Quick Overview
Job Description
The ideal candidate has hands-on experience with a CLM/PKI platform (such as Venafi, Keyfactor, or AppViewX), a solid understanding of public key infrastructure fundamentals, and enough core networking background (Cisco, load balancers, firewalls, DNS) to integrate certificate automation directly into enterprise network infrastructure. Financial services or other regulated-industry experience is strongly preferred given the compliance and audit demands of a banking environment.
Key Responsibilities
Administer and support the enterprise Certificate Lifecycle Management (CLM) platform, including certificate issuance, renewal, rotation, and revocation workflows.
Maintain and monitor the health of the bank's PKI environment, including root/intermediate CAs, certificate templates, and trust chains.
Automate certificate discovery, expiration alerting, and renewal to reduce manual touchpoints and prevent unplanned outages caused by expired certificates.
Integrate certificate lifecycle automation with network and infrastructure devices, including load balancers, firewalls, web servers, and Cisco networking equipment.
Partner with network, security, infrastructure, and application teams to onboard new systems into the CLM platform and troubleshoot certificate-related connectivity or trust issues.
Support HSM (Hardware Security Module) operations related to key storage and certificate signing, where applicable.
Develop and maintain runbooks, standard operating procedures, and audit documentation to support internal controls and regulatory/compliance reviews.
Participate in incident response and root cause analysis for certificate- or PKI-related outages and security events.
Evaluate and recommend improvements to certificate governance, key management practices, and automation coverage across the environment.
Required Qualifications
Hands-on experience administering a CLM/PKI platform such as Venafi, Keyfactor (EJBCA), AppViewX, DigiCert CertCentral, or Sectigo.
Working knowledge of PKI fundamentals: certificate authorities, certificate chains, key pairs, CSR generation, and revocation (CRL/OCSP).
Core networking experience: TCP/IP, DNS, load balancers, firewalls, and enterprise network architecture (Cisco environments preferred).
Understanding of TLS/SSL protocols and how certificate issues manifest as application or connectivity failures.
Scripting/automation experience (PowerShell, Python, or similar) for certificate lifecycle automation and reporting.
Experience working in a regulated environment (banking/financial services strongly preferred) with awareness of audit and compliance requirements (e.g., PCI-DSS, SOX, FFIEC).
Strong documentation habits and ability to communicate clearly with cross-functional network, security, and application teams.
Preferred Qualifications
Experience with Hardware Security Modules (HSM), such as Thales Luna or similar.
Exposure to cloud-native certificate management (Azure Key Vault, AWS Certificate Manager).
Familiarity with ServiceNow or similar ITSM tooling for change and incident management.
Relevant certifications (Security+, Venafi/Keyfactor platform certifications, or CISSP) a plus
Similar jobs
- IN
Senior MERN Stack Engineer
NewINGENworks
United States🇺🇸HybridYesterdayEngineering - GE
Quality Engineer - Hybrid
NewGenesis10
Redmond, WA🇺🇸$62 - $72/hrHybridYesterdayEngineering - ST
Forward Deployed Engineer (FDE) - Gemini Customer Experience (Gemini CX/Conversational AI)
NewSoftPath Technologies LLC
Sunnyvale, CA🇺🇸HybridYesterdayStakeholder ManagementEngineering - AL
DevSecOps Engineer with Security Clearance
NewALKU
Gaithersburg, MD🇺🇸HybridYesterdayEngineering - SO
Senior Kafka Engineer
NewSolugenix Corporation
Irvine, CA🇺🇸$80 - $85/hrHybridYesterdayEngineering - ZC
Quality Engineer (Aerospace/Aviation)
NewZtek Consulting
Rutland, VT🇺🇸HybridYesterdayGD&TEngineering