Job DescriptionWe are seeking an experienced and dedicated
Infrastructure Engineer specializing in Security, Certificates, and Networks. In this role, you will be responsible for safeguarding our enterprise network infrastructure, managing the lifecycle of digital certificates (PKI), and ensuring secure, high-performance data communication across our hybrid cloud and on-premises environments.
The ideal candidate possesses a deep understanding of network security protocols, hands-on experience automated certificate deployment, and a proven track record of maintaining secure network boundaries.
Key ResponsibilitiesPublic Key Infrastructure (PKI) & Certificate Management- LifecycleManagement: Oversee the end-to-end lifecycle (generation,installation, renewal, and revocation) of SSL/TLS and SSH certificatesacross servers, load balancers, and applications.
- Automation: Implement and manage automated certificate renewal pipelines usingprotocols like ACME and tools such as Venafi, Certbot, or HashiCorp Vault.
- Compliance: Ensure all internal and external-facing systems comply with corporateencryption and certificate authority (CA) standards (e.g., DigiCert, Let'sEncrypt, Microsoft ADCS).
Network Security & Administration- PerimeterSecurity: Deploy, configure, and maintain enterprise firewalls (e.g.,Palo Alto, Fortinet, Check Point), Intrusion Detection/Prevention Systems(IDS/IPS), and Web Application Firewalls (WAF).
- NetworkConnectivity: Manage secure site-to-site VPNs, remote access VPNs, andsoftware-defined networks (SDN) across hybrid environments.
- AccessControl: Implement and enforce Network Access Control (NAC) policies,segmenting networks to minimize security risks and control user and deviceaccess.
Monitoring & Incident Response- TrafficAnalysis: Monitor network traffic, logs, and alerts via SIEM tools todetect and investigate potential security breaches or anomalous activity.
- VulnerabilityRemediation: Identify network-level vulnerabilities, coordinate patchmanagement schedules for network appliances, and upgrade firmware toneutralize threats.
- DisasterRecovery: Maintain and regularly test network recovery configurationsto guarantee business continuity during outages or security incidents.
Required Skills & Qualifications- Experience: 5+ years of dedicated professional experience in network engineering,infrastructure security, or cyber security operations.
- CertificateExpertise: Thorough understanding of cryptographic protocols, PKIarchitecture, symmetric/asymmetric encryption, and managing SSL/TLScertificates.
- CoreNetworking: Deep knowledge of TCP/IP, routing protocols (BGP, OSPF),DNS architecture, and load balancing technologies (e.g., F5 BIG-IP, CitrixADC).
- SecurityHardware: Hands-on experience configuring and troubleshootingnext-generation enterprise firewalls and cloud network security groups(AWS NSGs / Azure Firewalls).
- IdentityManagement: Experience with secure protocols like OAuth2, SAML,RADIUS, and TACACS+.
Preferred/Nice-to-Have Skills- Proficiencywith Infrastructure as Code (IaC) tools like Terraform or Ansible forautomating network and security configurations.
- Scriptingcapability (Python, Bash, or PowerShell) to automate certificate renewalsand health checks.
- Relevantindustry certifications such as CISSP, CCNP Security, CompTIA Security+,or cloud provider security specialties (AWS/Azure).