01 Oct
|
Whizdom
|
Melbourne
PKI Certificate Lifecycle Management Engineer
Location: Melbourne
Contract: Initial 6-month contract with potential extension
Start: ASAP
We are seeking an experienced PKI Certificate Lifecycle Management Engineer to support the design, implementation and ongoing operation of enterprise PKI and certificate lifecycle management solutions.
This hands-on role will support the implementation and operationalisation of DigiCert One, helping improve certificate governance, automation and compliance across a complex enterprise environment.
Key Responsibilities
Lead the configuration and operation of PKI Certificate Lifecycle Management solutions
Design, build and configure DigiCert One environments and tenants
Implement and manage DigiCert One Trust Lifecycle Manager
Manage certificate issuance, renewal, revocation, rotation and expiration
Design and maintain enterprise PKI and certificate lifecycle solutions
Implement and manage Hardware Security Module solutions
Integrate DigiCert One, certificate authorities and PKI platforms with HSM infrastructure
Manage HSM provisioning, clustering, firmware updates, key ceremonies, backups and disaster recovery
Protect cryptographic keys used for certificate authorities, code signing and mutual TLS
Troubleshoot HSM incidents, performance issues and integration challenges
Develop and maintain PKI policies, standards, procedures and operational documentation
Monitor PKI systems for performance, availability and security issues
Resolve certificate-related incidents, outages and configuration problems
Support security audits, risk assessments and compliance reviews
Work closely with application, infrastructure and security teams
Provide technical guidance on PKI standards and best practices
Skills and Experience
Robust expertise in Public Key Infrastructure and Certificate Lifecycle Management
Hands-on experience with DigiCert One and Trust Lifecycle Manager
Experience managing the complete certificate lifecycle
Strong understanding of X.509 certificates, TLS/SSL, key pairs and cryptographic algorithms
Experience supporting enterprise PKI across hybrid cloud and on-premises environments
Strong hands-on experience with Hardware Security Modules and enterprise key management
Experience implementing HSM-backed Root CA and Intermediate CA environments
Knowledge of secure key generation, storage, backup, recovery and partition management
Experience integrating DigiCert One, Microsoft ADCS, Entrust or similar PKI platforms with HSM technologies
Experience supporting Windows and Linux environments
Strong troubleshooting skills across applications, endpoints and infrastructure
Highly Regarded
Experience with Thales Luna HSM, Entrust nShield, Utimaco, AWS CloudHSM or Azure Managed HSM
Experience conducting CA key ceremonies, secure key migrations and PKI disaster recovery
Knowledge of FIPS ***** or FIPS ***** cryptographic modules
Automation experience using PowerShell, Python or REST APIs
Knowledge of NIST, ISO and CIS security standards
Experience supporting zero-trust, encryption compliance or vulnerability management initiatives
DigiCert, Microsoft, AWS, Azure, Security+, CISSP, CISM or CCSP certifications
Why Apply?
Initial 6-month Melbourne contract with potential extension
ASAP start
Work with DigiCert One and enterprise PKI technologies
Hands-on involvement with HSM-backed certificate environments
Support a strategic enterprise security initiative
Work across certificate governance, automation and compliance
#J-*****-Ljbffr
📌 Pki Certificate Lifecycle Management Engineer (Melbourne)
🏢 Whizdom
📍 Melbourne