Job Summary
We are seeking a highly skilled Senior PKI & Venafi Engineer to support and enhance enterprise Certificate Lifecycle Management (CLM) and Public Key Infrastructure (PKI) capabilities.
The candidate will be responsible for application onboarding, certificate lifecycle automation, PKI operations, certificate governance, platform resiliency, and technical consultation across hybrid and cloud environments.
The successful candidate will serve as a subject matter expert in enterprise certificates, PKI architecture, Venafi Trust Protection Platform, certificate automation patterns, and operational support. The engineer will collaborate with application, infrastructure, cloud, and security teams to ensure certificates are securely deployed, monitored, renewed, and governed throughout their lifecycle.
Key Responsibilities
1. Certificate Lifecycle Management (CLM)
- Administer and support enterprise Certificate Lifecycle Management services.
- Manage the complete certificate lifecycle, including discovery, request, issuance, renewal, revocation, deployment, monitoring, and retirement.
- Ensure certificates comply with enterprise standards and industry requirements.
- Maintain certificate inventory, visibility, ownership, and accountability records.
- Identify and remediate expiring, unmanaged, self-signed, and non-compliant certificates.
2. Venafi Platform Administration
- Administer, configure, and maintain the Venafi platform and supporting infrastructure.
- Configure and manage policies, workflows, certificate authorities, integrations, discovery jobs, notifications, reporting, and access controls.
- Support platform upgrades, maintenance, and technology refresh initiatives.
- Collaborate with Venafi support teams and vendors to troubleshoot technical issues and implement platform enhancements.
3. Application Onboarding and Solution Engineering
- Lead application onboarding into the Certificate Lifecycle Management platform.
- Assess application certificate requirements and define appropriate onboarding approaches.
- Design automation patterns based on application architecture and operational requirements.
- Partner with application teams to understand deployment architectures, certificate formats, trust requirements, and operational processes.
- Support onboarding across the following environments and technologies:
- Windows and Linux
- Azure and cloud-native platforms
- Kubernetes
- WebLogic and IIS
- F5
- Kafka and Solace
- Ping
- Provide technical consultation and solution recommendations to application teams.
4. Certificate Lifecycle Automation
- Design, implement, and support certificate lifecycle automation solutions.
- Develop automation patterns using:
- Venafi Native Drivers
- Venafi APIs
- vCert utilities
- CI/CD pipelines
- GitHub Actions
- Azure DevOps
- PowerShell
- Python
- Ansible
- Automate certificate renewal, provisioning, deployment validation, and application restart activities.
- Reduce manual certificate deployment processes and associated operational risks.
- Create reusable automation patterns and onboarding frameworks for enterprise-wide adoption.
5. PKI Operations and Resiliency
- Support internal PKI infrastructure and certificate authority services.
- Participate in certificate authority operations, CRL publication, backup and recovery testing, and disaster recovery exercises.
- Support platform resiliency and availability improvements.
- Monitor certificate ecosystem health and service availability.
- Assist with root and intermediate certificate management.
- Participate in major incident response and technical troubleshooting.
6. Security and Governance
- Support certificate governance and compliance initiatives.
- Maintain certificate ownership, metadata, and accountability records.
- Ensure adherence to enterprise security standards covering:
- TLS/SSL
- Certificate issuance
- Cryptographic key management
- Certificate authority controls
- Help maintain secure and compliant certificate management practices across enterprise environments.
Essential Technical Skills
- Venafi: Venafi Trust Protection Platform administration, configuration, policies, workflows, discovery, and integrations.
- PKI: Public Key Infrastructure operations, certificate authorities, root and intermediate certificates, and CRL publication.
- Certificate Lifecycle Management: Certificate discovery, issuance, renewal, revocation, deployment, monitoring, and retirement.
- Automation: Venafi APIs, Native Drivers, vCert utilities, Python, PowerShell, and Ansible.
- DevOps Integration: CI/CD pipelines, GitHub Actions, and Azure DevOps.
- Application Onboarding: Certificate integration across Windows, Linux, Azure, Kubernetes, WebLogic, IIS, F5, Kafka, Solace, and Ping.
- Security and Governance: TLS/SSL, cryptographic key management, certificate compliance, ownership, and accountability.
- Operational Resiliency: Troubleshooting, incident response, backup and recovery, disaster recovery, and platform availability.