- PKI Certificate Lifecycle Management Engineer
- Melbourne
- Contract 6+ Months / Permanent
Our client in Melbourne is looking for PKI Certificate Lifecycle Management Engineer this is a contract 6+ months or Permanent role. Please email me at
[email protected] for more information.
:
· Lead the enablement, configuration, and operation of PKI Certificate Lifecycle Management (CLM) solutions in a SaaS environment
· Design, build, and configure DigiCert One, including account setup, workplace creation, and tenant configuration
· Implement and manage DigiCert One Trust Lifecycle Manager (TLM) for certificate issuance, renewal, and revocation
· Design, implement, and maintain enterprise Public Key Infrastructure (PKI) and Certificate Lifecycle
· Design, implement, and manage Hardware Security Module (HSM) solutions for secure generation, storage, backup, recovery, and protection of cryptographic keys.
· Integrate DigiCert One, PKI platforms, and certificate authorities with HSM infrastructure to ensure compliance with enterprise security standards.
- Configure and administer PKI platforms to ensure secure certificate issuance, renewal, revocation, and compliance
- Support the ongoing operation and availability of certificate management services across the enterprise
- Develop and maintain PKI policies, standards, and procedures aligned to security and compliance requirements
- Work closely with application, infrastructure, and security teams to support certificate-based authentication and encryption use cases
- Perform certificate lifecycle operations, including key management, certificate rotation, and expiration management
- Monitor PKI systems for performance, availability, and security issues
- Troubleshoot and resolve certificate-related incidents, outages, and configuration issues
- Maintain technical documentation, runbooks, and operational procedures for PKI services
- Ensure compliance with internal security standards and external regulatory requirements related to cryptography and certificates
- Support audits, security reviews, and risk assessments relating to PKI and certificate usage
- Provide technical guidance and subject-matter expertise on PKI best practices and industry standards
Required Skills & Experience
· Strong expertise in Public Key Infrastructure (PKI) and Certificate Lifecycle Management (CLM) concepts and operations
· Hands-on experience with DigiCert One, including Trust Lifecycle Manager (TLM)
· Proven experience managing the full certificate lifecycle, including issuance, renewal, revocation, and expiration management
· Solid understanding of X.509 certificates, TLS/SSL, key pairs, and cryptographic algorithms
· Experience supporting enterprise-scale PKI environments across hybrid (on-prem and cloud) infrastructures
· Familiarity with certificate discovery, automation, and governance frameworks
· Strong troubleshooting skills for certificate-related issues impacting applications, endpoints, and infrastructure
· Experience working with Windows and Linux operating systems in secure environments
· Understanding of security controls, encryption standards, and compliance requirements related to PKI
· Strong hands-on experience with Hardware Security Modules (HSMs) and enterprise key management solutions.
· Proven experience implementing and managing HSM-backed PKI environments for Root CA, Intermediate CA, and certificate lifecycle management platforms.
· Knowledge of HSM concepts including key generation, secure key storage, key backup/recovery, partition management,
and cryptographic operations.
· Experience integrating PKI platforms such as DigiCert One, Microsoft ADCS, Entrust, or similar solutions with HSM technologies.
· Understanding of cryptographic standards, key protection requirements, and compliance frameworks governing HSM usage.
· Experience supporting operational and troubleshooting activities related to enterprise HSM infrastructure.
Education & Certifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent practical experience)
- Preferred certifications:
· DigiCert Certified Professional (or equivalent PKI certification)
· Microsoft, AWS, or Azure security certifications with PKI focus
· CompTIA Security+ or equivalent cybersecurity certification
· CISSP, CISM, or CCSP is a plus
Preferred Skills
· Experience with certificate automation tools, APIs, and scripting (e.g., PowerShell, Python, REST APIs)
· Knowledge of cryptographic standards and regulations (e.g., NIST, ISO, CIS benchmarks)
· Experience supporting certificate-based authentication for applications, devices, and services
· Exposure to vulnerability management, encryption compliance, or zero-trust initiatives
· Ability to work effectively with application, infrastructure, and security teams in large enterprises
· Experience with enterprise HSM platforms such as Thales Luna HSM, Entrust nShield, Utimaco, AWS CloudHSM, Azure Managed HSM, or similar technologies.
· Experience conducting CA key ceremonies, secure key migration, and PKI disaster recovery activities involving HSM-protected keys.
- · Familiarity with FIPS 140-2/140-3 validated cryptographic modules and regulatory requirements for key protection.
Only shortlisted candidates will be contacted for this role. To apply, please submit your resume ASAP for immediate consideration or email
[email protected]
📌 PKI Certificate Lifecycle Management Engineer (Melbourne)
🏢 ITbility
📍 Melbourne