25 Sep
|
Wipro
|
Victoria
Job Description
n
The PKI Certificate Lifecycle Management (CLM) Engineer / Architect is responsible for the design, implementation, enablement, and ongoing operation of enterprise PKI and certificate lifecycle management solutions. This role will support a long‑term, multi‑phase PKI improvement initiative, focused on implementing and operationalising DigiCert One (SaaS) to improve certificate governance, automation, and compliance across the organisation.
n
The role will work closely with security, infrastructure, and application teams throughout phases of the program, while also providing BAU and operational support once the platform is live.
Key Responsibilities n
n
- Lead the enablement, configuration, and operation of PKI Certificate Lifecycle Management (CLM) solutions in a SaaS environment
n
- Design, build, and configure DigiCert One , including account setup, environment creation, and tenant configuration
n
- Implement and manage DigiCert One Trust Lifecycle Manager (TLM) for certificate issuance, renewal, and revocation
n
- Design, implement, and maintain enterprise Public Key Infrastructure (PKI) and Certificate Lifecycle
n
- Design, implement, and manage Hardware Security Module (HSM) solutions for secure generation, storage, backup, recovery, and protection of cryptographic keys.
n
- Integrate DigiCert One, PKI platforms, and certificate authorities with HSM infrastructure to ensure compliance with enterprise security standards.
n
- Manage HSM lifecycle activities, including provisioning, clustering, firmware updates, key ceremonies, backup, escrow, and disaster recovery.
n
- Ensure cryptographic keys used for certificate authorities, code signing, mutual TLS, and other security services are protected using industry best practices.
n
- Troubleshoot and resolve HSM-related incidents, performance issues, and integration challenges.
n
Management (CLM) solutions nn
- Configure and administer PKI platforms to ensure secure certificate issuance, renewal, revocation, and compliance
n
- Support the ongoing operation and availability of certificate management services across the enterprise
n
- Develop and maintain PKI policies, standards,
and procedures aligned to security and compliance requirements
n
- Work closely with application, infrastructure, and security teams to support certificate‑based authentication and encryption use cases
n
- Perform certificate lifecycle operations, including key management, certificate rotation, and expiration management
n
- Monitor PKI systems for performance, availability, and security issues
n
- Troubleshoot and resolve certificate‑related incidents, outages, and configuration issues
n
- Maintain technical documentation, runbooks, and operational procedures for PKI services
n
- Ensure compliance with internal security standards and external regulatory requirements related to cryptography and certificates
n
- Support audits, security reviews, and risk assessments relating to PKI and certificate usage
n
- Provide technical guidance and subject‑matter expertise on PKI best practices and industry standards
n
Required Skills & Experience nn
- Strong expertise in Public Key Infrastructure (PKI) and Certificate Lifecycle Management (CLM) concepts and operations
n
- Hands‑on experience with DigiCert One, including Trust Lifecycle Manager (TLM)
n
- Proven experience managing the full certificate lifecycle, including issuance, renewal, revocation, and expiration management
n
- Solid understanding of X.509 certificates, TLS/SSL, key pairs, and cryptographic algorithms
n
- Experience supporting enterprise‑scale PKI environments across hybrid (on‑prem and cloud) infrastructures
n
- Familiarity with certificate discovery, automation, and governance frameworks
n
- Strong troubleshooting skills for certificate‑related issues impacting applications, endpoints, and infrastructure
n
- Experience working with Windows and Linux operating systems in secure environments
n
- Understanding of security controls, encryption standards, and compliance requirements related to PKI
n
- Solid hands‑on experience with Hardware Security Modules (HSMs) and enterprise key management solutions.
n
- Proven experience implementing and managing HSM-backed PKI environments for Root CA, Intermediate CA, and certificate lifecycle management platforms.
n
- Knowledge of HSM concepts including key generation, secure key storage, key backup/recovery, partition management, and cryptographic operations.
n
- Experience integrating PKI platforms such as DigiCert One, Microsoft ADCS, Entrust, or similar solutions with HSM technologies.
n
- Understanding of cryptographic standards, key protection requirements, and compliance frameworks governing HSM usage.
n
- Experience supporting operational and troubleshooting activities related to enterprise HSM infrastructure.
n
Education & Certifications nn
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent practical experience)
n
nn
- DigiCert Certified Professional (or equivalent PKI certification)
n
- Microsoft, AWS, or Azure security certifications with PKI focus
n
- CompTIA Security+ or equivalent cybersecurity certification
n
- CISSP, CISM, or CCSP is a plus
n
Preferred Skills nn
- Experience with certificate automation tools, APIs, and scripting (e.g., PowerShell, Python, REST APIs)
n
- Knowledge of cryptographic standards and regulations (e.g., NIST, ISO, CIS benchmarks)
n
- Experience supporting certificate‑based authentication for applications, devices, and services
n
- Exposure to vulnerability management, encryption compliance, or zero‑trust initiatives
n
- Ability to work effectively with application, infrastructure, and security teams in large enterprises
n
- Experience with enterprise HSM platforms such as Thales Luna HSM, Entrust nShield, Utimaco, AWS CloudHSM, Azure Managed HSM, or similar technologies.
n
- Experience conducting CA key ceremonies, secure key migration, and PKI disaster recovery activities involving HSM‑protected keys.
n
- Familiarity with FIPS 140-2/140-3 validated cryptographic modules and regulatory requirements for key protection.
n
n
#J-18808-Ljbffr
📌 PKI Certificate Lifecycle Management Engineer (Victoria)
🏢 Wipro
📍 Victoria