Haystack
← Back to Jobs
Engineering
CL

PKI Engineer with Venafi

ClifyXUnited States🇺🇸United StatesPosted Sep 15, 2026

Why This Role Stands Out

This hybrid role offers a competitive salary and the chance to lead impactful digital client enablement initiatives, fostering continuous improvement across technology teams. You'll thrive here if you have strong Agile leadership and experience coordinating complex technology projects, making this an excellent opportunity to advance your career. Apply today to join a dynamic environment focused on innovation and delivery excellence.

Quick Overview

Salary
$90k - $100k/yr
Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
1 week ago

Job Description

PKI Engineer with Venafi

Location: Remote
Employment Type: Full Time

Job Summary

We are seeking an experienced PKI Engineer / Venafi Engineer with strong hands-on expertise in Public Key Infrastructure (PKI), Venafi Trust Protection Platform (TPP), Certificate Lifecycle Management (CLM), X.509 certificates, TLS/SSL, certificate authorities, cryptography, and certificate automation.

The ideal candidate will be responsible for designing, implementing, supporting, and automating enterprise-scale PKI and certificate management solutions. This role will work across application, infrastructure, cloud, DevOps, and security teams to improve machine identity security, certificate lifecycle management, certificate automation, and Zero Trust security.

Strong experience with Venafi TPP / Venafi SaaS, certificate discovery, certificate automation, Venafi APIs, vCert, Adaptable Apps, Native Drivers, Azure, Kubernetes, F5, IIS, Linux, and CI/CD automation is highly desirable.

Must-Have Technical Skills

PKI & Cryptography

  • Strong hands-on experience with Public Key Infrastructure (PKI).

  • Strong understanding of:

    • X.509 Certificates

    • TLS/SSL

    • Certificate Authorities (CA)

    • Root CA

    • Intermediate / Issuing CA

    • Certificate Revocation Lists (CRL)

    • OCSP

    • Cryptographic Key Management

    • Hardware Security Modules (HSM)

    • Code Signing Certificates

    • Certificate Authentication

    • Digital Certificates

    • PKCS standards

  • Strong understanding of PKI architecture and certificate lifecycle management.

  • Experience supporting enterprise PKI environments and certificate trust chains.

  • Ability to troubleshoot complex certificate, TLS/SSL, trust-store, key-store, and authentication issues.

Venafi Expertise

Strong hands-on experience with:

  • Venafi Trust Protection Platform (TPP)

  • Venafi SaaS

  • Venafi TLS Protect

  • Certificate Discovery

  • Certificate Inventory

  • Certificate Automation

  • Certificate Lifecycle Management

  • Certificate Lifecycle Workflows

  • Certificate Provisioning

  • Certificate Renewal

  • Certificate Deployment

  • Venafi APIs

  • vCert

  • Adaptable Apps

  • Native Drivers

  • Venafi Policy Management

  • Reporting and Governance

  • Certificate Ownership and Governance

Certificate Automation & DevSecOps

Experience designing and implementing certificate automation using:

  • PowerShell

  • Python

  • Ansible

  • REST APIs

  • Venafi APIs

  • vCert

  • GitHub Actions

  • Azure DevOps

  • CI/CD Pipelines

  • Infrastructure Automation

  • Integrate certificate lifecycle processes into DevSecOps and CI/CD pipelines.

  • Automate certificate discovery, provisioning, renewal, deployment, and revocation.

  • Reduce manual certificate management through scalable automation frameworks.

Platforms & Application Integrations

Hands-on experience supporting certificate management across:

  • Windows Server / IIS

  • Linux / Unix

  • Microsoft Azure

  • Azure Key Vault

  • Kubernetes

  • F5 Load Balancers

  • Apache

  • Tomcat

  • WebLogic

  • Kafka

  • Solace

  • PingFederate

  • ServiceNow

Experience integrating PKI and certificate management solutions with enterprise applications, infrastructure platforms, middleware, cloud services, and security tools.

Identity & Security Skills

Working knowledge of:

  • Identity & Access Management (IAM)

  • Authentication

  • Authorization

  • Identity Federation

  • SSO

  • MFA

  • Passwordless Authentication

  • Role-Based Access Control (RBAC)

  • Privileged Identity Management (PIM)

  • Entitlement Management

  • Secrets Management

  • Machine Identity

  • Zero Trust

  • Least Privilege

  • Defense in Depth

  • Cloud Security

  • Security Monitoring

Key Responsibilities

PKI Engineering

  • Design, implement, configure, and support enterprise PKI infrastructure.

  • Manage Root CA, Intermediate CA, certificate policies, certificate chains, CRL, OCSP, and trust relationships.

