> Markdown version of [/jobs/ext/3014544-certificate-lifecycle-pki-engineer-with-venafi-expertise](https://www.wearedevelopers.com/jobs/ext/3014544-certificate-lifecycle-pki-engineer-with-venafi-expertise). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Certificate Lifecycle / PKI Engineer with Venafi Expertise - **Company:** Northern Base - **Location:** Chicago, IL, United States (Remote available) - **Salary:** $62,998.0 - $90,586.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Apache HTTP Server, Apache Tomcat, Application Integration Architecture, Audit Trail, User Authentication, Microsoft Azure, Oracle WebLogic Server, Software as a Service, Cloud Computing Security, Continuous Integration, Linux, Domain Name System (DNS), Multi-Factor Authentication, Federated Identity Management, Github, Identity and Access Management, Internet Information Services (IIS), IT Management, Virtual Private Networks (VPN), Mobile Application Software, Python (Programming Language), Key Management, OAuth, OpenID, Open Web Application Security, Public Key Infrastructure, X.509, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Ansible, Kusto Query Language, Zero Trust Network Access, Security Assertion Markup Language (SAML), Session Management, Single Sign-On, Systems Integration, Transport Layer Security, Load Balancing, Okta, ReactJS, Software Security, Pingfederate, Kubernetes, Information Technology, Microsoft Sentinel, Apache Kafka, Front End Software Development, Restful APIs, Security Orchestration, Automation & Response, Servicenow, Microservices - **Published:** September 20, 2026 - **Apply:** https://www.careerjet.com/jobad/us39f34c0e0adf0184d04857d69038f799 ## About the Role * Public Key Infrastructure (PKI) and Cryptography * X.509 Certificates, TLS/SSL, Certificate Authorities * CRL, OCSP, Key Management, and HSM * Root and Intermediate CA Management * Code Signing Certificates * Venafi Trust Protection Platform (TPP) * Venafi SaaS and Certificate Discovery * Certificate Automation and Lifecycle Workflows * Venafi APIs, Adaptable Apps, and Native Drivers * Certificate Reporting and Governance * Windows IIS, Linux/Unix, Apache, Tomcat, WebLogic * Microsoft Azure and Azure Key Vault * Kubernetes and F5 Load Balancers * ServiceNow Integrations * GitHub Actions, Azure DevOps, and CI/CD Pipelines * PowerShell, Python, REST APIs, and Ansible * Identity and Access Management (IAM) * Authentication, Authorization, and Secrets Management * Zero Trust and Cloud Security Preferred Experience: * Entra ID / Azure AD * Microsoft Entra Permissions Management (EPM) * Microsoft Sentinel and KQL * AWS Security * Okta and PingFederate * OAuth, OIDC, SAML, SSO, MFA, and Conditional Access * JWT and Session Management * API Security and Application Registration * CIEM and Privileged Identity Management * Threat Modeling and OWASP * Docker and Kubernetes Security * Kafka and Solace * Java Microservices and React Applications * Azure Application Gateway, WAF, NSGs, DLP, VPN, DNS, and CDN * Infrastructure and Security Automation, * Bachelor's Degree in Computer Science or related field preferred ## Description * Lead identity-centric workforce security initiatives focused on authentication and access management * Develop identity solutions using Zero Trust, least privilege, and defense-in-depth principles * Design and implement certificate lifecycle and PKI automation solutions * Support Entra ID identity, authentication flows, and modern identity patterns * Review and provide security guidance on identity and access management solutions * Troubleshoot complex identity and certificate-related issues using Sentinel, KQL, audit logs, and platform tools * Support OAuth/OIDC flows, authorization patterns, identity federation, cryptography, and cloud-native security * Develop security solutions for microservices, frontend, and mobile applications * Support code signing, certificate authentication, TLS/SSL, API security, and application integrations * Contribute to CIEM, RBAC, PAM, JIT access, secrets management, and identity governance solutions * Apply threat modeling, application security, and OWASP security practices * Support container and Kubernetes security initiatives * Collaborate with stakeholders and provide security consultation to IT management and technology teams, Description: This position is based on a hybrid work schedule and will require in-office work 3 days per week. This position will offer you the ability to directly apply your kn… + 1 month ago + ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)