Certificate Lifecycle/ PKI Engineer with Venafi Expertise

Siri InfoSolutions Inc
Chicago, IL, United States
1 day ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$62,998.0 - $90,586.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) Microsoft Windows Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Apache HTTP Server Apache Tomcat Application Integration Architecture Audit Trail User Authentication Microsoft Azure Oracle WebLogic Server
+54 more
Software as a Service Cloud Computing Cloud Computing Security Linux DevOps Domain Name System (DNS) Multi-Factor Authentication Federated Identity Management Github Hardware Security Module Identity and Access Management Internet Information Services (IIS) IT Management Virtual Private Networks (VPN) Mobile Application Software Python (Programming Language) Key Management Lightweight Directory Access Protocols (LDAP) Massachusetts Comprehensive Assessment Systems OAuth OpenID Open Web Application Security Ping (Networking Utility) Public Key Infrastructure X.509 Windows PowerShell Role-Based Access Control Azure Active Directory Cloud Services Ansible Kusto Query Language Zero Trust Network Access Security Assertion Markup Language (SAML) Single Sign-On Systems Integration Transport Layer Security Load Balancing Cloud Platform System Okta ReactJS Software Security Software Troubleshooting Firewalls (Computer Science) Pingfederate Kubernetes Infrastructure Automation Frameworks Apache Kafka Front End Software Development Restful APIs Devsecops Api Management Docker Servicenow Microservices

Requirements

5+ years of experience supporting PKI, TLS Certificates, or Certificate Lifecycle Management. 3+ years of hands-on Venafi administration and engineering experience Lead Identity centric Workforce Security team to develop authentication and access management solutions Drive the development of identity solutions, access patterns, modern security protocols, practicing Zero trust, least privileged, defense in depth principles Good understanding of AI concepts, Patterns and impact on identity and access management domain Participate and engage in AI adoption with Identity focus, knowledge and understanding of Entra ID agentic Identity, authentication flows and Patterns Review and provide feedback on Identity and access management related security solutions proposed by stakeholders and can provide consultation to the partners and IT Management In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, AWS Security Knowledge on Okta, PingFederate, Entitlement management solutions Strong knowledge on Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, Conditional access policies, MFA, Ker beros, LDAP, Identity Federations etc. Experience in providing security solutions for Java based Micro services, React based frontends and Android/iOS based mobile applications on the Azure Hands-of experience in JWT, session handling, Code signing, Certificate authentication, TLS/SSL, API Security, Application registration, application integration scenarios etc. Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc. Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure smooth remediation of toxic combinations, high risk entitlements etc. Understanding and application of threat modeling concepts and methodologies Understanding of Applications security, OWASP standards, security best practices, browser compatibilities/storages/cookies Acts as Workforce cybersecurity expert to in solutions spanning end user computing, proxy solutions, MFA, SSO, conditional accesses, Passwordless, Yubikey, bio-metric solutions, identity and governance scenarios, Secrets Management, automation, role based access control, Privileged identity management, Just in time accesses etc. Participates in solutions to support- token handling, OIDC/ OAuth flows, authorization patterns, identity federation, cloud architectures, cryptography, cloud native services, cloud security etc. Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, privileged access management etc. Ability to support operations in troubleshooting complex identity scenarios with hands-on experience on Sentinel/KQL/Audit logs etc. Good understanding of concepts related to docker Security, container orchestrations/Kubernetes Must Have Technical/Functional Skills PKI & Cryptography o Public Key Infrastructure (PKI) o X.509 Certificates o TLS/SSL o Certificate Authorities (CA) o Certificate Revocation Lists (CRL) o OCSP o Key Management o Hardware Security Modules (HSM) o Code Signing Certificates o Root and Intermediate CA Management Venafi Expertise o Venafi Trust Protection Platform (TPP) o Venafi SaaS o Certificate Discovery o Certificate Automation o Venafi APIs o Adaptable Apps o Native Drivers o Reporting and Governance o Certificate Lifecycle Workflows Platforms & Integrations o Windows IIS o Linux/Unix o Microsoft Azure o Azure Key Vault o Kubernetes o F5 Load Balancers o Apache o Tomcat o WebLogic o Kafka o Solace o Ping Federate o ServiceNow Integrations DevOps & Automation o GitHub Actions o Azure DevOps o CI/CD Pipelines o PowerShell o Python o REST APIs o Ansible o Infrastructure Automation Security Domains o Authentication o Authorization o Identity & Access Management o Secrets Management o Zero Trust Principles o Cloud Security o Security Monitoring Strong understanding of PKI architecture and certificate lifecycle processes. Experience implementing certificate automation patterns and DevSecOps integrations. Experience supporting enterprise-scale certificate environments. Strong troubleshooting, analytical, and problem-solving skills. Excellent communication and stakeholder management skills.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all