  • Support enterprise certificate issuance, renewal, deployment, revocation, and troubleshooting.

  • Implement secure certificate and cryptographic key management practices.

  • Support HSM integration and secure key-management processes.

  • Manage and troubleshoot TLS/SSL certificates across enterprise infrastructure.

  • Support code-signing certificate management and certificate-based authentication.

Venafi Engineering

  • Configure, administer, and support Venafi Trust Protection Platform (TPP) and Venafi SaaS.

  • Perform certificate discovery and onboard applications into Venafi.

  • Configure Venafi policies, workflows, access controls, reporting, and governance.

  • Develop and maintain certificate lifecycle workflows.

  • Use Venafi APIs, vCert, Adaptable Apps, and Native Drivers for certificate automation.

  • Support Venafi upgrades, configuration changes, integrations, and platform enhancements.

  • Monitor certificate environments and proactively identify certificate expiration and compliance risks.

Certificate Automation

  • Design and implement automated certificate provisioning and renewal solutions.

  • Develop automation using PowerShell, Python, Ansible, REST APIs, GitHub Actions, and Azure DevOps.

  • Integrate certificate management into CI/CD pipelines and DevSecOps processes.

  • Automate certificate deployment across servers, applications, load balancers, middleware, Kubernetes, and cloud environments.

  • Develop reusable automation patterns and operational procedures.

Application & Cloud Support

  • Support certificate deployment across IIS, Apache, Tomcat, WebLogic, F5, Kafka, Solace, Kubernetes, Azure, and other enterprise platforms.

  • Integrate certificate management with Azure Key Vault and cloud-native security services.

  • Provide technical support for PKI integrations with enterprise applications and infrastructure.

  • Troubleshoot certificate authentication, TLS/SSL, trust-chain, and connectivity issues.

  • Work with application and infrastructure teams to onboard applications into certificate lifecycle management platforms.

IAM & Workforce Security

  • Support identity-centric security solutions involving authentication and access management.

  • Contribute to Zero Trust, least privilege, and defense-in-depth initiatives.

  • Provide PKI and certificate expertise for authentication, SSO, MFA, passwordless, and identity federation solutions.

  • Support identity solutions involving Microsoft Entra ID, Okta, PingFederate, and entitlement management.

  • Provide guidance on certificate-based authentication, JWT, OAuth, OIDC, and SAML integrations.

Cloud & Security Operations

  • Support security solutions across Microsoft Azure and AWS environments.

  • Work with security teams on cloud identity, access control, certificate management, and security monitoring.

  • Support Microsoft Sentinel, KQL, audit logs, and identity/security monitoring.

  • Troubleshoot complex identity, certificate, and authentication incidents.

  • Collaborate with application, infrastructure, cloud, DevOps, and cybersecurity teams.

Application & API Security

Working knowledge of:

  • JWT

  • OAuth 2.0

  • OpenID Connect (OIDC)

  • SAML

  • API Security

  • Certificate Authentication

  • Application Registration

  • Application Integration

  • Token Handling

  • Session Management

  • REST APIs

  • API Management

  • Web Services

Understanding of application security principles including OWASP, secure authentication, authorization patterns, browser security, cookies, session handling, and secure application integration.

Cloud & Infrastructure Security

Knowledge of:

  • Microsoft Azure

  • AWS Security

  • Azure Key Vault

  • Microsoft Entra ID

  • Kubernetes

  • Docker

  • Cloud Security

  • RBAC

  • Identity Governance

  • Privileged Access Management

  • CIEM

  • Firewalls

  • WAF

  • Application Gateway

  • NSGs

  • DLP

  • VPN

  • DNS

  • CDN

  • Application Proxy

  • API Management

AI & Emerging Identity Technologies

  • Working knowledge of AI concepts and AI security patterns.

  • Understanding of the impact of Generative AI and Agentic AI on Identity and Access Management.

  • Awareness of emerging AI agent identity, authentication, authorization, and access-control patterns.

  • Participate in AI adoption initiatives where identity, security, and access management are involved.

  • Evaluate security implications of AI-enabled applications, agents, APIs, and machine identities.

Security & Governance

  • Apply security best practices across PKI, identity, certificate management, and cloud environments.

  • Support enterprise Zero Trust initiatives.

  • Apply least-privilege and defense-in-depth principles.

  • Participate in threat modeling and security architecture reviews.

  • Support certificate governance, reporting, compliance, and security posture assessments.

  • Identify certificate, cryptographic, identity, and access-related risks.

  • Support security audits and remediation activities.

Required Experience

  • Strong experience in PKI engineering, certificate management, or information security.

