Position: PKI Venafi Architect
Position Type: Fulltime
Location: Chicago, IL Hybrid, 3 days per week in office
Desired Skills: Cyber Security | Information Security
Salary Range: $115,000-$140,000 a year
Experience: 8 - 14 years of experience
Job Description:
PKI Venafi Architect
PKI & Security Architecture
Design and maintain enterprise PKI architecture, including Root CA, Issuing CA, CRL, OCSP, HSM, and trust frameworks.
Develop certificate governance standards, policies, and cryptographic control frameworks.
Architect highly available and resilient PKI and CLM platforms.
Drive enterprise machine identity and certificate management strategy.
Venafi Platform Architecture
Must Have Technical/Functional Skills
PKI & Security Architecture
Design and maintain enterprise PKI architecture, including Root CA, Issuing CA, CRL, OCSP, HSM, and trust frameworks.
Develop certificate governance standards, policies, and cryptographic control frameworks.
Architect highly available and resilient PKI and CLM platforms.
Drive enterprise machine identity and certificate management strategy.
Venafi Platform Architecture
Design and administer Venafi Trust Protection Platform (TPP).
Define onboarding standards, workflows, policies, reporting, discovery jobs, and access models.
Architect integrations between Venafi and enterprise applications, cloud services, and security platforms.
Lead Venafi platform upgrades, enhancements, and optimization initiatives.
Roles & Responsibilities
Certificate Lifecycle Automation
o Venafi APIs
o vCert
o PowerShell
o Python
o Ansible
o GitHub Actions
o Azure DevOps o CI/CD pipelines
Drive adoption of certificate automation across enterprise application portfolios. Application & Cloud Integration
Lead application onboarding into CLM services.
Support certificate deployment and automation across:
o Windows Server
o Linux/Unix
o IIS
o Apache o Tomcat o WebLogic
o Kubernetes
o Azure
o AWS
o F5 Load Balancers
o Kafka
o Solace
o PingFederate
Governance & Compliance
Ensure compliance with NIST, PCI-DSS, SOX, ISO 27001, FedRAMP, and enterprise security standards.
Conduct cryptographic risk assessments and certificate posture reviews.
Define certificate ownership models and governance processes.
Support audits and regulatory compliance activities
Required Qualifications
Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related discipline.
10+ years of Information Security experience.
5+ years of hands-on PKI architecture experience.
5+ years of Venafi Trust Protection Platform experience.
Strong expertise in:
o X.509 Certificates
o TLS/SSL
o PKI
o CLM o CRL/OCSP
o HSM Technologies
o Digital Signatures
o Cryptographic Key Management
Preferred Qualifications
CISSP, CISM, CCSP, or equivalent certification.
Venafi Certified Professional/Architect certification.
Experience with:
o Keyfactor
o DigiCert
o Entrust
o Microsoft ADCS
o HashiCorp Vault
o Azure Key Vault
o AWS Certificate Manager
Technical Skills PKI & Cryptography
PKI Architecture
X.509 Certificates
TLS/SSL
PKCS Standards
Digital Signatures
HSM Integration
CRL / OCSP Venafi
Venafi TPP
Venafi TLS Protect
Certificate Discovery
Policy Management
Workflow Automation
Reporting & Governance Cloud & DevOps
Azure
AWS
Kubernetes
GitHub Actions
Azure DevOps
CI/CD Pipelines
Infrastructure as Code Programming & Automation
PowerShell Python
REST APIs
Ansible Leadership Expectations
Serve as the PKI and Machine Identity SME.
Provide technical leadership to engineering and operations teams.
Develop enterprise PKI roadmaps and modernization strategies.
Mentor engineers and establish best practices for certificate lifecycle management.
Drive Zero Trust and identity-centric security initiatives.