Why This Role Stands Out
This hybrid role offers a competitive salary and the chance to lead impactful digital client enablement initiatives, fostering continuous improvement across technology teams. You'll thrive here if you have strong Agile leadership and experience coordinating complex technology projects, making this an excellent opportunity to advance your career. Apply today to join a dynamic environment focused on innovation and delivery excellence.
Quick Overview
Job Description
PKI Engineer with Venafi
Location: Remote
Employment Type: Full Time
Job Summary
We are seeking an experienced PKI Engineer / Venafi Engineer with strong hands-on expertise in Public Key Infrastructure (PKI), Venafi Trust Protection Platform (TPP), Certificate Lifecycle Management (CLM), X.509 certificates, TLS/SSL, certificate authorities, cryptography, and certificate automation.
The ideal candidate will be responsible for designing, implementing, supporting, and automating enterprise-scale PKI and certificate management solutions. This role will work across application, infrastructure, cloud, DevOps, and security teams to improve machine identity security, certificate lifecycle management, certificate automation, and Zero Trust security.
Strong experience with Venafi TPP / Venafi SaaS, certificate discovery, certificate automation, Venafi APIs, vCert, Adaptable Apps, Native Drivers, Azure, Kubernetes, F5, IIS, Linux, and CI/CD automation is highly desirable.
Must-Have Technical Skills
PKI & Cryptography
Strong hands-on experience with Public Key Infrastructure (PKI).
Strong understanding of:
X.509 Certificates
TLS/SSL
Certificate Authorities (CA)
Root CA
Intermediate / Issuing CA
Certificate Revocation Lists (CRL)
OCSP
Cryptographic Key Management
Hardware Security Modules (HSM)
Code Signing Certificates
Certificate Authentication
Digital Certificates
PKCS standards
Strong understanding of PKI architecture and certificate lifecycle management.
Experience supporting enterprise PKI environments and certificate trust chains.
Ability to troubleshoot complex certificate, TLS/SSL, trust-store, key-store, and authentication issues.
Venafi Expertise
Strong hands-on experience with:
Venafi Trust Protection Platform (TPP)
Venafi SaaS
Venafi TLS Protect
Certificate Discovery
Certificate Inventory
Certificate Automation
Certificate Lifecycle Management
Certificate Lifecycle Workflows
Certificate Provisioning
Certificate Renewal
Certificate Deployment
Venafi APIs
vCert
Adaptable Apps
Native Drivers
Venafi Policy Management
Reporting and Governance
Certificate Ownership and Governance
Certificate Automation & DevSecOps
Experience designing and implementing certificate automation using:
PowerShell
Python
Ansible
REST APIs
Venafi APIs
vCert
GitHub Actions
Azure DevOps
CI/CD Pipelines
Infrastructure Automation
Integrate certificate lifecycle processes into DevSecOps and CI/CD pipelines.
Automate certificate discovery, provisioning, renewal, deployment, and revocation.
Reduce manual certificate management through scalable automation frameworks.
Platforms & Application Integrations
Hands-on experience supporting certificate management across:
Windows Server / IIS
Linux / Unix
Microsoft Azure
Azure Key Vault
Kubernetes
F5 Load Balancers
Apache
Tomcat
WebLogic
Kafka
Solace
PingFederate
ServiceNow
Experience integrating PKI and certificate management solutions with enterprise applications, infrastructure platforms, middleware, cloud services, and security tools.
Identity & Security Skills
Working knowledge of:
Identity & Access Management (IAM)
Authentication
Authorization
Identity Federation
SSO
MFA
Passwordless Authentication
Role-Based Access Control (RBAC)
Privileged Identity Management (PIM)
Entitlement Management
Secrets Management
Machine Identity
Zero Trust
Least Privilege
Defense in Depth
Cloud Security
Security Monitoring
Key Responsibilities
PKI Engineering
Design, implement, configure, and support enterprise PKI infrastructure.
Manage Root CA, Intermediate CA, certificate policies, certificate chains, CRL, OCSP, and trust relationships.
Support enterprise certificate issuance, renewal, deployment, revocation, and troubleshooting.
Implement secure certificate and cryptographic key management practices.
Support HSM integration and secure key-management processes.
Manage and troubleshoot TLS/SSL certificates across enterprise infrastructure.
Support code-signing certificate management and certificate-based authentication.
Venafi Engineering
Configure, administer, and support Venafi Trust Protection Platform (TPP) and Venafi SaaS.
Perform certificate discovery and onboard applications into Venafi.
Configure Venafi policies, workflows, access controls, reporting, and governance.
Develop and maintain certificate lifecycle workflows.
Use Venafi APIs, vCert, Adaptable Apps, and Native Drivers for certificate automation.