  • Hands-on Venafi TPP / Venafi SaaS experience.

  • Strong understanding of enterprise PKI architecture and certificate lifecycle processes.

  • Experience implementing certificate automation and DevSecOps integrations.

  • Experience supporting large-scale enterprise certificate environments.

  • Hands-on scripting experience with PowerShell and/or Python.

  • Experience with REST APIs and automation.

  • Strong troubleshooting and problem-solving skills.

  • Excellent communication and stakeholder-management skills.

Preferred Skills

  • Experience with Microsoft Entra ID / Azure AD.

  • Experience with Okta or PingFederate.

  • Experience with ServiceNow integrations.

  • Experience with Azure Key Vault.

  • Experience with Kubernetes and container security.

  • Experience with AWS Security.

  • Experience with Microsoft Sentinel and KQL.

  • Experience with CIEM, PAM, PIM, and identity governance.

  • Experience with Keyfactor, DigiCert, Entrust, Microsoft ADCS, or HashiCorp Vault.

  • Experience in enterprise-scale or highly regulated environments.

  • Venafi certification is a plus.

  • Security certifications such as CISSP, CISM, or CCSP are a plus.

Technical Skills Summary

PKI: PKI, Public Key Infrastructure, X.509, TLS, SSL, Certificate Authority, Root CA, Intermediate CA, CRL, OCSP, HSM, Code Signing, Cryptography, Key Management, Certificate Authentication

Venafi: Venafi TPP, Venafi Trust Protection Platform, Venafi SaaS, Venafi TLS Protect, Certificate Discovery, Certificate Automation, Certificate Lifecycle Management, Venafi APIs, vCert, Adaptable Apps, Native Drivers, Policy Management, Reporting, Governance

Automation: PowerShell, Python, Ansible, REST APIs, GitHub Actions, Azure DevOps, CI/CD, DevSecOps, Infrastructure Automation

Platforms: Windows, IIS, Linux, Unix, Apache, Tomcat, WebLogic, Kubernetes, F5, Kafka, Solace, PingFederate, ServiceNow

Cloud: Microsoft Azure, Azure Key Vault, AWS, Cloud Security, Cloud IAM

Identity: Microsoft Entra ID, Azure AD, IAM, SSO, MFA, Passwordless, OAuth, OIDC, SAML, JWT, RBAC, PIM, PAM, CIEM, Entitlement Management, Identity Federation

Security: Zero Trust, Least Privilege, Defense in Depth, Secrets Management, API Security, OWASP, Threat Modeling, Security Monitoring, Microsoft Sentinel, KQL

Ideal Candidate Profile

The ideal candidate is a PKI Engineer / Venafi Engineer with strong hands-on experience in enterprise certificate management and automation.

The candidate should be able to manage the complete certificate lifecycle:

Certificate Discovery → Inventory → Policy → Application Onboarding → Provisioning → Deployment → Monitoring → Renewal → Revocation → Governance

Strong candidates will also understand how PKI and machine identity integrate with IAM, cloud security, DevSecOps, application security, and Zero Trust architectures.

Core Dice Search Keywords

PKI Engineer, PKI Security Engineer, PKI Administrator, PKI Architect, Venafi Engineer, Venafi Administrator, Venafi TPP Engineer, Venafi Developer, Venafi Consultant, Certificate Management Engineer, Certificate Lifecycle Management, CLM, Machine Identity, Machine Identity Management, Public Key Infrastructure, PKI, X.509, TLS, SSL, Certificate Authority, CA, Root CA, Intermediate CA, CRL, OCSP, HSM, Hardware Security Module, Cryptography, Code Signing, Certificate Authentication, Venafi TPP, Venafi Trust Protection Platform, Venafi SaaS, Venafi TLS Protect, Certificate Discovery, Certificate Automation, Venafi API, vCert, Adaptable Apps, Native Drivers, Certificate Provisioning, Certificate Renewal, Certificate Deployment, Certificate Governance, Azure Key Vault, Microsoft Azure, AWS, Kubernetes, IIS, Windows Server, Linux, Apache, Tomcat, WebLogic, F5, Kafka, Solace, PingFederate, ServiceNow, PowerShell, Python, Ansible, REST API, GitHub Actions, Azure DevOps, CI/CD, DevSecOps, IAM, Identity and Access Management, Microsoft Entra ID, Azure AD, Okta, OAuth, OIDC, SAML, SSO, MFA, Passwordless, RBAC, PIM, PAM, CIEM, Zero Trust, Secrets Management, Cloud Security, API Security, Microsoft Sentinel, KQL, OWASP, Machine Identity Security.

Similar jobs