30 Sep
|
Wipro APAC
|
Melbourne
30 Sep
Wipro APAC
Melbourne
SSPKI Certificate Lifecycle Management Engineer
Role Summary
The PKI Certificate Lifecycle Management (CLM) Engineer / Architect is responsible for
the design, implementation, enablement, and ongoing operation of enterprise PKI and
certificate lifecycle management solutions. This role will support a longterm, multiphase PKI
improvement initiative, focused on implementing and operationalising DigiCert One
(SaaS) to improve certificate governance, automation, and compliance across the
organisation.
The role will work closely with security, infrastructure, and application teams
throughout phases of the program, while also providing BAU and operational
support once the platform is live.
Key Responsibilities
Lead the enablement, configuration, and operation of PKI Certificate Lifecycle
Management (CLM) solutions in a SaaS environment
Design, build, and configure DigiCert One, including account setup, setting
creation, and tenant configuration
Implement and manage DigiCert One Trust Lifecycle Manager (TLM) for certificate
issuance, renewal, and revocation
Design, implement, and maintain enterprise Public Key Infrastructure
(PKI) and Certificate Lifecycle
Design, implement, and manage Hardware Security Module (HSM) solutions for
secure generation, storage, backup, recovery, and protection of cryptographic keys.
Integrate DigiCert One, PKI platforms, and certificate authorities with HSM
infrastructure to ensure compliance with enterprise security standards.
Manage HSM lifecycle activities, including provisioning, clustering, firmware updates,
key ceremonies, backup, escrow, and disaster recovery.
Ensure cryptographic keys used for certificate authorities, code signing, mutual TLS,
and other security services are protected using industry best practices.
Troubleshoot and resolve HSM-related incidents, performance issues, and
integration challenges.
Management (CLM) solutions
• Configure and administer PKI platforms to ensure secure certificate issuance, renewal,
revocation, and compliance
• Support the ongoing operation and availability of certificate management services across
the enterprise
• Develop and maintain PKI policies, standards, and procedures aligned to security and
compliance requirements
Public
• Work closely with application, infrastructure, and security teams to support certificatebased
authentication and encryption use cases
• Perform certificate lifecycle operations, including key management, certificate rotation, and
expiration management
• Monitor PKI systems for performance, availability, and security issues
• Troubleshoot and resolve certificaterelated incidents, outages, and configuration issues
• Maintain technical documentation, runbooks, and operational procedures for PKI services
• Ensure compliance with internal security standards and external regulatory requirements
related to cryptography and certificates
• Support audits, security reviews, and risk assessments relating to PKI and certificate usage
• Provide technical guidance and subjectmatter expertise on PKI best practices and industry
standards
Required Skills & Experience
Strong expertise in Public Key Infrastructure (PKI) and Certificate Lifecycle
Management (CLM) concepts and operations
Handson experience with DigiCert One, including Trust Lifecycle Manager (TLM)
Proven experience managing the full certificate lifecycle, including issuance, renewal,
revocation, and expiration management
Solid understanding of X.509 certificates, TLS/SSL, key pairs, and cryptographic
algorithms
Experience supporting enterprisescale PKI environments across hybrid (onprem and
cloud) infrastructures
Familiarity with certificate discovery, automation, and governance frameworks
Strong troubleshooting skills for certificaterelated issues impacting applications,
endpoints, and infrastructure
Experience working with Windows and Linux operating systems in secure
environments
Understanding of security controls, encryption standards, and compliance
requirements related to PKI
Strong hands-on experience with Hardware Security Modules (HSMs) and enterprise
key management solutions.
Proven experience implementing and managing HSM-backed PKI environments for
Root CA, Intermediate CA,
and certificate lifecycle management platforms.
Knowledge of HSM concepts including key generation, secure key storage, key
backup/recovery, partition management, and cryptographic operations.
Experience integrating PKI platforms such as DigiCert One, Microsoft ADCS, Entrust,
or similar solutions with HSM technologies.
Public
Understanding of cryptographic standards, key protection requirements, and
compliance frameworks governing HSM usage.
Experience supporting operational and troubleshooting activities related to enterprise
HSM infrastructure.
Education & Certifications
• Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a
related field (or equivalent practical experience)
• Preferred certifications:
DigiCert Certified Skilled (or equivalent PKI certification)
Microsoft, AWS, or Azure security certifications with PKI focus
CompTIA Security+ or equivalent cybersecurity certification
CISSP, CISM, or CCSP is a plus
Preferred Skills
Experience with certificate automation tools, APIs, and scripting (e.g., PowerShell,
Python, REST APIs)
Knowledge of cryptographic standards and regulations (e.g., NIST, ISO, CIS
benchmarks)
Experience supporting certificatebased authentication for applications, devices, and
services
Exposure to vulnerability management, encryption compliance, or zerotrust initiatives
Ability to work effectively with application, infrastructure, and security teams in large
enterprises
Experience with enterprise HSM platforms such as Thales Luna HSM, Entrust
nShield, Utimaco, AWS CloudHSM, Azure Managed HSM, or similar technologies.
Experience conducting CA key ceremonies, secure key migration, and PKI disaster
recovery activities involving HSM-protected keys.
Familiarity with FIPS 140-2/140-3 validated cryptographic modules and regulatory
requirements for key protection.
What We Offer
• Competitive salary and comprehensive benefits package
• Longterm engagement on a strategic enterprise security initiative
• Opportunities for professional development, training, and certification sponsorship
Public
• Exposure to enterprisescale PKI and security transformation programs
• A collaborative and flexible work environment focused on innovation and security
📌 End Point Security- PKI (Melbourne)
🏢 Wipro APAC
📍 Melbourne