Senior PKI Architect Design & Implementation Specialist

Greenville, SC, US • Posted 10 hours ago • Updated 47 minutes ago
Contract W2
On-site
Fitment

Dice Job Match Score™

⭐ Evaluating experience...

Job Details

Skills

  • Deployment
  • including design
  • 10+ years of hands-on experience with Microsoft Active Directory Certificate Services (AD CS) -OR Equivalent platform
  • and troubleshooting of Certificate Authorities (CAs)
  • Online Responders (OCSP)
  • and Network Device Enrollment Service (NDES). 3+ years of expertise in certificate lifecycle management (CLM) platforms (e.g.
  • Venafi
  • AppViewX
  • Keyfactor) and Hardware Security Modules (HSMs) (e.g.
  • Thales
  • nCipher
  • Utimaco). 5+ years of proven track record of successfully delivering complex PKI projects in large scale enterprise environments. 5+ years of experience driving products from concept and ideation through successful launch. 5+ years of exper

Summary

Role:

Senior PKI Architect Design & Implementation Specialist

Duration:

12+ Months (High possibilities of extension)

Experience

  • 10+ years of hands-on experience with Microsoft Active Directory Certificate Services (AD CS) -OR Equivalent platform, including design, deployment, and troubleshooting of Certificate Authorities (CAs), Online Responders (OCSP), and Network Device Enrollment Service (NDES).
  • 3+ years of expertise in certificate lifecycle management (CLM) platforms (e.g., Venafi, AppViewX, Keyfactor) and Hardware Security Modules (HSMs) (e.g., Thales, nCipher, Utimaco).
  • 5+ years of proven track record of successfully delivering complex PKI projects in largescale enterprise environments.
  • 5+ years of experience driving products from concept and ideation through successful launch.
  • 5+ years of experience working on a team employing standardized project delivery methods (Agile/Scrum development methods preferred).
  • 5+ years of experience in understanding of and working with non-functional requirements.
  • 5+ years of experience of working in an enterprise environment.

Certifications (Preferred)

  • CISSP
  • SANS GIAC (e.g., GSEC, GCWN)
  • Microsoft Certified: Azure Security Engineer Associate

Education

Bachelor's or master's degree.

Position Purpose / Scope

This role leads the architecture, design, implementation, and management of enterprise-level Public Key Infrastructure (PKI) solutions. The position ensures high availability, scalability, and security across global BMW Group locations and drives strategic PKI initiatives, including adoption of emerging technologies and industry best practices.

Position Responsibilities/Accountabilities:

  • Architects and deploys Microsoft Active Directory Certificate Services (AD CS) components, including Certificate Authorities (CAs), Online Responders (OCSP), Certificate Revocation Lists (CRLs) and Network Device Enrollment Service (NDES)
  • Manages the full certificate lifecycle using advanced Certificate Lifecycle Management (CLM) platforms and Hardware Security Modules (HSMs).
  • Develops and implements automation scripts (PowerShell, Python) for PKI operations, certificate issuance, revocation, and monitoring.
  • Implements proof of concepts for PKI solutions.
  • Provides expert-level (Tier 3) support for complex PKI and Certificate Management incidents, performing root cause analysis and implementing permanent solutions.
  • Collaborates with cross-functional teams, including Product Owners, DevOps, and IT Security, to integrate PKI solutions into various applications and services.
  • Contributes to the overall security architecture, providing expert guidance on cryptographic standards, key management, and secure communication protocols.
  • Conducts comprehensive risk assessments for PKI deployments and develop mitigation strategies to ensure compliance with industry regulations and internal security policies.
  • Creates and maintains high-quality technical documentation, including design specifications, operational procedures, and test plans.
  • Conducts research on existing systems and devise solutions that work within those systems.
  • Responds to questions regarding PKI and Certificate Management capabilities and requirements.
  • Maintains a high-level understanding of the organization's IT-Security processes and requirements.
  • Works on the delivery of DevOps User Stories within specified functional area(s).
  • Supports the roll-out and operation of global Public Key Infrastructure (PKI) and Certificate Management initiatives within the BMW Group for multiple departments and all BMW global locations.
  • Understands and models VPS (Value Added Production System) Principles and concepts
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10203745
  • Position Id: 2025-2637/1942
  • Posted 10 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Charlotte, North Carolina

Today

Full-time

USD 75.00 - 85.00 per hour

Charlotte, North Carolina

Today

Contract

No location provided

Today

Full-time

USD 85,100.00 - 169,800.00 per year

No location provided

Today

Full-time

Search all similar jobs