Job Summary
We are seeking a highly experienced PKI professional to support the design, administration, modernization, and operational management of enterprise Public Key Infrastructure (PKI) environments. The role requires deep expertise in Microsoft Active Directory Certificate Services (ADCS), Certificate Authorities (CA), Certificate Revocation Lists (CRL), certificate lifecycle management, and enterprise identity security. This position will help strengthen enterprise certificate management, modernize PKI operations, improve certificate lifecycle governance, and support broader identity and access management initiatives, including machine and non-human identity security.
Key Responsibilities
• Design, implement, and maintain enterprise PKI environments.
• Administer and support Microsoft Active Directory Certificate Services (ADCS).
• Manage Root CA, Intermediate CA, and Issuing CA infrastructure.
• Configure and maintain Certificate Revocation Lists (CRL) and Online Certificate Status Protocol (OCSP).
• Oversee certificate issuance, renewal, revocation, and lifecycle management processes.
• Implement certificate automation for servers, applications, users, and devices.
• Support encryption, digital signing, authentication, and secure communications initiatives.
• Troubleshoot PKI-related issues impacting applications, servers, and network infrastructure.
• Ensure compliance with security policies, regulatory requirements, and industry best practices.
• Develop PKI architecture documentation, operational procedures, and governance standards.
• Partner with IAM, Cybersecurity, Infrastructure, and Application teams on certificate-related initiatives.
• Support PKI migrations, upgrades, and modernization projects.
• Secure service accounts, machine identities, and non-human identities.
Required Qualifications
• 8+ years of experience in PKI and Identity Security.
• Strong hands-on expertise with Microsoft ADCS.
• Strong experience with Certificate Authorities (CA), including Root CA, Intermediate CA, and Issuing CA infrastructure.
• Strong experience with Certificate Revocation Lists (CRL) and OCSP.
• Experience with SSL/TLS certificates.
• Strong knowledge of certificate lifecycle management.
• Experience with Active Directory.
• Experience with Microsoft Entra ID / Azure AD.
• Experience securing service accounts, machine identities, and non-human identities.
• Strong troubleshooting and root-cause analysis skills.
• Experience with PKI migrations, upgrades, and modernization projects.
Preferred Qualifications
• Experience with Venafi, Keyfactor, AppViewX, DigiCert Trust Lifecycle Manager, or similar certificate management platforms.
• Knowledge of Zero Trust security principles.
• Understanding of Hardware Security Modules (HSMs).
• Experience with IAM platforms such as SailPoint, Saviynt, CyberArk, BeyondTrust, or Delinea.
• Experience with cloud PKI and certificate services in Azure and AWS.
• Experience with automation using PowerShell or other scripting languages.
Certifications
• Security certifications such as CISSP, Microsoft Security, or PKI-related certifications.