01 Oct
|
ITbility
|
Melbourne
01 Oct
ITbility
Melbourne
Job Description
n
PKI Certificate Lifecycle Management Engineer
n
Melbourne
n
Contract 6+ Months / Permanent
n
n
Our client in
Melbourne
is looking for PKI Certificate Lifecycle Management Engineerthis is a
contract 6+ months or Permanent
role.
n
n
Lead the enablement, configuration, and operation of PKI Certificate Lifecycle Management (CLM) solutions in a SaaS environment
n
Design, build, and configure DigiCert One, including account setup, environment creation, and tenant configuration
n
Implement and manage DigiCert One Trust Lifecycle Manager (TLM) for certificate issuance, renewal, and revocation
n
Design, implement, and maintain enterprise Public Key Infrastructure (PKI) and Certificate Lifecycle
n
Design, implement, and manage Hardware Security Module (HSM) solutions for secure generation, storage, backup, recovery, and protection of cryptographic keys.
n
Integrate DigiCert One, PKI platforms, and certificate authorities with HSM infrastructure to ensure compliance with enterprise security standards.
n
Configure and administer PKI platforms to ensure secure certificate issuance, renewal, revocation, and compliance
n
Support the ongoing operation and availability of certificate management services across the enterprise
n
Develop and maintain PKI policies, standards, and procedures aligned to security and compliance requirements
n
Work closely with application, infrastructure, and security teams to support certificate-based authentication and encryption use cases
n
Perform certificate lifecycle operations, including key management, certificate rotation, and expiration management
n
Monitor PKI systems for performance, availability, and security issues
n
Troubleshoot and resolve certificate-related incidents, outages, and configuration issues
n
Maintain technical documentation, runbooks, and operational procedures for PKI services
n
Ensure compliance with internal security standards and external regulatory requirements related to cryptography and certificates
n
Support audits, security reviews, and risk assessments relating to PKI and certificate usage
n
Provide technical guidance and subject-matter expertise on PKI best practices and industry standards
n
Required Skills & Experience n
n
Strong expertise in Public Key Infrastructure (PKI) and Certificate Lifecycle Management (CLM) concepts and operations
n
Hands-on experience with DigiCert One, including Trust Lifecycle Manager (TLM)
n
Proven experience managing the full certificate lifecycle, including issuance, renewal, revocation, and expiration management
n
Solid understanding of X.509 certificates, TLS/SSL, key pairs, and cryptographic algorithms
n
Experience supporting enterprise-scale PKI environments across hybrid (on-prem and cloud) infrastructures
n
Familiarity with certificate discovery, automation, and governance frameworks
n
Strong troubleshooting skills for certificate-related issues impacting applications, endpoints, and infrastructure
n
Experience working with Windows and Linux operating systems in secure environments
n
Understanding of security controls, encryption standards, and compliance requirements related to PKI
n
Solid hands-on experience with Hardware Security Modules (HSMs) and enterprise key management solutions.
n
Proven experience implementing and managing HSM-backed PKI environments for Root CA, Intermediate CA, and certificate lifecycle management platforms.
n
Knowledge of HSM concepts including key generation, secure key storage,
key backup/recovery, partition management, and cryptographic operations.
n
Experience integrating PKI platforms such as DigiCert One, Microsoft ADCS, Entrust, or similar solutions with HSM technologies.
n
Understanding of cryptographic standards, key protection requirements, and compliance frameworks governing HSM usage.
n
Experience supporting operational and troubleshooting activities related to enterprise HSM infrastructure.
n
Education & Certifications n
n
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent practical experience)
n
DigiCert Certified Professional (or equivalent PKI certification)
n
Microsoft, AWS, or Azure security certifications with PKI focus
n
CompTIA Security+ or equivalent cybersecurity certification
n
CISSP, CISM, or CCSP is a plus
n
Preferred Skills n
n
Experience with certificate automation tools, APIs, and scripting (e.g., PowerShell, Python, REST APIs)
n
Knowledge of cryptographic standards and regulations (e.g., NIST, ISO, CIS benchmarks)
n
Experience supporting certificate-based authentication for applications, devices, and services
n
Exposure to vulnerability management, encryption compliance, or zero‐trust initiatives
n
Ability to work effectively with application, infrastructure, and security teams in large enterprises
n
Experience with enterprise HSM platforms such as Thales Luna HSM, Entrust nShield, Utimaco, AWS CloudHSM, Azure Managed HSM, or similar technologies.
n
Experience conducting CA key ceremonies, secure key migration, and PKI disaster recovery activities involving HSM‐protected keys.
n
Familiarity with FIPS *********** validated cryptographic modules and regulatory requirements for key protection.
n
n
Only shortlisted candidates will be contacted for this role.
#J-*****-Ljbffr
📌 Pki Certificate Lifecycle Management Engineer (Melbourne)
🏢 ITbility
📍 Melbourne