Role: Public Key Infrastructure
Location: Melbourne
:
Required Skills & Experience
- Solid expertise in Public Key Infrastructure (PKI) and Certificate Lifecycle Management (CLM) concepts and operations
- Hands‑on experience with DigiCert One, including Trust Lifecycle Manager (TLM)
- Proven experience managing the full certificate lifecycle, including issuance, renewal, revocation, and expiration management
- Solid understanding of X.509 certificates, TLS/SSL, key pairs, and cryptographic algorithms
- Experience supporting enterprise‑scale PKI environments across hybrid (on‑prem and cloud) infrastructures
- Familiarity with certificate discovery, automation, and governance frameworks
- Strong troubleshooting skills for certificate‑related issues impacting applications, endpoints, and infrastructure
- Experience working with Windows and Linux operating systems in secure environments
- Understanding of security controls, encryption standards, and compliance requirements related to PKI
- Strong hands-on experience with Hardware Security Modules (HSMs) and enterprise key management solutions.
- Proven experience implementing and managing HSM-backed PKI environments for Root CA, Intermediate CA, and certificate lifecycle management platforms.
- Knowledge of HSM concepts including key generation, secure key storage, key backup/recovery, partition management, and cryptographic operations.
- Experience integrating PKI platforms such as DigiCert One, Microsoft ADCS, Entrust, or similar solutions with HSM technologies.
- Understanding of cryptographic standards, key protection requirements, and compliance frameworks governing HSM usage.
- Experience supporting operational and troubleshooting activities related to enterprise HSM infrastructure.
Preferred Skills
- Experience with certificate automation tools, APIs, and scripting (e.g., PowerShell, Python, REST APIs)
- Knowledge of cryptographic standards and regulations (e.g., NIST, ISO, CIS benchmarks)
- Experience supporting certificate‑based authentication for applications, devices, and services
- Exposure to vulnerability management, encryption compliance, or zero‑trust initiatives
- Ability to work effectively with application, infrastructure, and security teams in large enterprises
- Experience with enterprise HSM platforms such as Thales Luna HSM, Entrust nShield, Utimaco, AWS CloudHSM, Azure Managed HSM, or similar technologies.
- Experience conducting CA key ceremonies, secure key migration, and PKI disaster recovery activities involving HSM-protected keys.
- Familiarity with FIPS 140-2/140-3 validated cryptographic modules and regulatory requirements for key protection.
Interested Candidates can share their updated resumes on
[email protected] or can reach me on +61283195549
📌 Public Key Infrastructure (Melbourne)
🏢 CareCone Group
📍 Melbourne