Certificate Lifecycle / PKI Engineer with Venafi Expertise

Northern Base
Chicago, IL, United States
3 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$62,998.0 - $90,586.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Microsoft Windows Application Programming Interfaces (APIs) Amazon Web Services Apache HTTP Server Apache Tomcat Application Integration Architecture Audit Trail User Authentication Microsoft Azure Oracle WebLogic Server Software as a Service
+44 more
Cloud Computing Security Continuous Integration Linux Domain Name System (DNS) Multi-Factor Authentication Federated Identity Management Github Identity and Access Management Internet Information Services (IIS) IT Management Virtual Private Networks (VPN) Mobile Application Software Python (Programming Language) Key Management OAuth OpenID Open Web Application Security Public Key Infrastructure X.509 Windows PowerShell Role-Based Access Control Azure Active Directory Ansible Kusto Query Language Zero Trust Network Access Security Assertion Markup Language (SAML) Session Management Single Sign-On Systems Integration Transport Layer Security Load Balancing Okta ReactJS Software Security Pingfederate Kubernetes Information Technology Microsoft Sentinel Apache Kafka Front End Software Development Restful APIs Security Orchestration, Automation & Response Servicenow Microservices

Job description

  • Lead identity-centric workforce security initiatives focused on authentication and access management
  • Develop identity solutions using Zero Trust, least privilege, and defense-in-depth principles
  • Design and implement certificate lifecycle and PKI automation solutions
  • Support Entra ID identity, authentication flows, and modern identity patterns
  • Review and provide security guidance on identity and access management solutions
  • Troubleshoot complex identity and certificate-related issues using Sentinel, KQL, audit logs, and platform tools
  • Support OAuth/OIDC flows, authorization patterns, identity federation, cryptography, and cloud-native security
  • Develop security solutions for microservices, frontend, and mobile applications
  • Support code signing, certificate authentication, TLS/SSL, API security, and application integrations
  • Contribute to CIEM, RBAC, PAM, JIT access, secrets management, and identity governance solutions
  • Apply threat modeling, application security, and OWASP security practices
  • Support container and Kubernetes security initiatives
  • Collaborate with stakeholders and provide security consultation to IT management and technology teams, Description: This position is based on a hybrid work schedule and will require in-office work 3 days per week. This position will offer you the ability to directly apply your kn…
  • 1 month ago +

Requirements

  • Public Key Infrastructure (PKI) and Cryptography
  • X.509 Certificates, TLS/SSL, Certificate Authorities
  • CRL, OCSP, Key Management, and HSM
  • Root and Intermediate CA Management
  • Code Signing Certificates
  • Venafi Trust Protection Platform (TPP)
  • Venafi SaaS and Certificate Discovery
  • Certificate Automation and Lifecycle Workflows
  • Venafi APIs, Adaptable Apps, and Native Drivers
  • Certificate Reporting and Governance
  • Windows IIS, Linux/Unix, Apache, Tomcat, WebLogic
  • Microsoft Azure and Azure Key Vault
  • Kubernetes and F5 Load Balancers
  • ServiceNow Integrations
  • GitHub Actions, Azure DevOps, and CI/CD Pipelines
  • PowerShell, Python, REST APIs, and Ansible
  • Identity and Access Management (IAM)
  • Authentication, Authorization, and Secrets Management
  • Zero Trust and Cloud Security

Preferred Experience:

  • Entra ID / Azure AD
  • Microsoft Entra Permissions Management (EPM)
  • Microsoft Sentinel and KQL
  • AWS Security
  • Okta and PingFederate
  • OAuth, OIDC, SAML, SSO, MFA, and Conditional Access
  • JWT and Session Management
  • API Security and Application Registration
  • CIEM and Privileged Identity Management
  • Threat Modeling and OWASP
  • Docker and Kubernetes Security
  • Kafka and Solace
  • Java Microservices and React Applications
  • Azure Application Gateway, WAF, NSGs, DLP, VPN, DNS, and CDN
  • Infrastructure and Security Automation, * Bachelor’s Degree in Computer Science or related field preferred

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all