Haystack
← Back to Jobs
Other
VT

PKI Venafi Architect

Vaarida Technologies llcChicago, IL🇺🇸United StatesPosted Sep 17, 2026

Why This Role Stands Out

This hybrid role offers a significant opportunity to shape enterprise PKI architecture and drive machine identity strategies with a reputable company. You'll thrive here if you possess strong Venafi platform and PKI expertise and are looking to grow your skills in a dynamic environment. Apply now to explore this exciting career advancement.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Chicago, IL, United States
Posted
3 days ago
AWSAnsibleApacheAzureComplianceGitHub ActionsKafkaKubernetesOnboardingPKIPowerShellPythonRegulatory ComplianceVault

Job Description

Job description Below

PKI & Security Architecture

  • Design and maintain enterprise PKI architecture, including Root CA, Issuing CA, CRL, OCSP, HSM, and trust frameworks.
  • Develop certificate governance standards, policies, and cryptographic control frameworks.
  • Architect highly available and resilient PKI and CLM platforms.
  • Drive enterprise machine identity and certificate management strategy.

Venafi Platform Architecture

  • Design and administer Venafi Trust Protection Platform (TPP).
  • Design and administer Venafi Trust Protection Platform (TPP).
  • Define onboarding standards, workflows, policies, reporting, discovery jobs, and access models.
  • Architect integrations between Venafi and enterprise applications, cloud services, and security platforms.
  • Lead Venafi platform upgrades, enhancements, and optimization initiatives.

Roles & Responsibilities

  • Certificate Lifecycle Automation
  • Architect automated certificate provisioning and renewal solutions.
  • Design automation frameworks using:
  • o Venafi APIs
  • o vCert
  • o PowerShell
  • o Python
  • o Ansible
  • o GitHub Actions
  • o Azure DevOps o CI/CD pipelines
  • Drive adoption of certificate automation across enterprise application portfolios. Application & Cloud Integration
  • Lead application onboarding into CLM services.
  • Support certificate deployment and automation across:
  • o Windows Server
  • o Linux/Unix
  • o IIS
  • o Apache o Tomcat o WebLogic
  • o Kubernetes
  • o Azure
  • o AWS
  • o F5 Load Balancers
  • o Kafka
  • o Solace
  • o PingFederate
  • Provide architecture guidance and troubleshooting support for complex trust and certificate-related issues.
  • Governance & Compliance
  • Ensure compliance with NIST, PCI-DSS, SOX, ISO 27001, FedRAMP, and enterprise security standards.
  • Conduct cryptographic risk assessments and certificate posture reviews.
  • Define certificate ownership models and governance processes.
  • Support audits and regulatory compliance activities
  • Required Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related discipline.
  • 10+ years of Information Security experience.
  • 5+ years of hands-on PKI architecture experience.
  • 5+ years of Venafi Trust Protection Platform experience.
  • Strong expertise in:
  • o X.509 Certificates
  • o TLS/SSL
  • o PKI
  • o CLM o CRL/OCSP
  • o HSM Technologies
  • o Digital Signatures
  • o Cryptographic Key Management
  • Experience designing PKI solutions in Azure and AWS environments.
  • Strong scripting skills using PowerShell and Python.
  • Preferred Qualifications
  • CISSP, CISM, CCSP, or equivalent certification.
  • Venafi Certified Professional/Architect certification.
  • Experience with:
  • o Keyfactor
  • o DigiCert
  • o Entrust
  • o Microsoft ADCS
  • o HashiCorp Vault
  • o Azure Key Vault
  • o AWS Certificate Manager
  • Experience operating in BFSI or other highly regulated environments.

Similar jobs