Overview
The PKI & Certificate Lifecycle Engineer will administer and support PKI services, assist with certificate-related issues, collaborate with technology teams, develop automation, and follow PKI governance and security standards.
What you'll do
- Administer and support DigiCert TLM and related PKI services, including certificate requests, issuance, renewal, revocation, inventory management, monitoring, and certificate retirement.
- Assist users and technology teams with public TLS, private TLS, S/MIME, code-signing, VPN/Wi-Fi, endpoint, server, application, and other machine identity certificates.
- Troubleshoot certificate lifecycle, trust, and deployment issues.
- Partner with network, application, cloud, endpoint, and infrastructure teams to gather requirements, coordinate certificate onboarding, support integrations, and resolve service issues.
- Develop scripts, reports, and workflows to improve certificate inventory, monitoring, renewal, notification, and operational efficiency.
- Contribute to service enhancements and broader PKI capabilities.
- Follow PKI governance and security standards.
- Maintain operational documentation.
- Support incident and problem management.
- Escalate risks and issues appropriately.
What you'll need
- 3+ years of experience in PKI, certificate management, cybersecurity, infrastructure engineering, or a related technical field.
- Practical understanding of X.509 certificates, certificate authorities, certificate chains, public/private keys, and SSL/TLS.
- Experience with an enterprise PKI, managed PKI, or certificate lifecycle management platform.
- Ability to troubleshoot certificate enrollment, renewal, trust, installation, and configuration issues.
- Basic scripting or automation experience using Python, PowerShell, Bash, or a similar technology.
- Familiarity with Windows and/or Linux environments, REST APIs, and enterprise networking concepts.
- Strong analytical, documentation, communication, and stakeholder management skills.
- Ability to work independently and collaborate with distributed global technology teams.
- Strong written and spoken English communication skills.
- Bachelor's degree in computer science, Information Technology, Cybersecurity, Engineering, or a related technical discipline.
Nice to have
- Experience with DigiCert TLM, DigiCert ONE, Venafi, Keyfactor, Microsoft AD CS, or similar PKI platforms.
- Exposure to certificate automation technologies such as ACME, SCEP, or EST.
- Familiarity with OpenSSL, cloud certificate management, Azure Key Vault, or AWS Certificate Manager.
- Experience supporting S/MIME, code signing, VPN/Wi-Fi, public/private TLS, or machine identity certificates.
- Familiarity with Microsoft Intune, Active Directory, Entra ID (Azure AD), and enterprise device certificate deployment.
- Exposure to DevOps methodologies and automation practices with certificate lifecycle automation.
- Exposure to CI/CD platforms such as Azure DevOps, GitHub Actions, GitLab CI/CD, or Jenkins.
Details
- Location: INMANBP Bangalore (INMANBP) Manyatha.
Read the full description and apply on the company’s own careers page.