Identity Encryption Engineer (PKI & Secrets Management)

Tranzeal, Inc.
United States
2 months ago
Apply on dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Continuous Integration DevOps Key Management Public Key Infrastructure Windows PowerShell SSL Certificate Management Google Cloud Cloud Platform System Cyberark Infrastructure as Code (IaC)
+3 more
Hashicorp Api Design Restful APIs

Job description

Seeking a Senior Identity Encryption Engineer with deep expertise in PKI, certificate lifecycle management, and enterprise secrets management. This role will modernize and automate cryptographic services by building scalable, self-service solutions, integrating enterprise security platforms, and implementing best practices across the organization., * Design, implement, and optimize enterprise PKI and certificate management solutions.

  • Build self-service certificate provisioning and lifecycle automation.
  • Develop API-driven integrations with Keyfactor, HashiCorp Vault, Azure Key Vault, and CI/CD pipelines.
  • Standardize certificate and secrets management across enterprise environments.
  • Automate workflows using PowerShell and Infrastructure as Code (IaC).
  • Deploy and manage HSMs and strengthen platform security through monitoring, patching, and system hardening.
  • Serve as the senior escalation point for complex PKI and directory services issues.
  • Collaborate with engineering, security, and DevOps teams to deliver secure, scalable solutions.

Requirements

  • 9+ years of experience with PKI, certificate lifecycle management, and cryptographic platforms.
  • 5+ years automating PKI, directory services, or secrets management.
  • Strong PowerShell scripting experience.
  • Hands-on experience with HSMs, REST APIs, IaC, and CI/CD.
  • Experience with Azure, AWS, or Google Cloud Platform (Azure Key Vault preferred).
  • Strong understanding of ITIL processes and enterprise security best practices.
  • Keyfactor Certificate Lifecycle Automation.
  • HashiCorp Vault and/or CyberArk.
  • Enterprise DevOps and secrets management experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

5:24 min

Demonstrating database encryption at rest with HashiCorp Vault

Alex Soto Alex Soto · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:39 min

Generating dynamic application secrets using HashiCorp Vault engines

Alex Soto Alex Soto · LIVE

Videos

See all

Related articles

See all