmented manual processes toward centralized, policy-driven automation.
• Build automation and reusable, self-service certificate APIs using ACME, SCEP, EST, REST, PowerShell, and Python; integrate with ServiceNow, CI/CD, Kubernetes, and DevOps tooling.
• Engineer HSM/KMS backed CA and signing services, including key ceremonies, backup, rotation, access control, and disaster recovery, across on-prem and cloud (AWS, Azure, GCP).
• Serve as the PKI and cryptographic engineering subject-matter expert for the Security Review Board and Architecture Review Board, and provide authoritative technical risk recommendations on IS Exception requests.
• Maintain strong knowledge of Active Directory and Microsoft Entra ID where they intersect with certificate services, certificate-based authentication, device identity, Conditional Access, and Privileged Identity Management.
• Maintain the enterprise cryptographic inventory and drive cryptographic agility, short-lived certificates, and post-quantum migration readiness.
• Treat PKI as business critical infrastructure: define resiliency, monitoring, and recovery procedures, and lead incident response and root-cause analysis for certificate, key, and trust failures.
• Serve as the senior technical authority for complex production certificate, trust, and cryptographic issues, translating decisions into reusable enterprise patterns.
What You'll Bring:
• Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or equivalent practical experience.
• 8+ years of progressive, hands-on experience in PKI, cryptographic engineering, identity engineering, or security engineering, with significant responsibility for enterprise PKI environments.
• Deep hands-on experience engineering or operating enterprise certificate authority environments, including Microsoft AD CS, certificate templates, trust chains, CRLs, and OCSP.
• Strong understanding of X.509, TLS/mTLS, certificate enrollment, revocation, trust models, and cryptographic key management.
• Experience implementing or operating an enterprise CLM platform and automating certificate lifecycle processes with ACME, SCEP, EST, REST APIs, PowerShell, or Python.
• Experience with certificate discovery and inventory across complex enterprise infrastructure, cloud platforms, containers, and Kubernetes.
• Experience with HSMs, KMS platforms, private-key protection, or cloud key-management services.
• Experience integrating PKI with cloud platforms (AWS, Azure, GCP), APIs, DevOps pipelines, service meshes, and workload identity patterns.
• Strong knowledge of Active Directory and Microsoft Entra ID, particularly where they intersect with PKI, certificate-based authentication, device identity, or non-human identity.
• Ability to conduct deep technical security reviews, identify material PKI and cryptographic risks, and define practical remediation or compensating controls.
• Strong communication skills, with the ability to explain complex PKI and cryptographic risk to engineers, architects, governance bodies, auditors, vendors, and senior leaders.
Preferred Qualifications:
• Experience with enterprise CLM platforms such as Venafi, AppViewX, Keyfactor, or DigiCert Trust Lifecycle Manager.
• Experience modernizing Microsoft AD CS or migrating toward managed private CA or PKI-as-a-Service.
• Experience with cloud PKI technologies such as AWS Private CA, Google Cloud Certificate Authority Service, or Azure Key Vault/Cloud PKI.
• Experience integrating certificate lifecycle capabilities with ServiceNow or similar workflow platforms.
• Experience with code signing, S/MIME, device certificates, Kubernetes certificate management, or service-mesh mTLS.
• Experience with cryptographic inventory, cryptographic-agility programs, or post-quantum migration initiatives.
• Experience implementing Microsoft's Enterprise Access Model, Tier 0 protections, or privileged-access modernization.
• Prior experience supporting a Security Review Board, Architecture Review Board, or IS Exception process; financial services or other regulated enterprise experience; relevant certifications (CISSP, CISM, CCSP, or a cloud security credential).
Job Level: LEVELPF5
Pay Transparency
Salary Range: $147,500-$211,000
Overtime eligible: Exempt
Discretionary bonus eligible: Yes
Sales bonus eligible: No
Actual base salary will be determined based on several factors but not limited to individual's experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
Our Benefits
We provide a full package of benefits for employees - and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work.Click hereto discover more about our comprehensive benefit options or visit our NYL Benefits Site.
Job Requisition ID: 94809