26 Sep
|
Whizdom
|
Melbourne
PKI Certificate Lifecycle Management Engineer
- Location: Melbourne
- Contract: Initial 6-month contract with potential extension
- Start: ASAP
We are seeking an experienced PKI Certificate Lifecycle Management Engineer to support the design, implementation and ongoing operation of enterprise PKI and certificate lifecycle management solutions. This hands-on role will support the implementation and operationalisation of DigiCert One , helping improve certificate governance, automation and compliance across a complex enterprise environment.
Key Responsibilities
- Lead the configuration and operation of PKI Certificate Lifecycle Management solutions
- Design, build and configure DigiCert One environments and tenants
- Implement and manage DigiCert One Trust Lifecycle Manager
- Manage certificate issuance, renewal, revocation, rotation and expiration
- Design and maintain enterprise PKI and certificate lifecycle solutions
- Implement and manage Hardware Security Module solutions
- Integrate DigiCert One, certificate authorities and PKI platforms with HSM infrastructure
- Manage HSM provisioning, clustering, firmware updates, key ceremonies, backups and disaster recovery
- Protect cryptographic keys used for certificate authorities, code signing and mutual TLS
- Troubleshoot HSM incidents, performance issues and integration challenges
- Develop and maintain PKI policies, standards, procedures and operational documentation
- Monitor PKI systems for performance, availability and security issues
- Resolve certificate-related incidents, outages and configuration problems
- Support security audits, risk assessments and compliance reviews
- Work closely with application, infrastructure and security teams
- Provide technical guidance on PKI standards and best practices
Skills and Experience
- Solid expertise in Public Key Infrastructure and Certificate Lifecycle Management
- Hands-on experience with DigiCert One and Trust Lifecycle Manager
- Experience managing the complete certificate lifecycle
- Strong understanding of X.509 certificates, TLS/SSL, key pairs and cryptographic algorithms
- Experience supporting enterprise PKI across hybrid cloud and on-premises environments
- Strong hands-on experience with Hardware Security Modules and enterprise key management
- Experience implementing HSM-backed Root CA and Intermediate CA environments
- Knowledge of secure key generation, storage, backup, recovery and partition management
- Experience integrating DigiCert One, Microsoft ADCS, Entrust or similar PKI platforms with HSM technologies
- Experience supporting Windows and Linux environments
- Strong troubleshooting skills across applications, endpoints and infrastructure
Highly Regarded
- Experience with Thales Luna HSM, Entrust nShield, Utimaco, AWS CloudHSM or Azure Managed HSM
- Experience conducting CA key ceremonies, secure key migrations and PKI disaster recovery
- Knowledge of FIPS 140-2 or FIPS 140-3 cryptographic modules
- Automation experience using PowerShell, Python or REST APIs
- Knowledge of NIST, ISO and CIS security standards
- Experience supporting zero-trust, encryption compliance or vulnerability management initiatives
- DigiCert, Microsoft, AWS, Azure, Security+, CISSP, CISM or CCSP certifications
Why Apply?
- Initial 6-month Melbourne contract with potential extension
- ASAP start
- Work with DigiCert One and enterprise PKI technologies
- Hands-on involvement with HSM-backed certificate environments
- Support a strategic enterprise security initiative
- Work across certificate governance, automation and compliance
If you are an experienced PKI Engineer with strong DigiCert One, certificate lifecycle management and HSM expertise, apply now with your updated resume.
📌 PKI Certificate Lifecycle Management Engineer (Melbourne)
🏢 Whizdom
📍 Melbourne