Support Venafi upgrades, configuration changes, integrations, and platform enhancements.
Monitor certificate environments and proactively identify certificate expiration and compliance risks.
Certificate Automation
Design and implement automated certificate provisioning and renewal solutions.
Develop automation using PowerShell, Python, Ansible, REST APIs, GitHub Actions, and Azure DevOps.
Integrate certificate management into CI/CD pipelines and DevSecOps processes.
Automate certificate deployment across servers, applications, load balancers, middleware, Kubernetes, and cloud environments.
Develop reusable automation patterns and operational procedures.
Application & Cloud Support
Support certificate deployment across IIS, Apache, Tomcat, WebLogic, F5, Kafka, Solace, Kubernetes, Azure, and other enterprise platforms.
Integrate certificate management with Azure Key Vault and cloud-native security services.
Provide technical support for PKI integrations with enterprise applications and infrastructure.
Troubleshoot certificate authentication, TLS/SSL, trust-chain, and connectivity issues.
Work with application and infrastructure teams to onboard applications into certificate lifecycle management platforms.
IAM & Workforce Security
Support identity-centric security solutions involving authentication and access management.
Contribute to Zero Trust, least privilege, and defense-in-depth initiatives.
Provide PKI and certificate expertise for authentication, SSO, MFA, passwordless, and identity federation solutions.
Support identity solutions involving Microsoft Entra ID, Okta, PingFederate, and entitlement management.
Provide guidance on certificate-based authentication, JWT, OAuth, OIDC, and SAML integrations.
Cloud & Security Operations
Support security solutions across Microsoft Azure and AWS environments.
Work with security teams on cloud identity, access control, certificate management, and security monitoring.
Support Microsoft Sentinel, KQL, audit logs, and identity/security monitoring.
Troubleshoot complex identity, certificate, and authentication incidents.
Collaborate with application, infrastructure, cloud, DevOps, and cybersecurity teams.
Application & API Security
Working knowledge of:
JWT
OAuth 2.0
OpenID Connect (OIDC)
SAML
API Security
Certificate Authentication
Application Registration
Application Integration
Token Handling
Session Management
REST APIs
API Management
Web Services
Understanding of application security principles including OWASP, secure authentication, authorization patterns, browser security, cookies, session handling, and secure application integration.
Cloud & Infrastructure Security
Knowledge of:
Microsoft Azure
AWS Security
Azure Key Vault
Microsoft Entra ID
Kubernetes
Docker
Cloud Security
RBAC
Identity Governance
Privileged Access Management
CIEM
Firewalls
WAF
Application Gateway
NSGs
DLP
VPN
DNS
CDN
Application Proxy
API Management
AI & Emerging Identity Technologies
Working knowledge of AI concepts and AI security patterns.
Understanding of the impact of Generative AI and Agentic AI on Identity and Access Management.
Awareness of emerging AI agent identity, authentication, authorization, and access-control patterns.
Participate in AI adoption initiatives where identity, security, and access management are involved.
Evaluate security implications of AI-enabled applications, agents, APIs, and machine identities.
Security & Governance
Apply security best practices across PKI, identity, certificate management, and cloud environments.
Support enterprise Zero Trust initiatives.
Apply least-privilege and defense-in-depth principles.
Participate in threat modeling and security architecture reviews.
Support certificate governance, reporting, compliance, and security posture assessments.
Identify certificate, cryptographic, identity, and access-related risks.
Support security audits and remediation activities.
Required Experience
Strong experience in PKI engineering, certificate management, or information security.
Hands-on Venafi TPP / Venafi SaaS experience.
Strong understanding of enterprise PKI architecture and certificate lifecycle processes.
Experience implementing certificate automation and DevSecOps integrations.
Experience supporting large-scale enterprise certificate environments.
Hands-on scripting experience with PowerShell and/or Python.
Experience with REST APIs and automation.
Strong troubleshooting and problem-solving skills.
Excellent communication and stakeholder-management skills.
Preferred Skills
Experience with Microsoft Entra ID / Azure AD.
Experience with Okta or PingFederate.
Experience with ServiceNow integrations.
Experience with Azure Key Vault.
Experience with Kubernetes and container security.
Experience with AWS Security.
Experience with Microsoft Sentinel and KQL.
Experience with CIEM, PAM, PIM, and identity governance.
Experience with Keyfactor, DigiCert, Entrust, Microsoft ADCS, or HashiCorp Vault.
Experience in enterprise-scale or highly regulated environments.
Venafi certification is a plus.
Security certifications such as CISSP, CISM, or CCSP are a plus.
Technical Skills Summary
PKI: PKI, Public Key Infrastructure, X.509, TLS, SSL, Certificate Authority, Root CA, Intermediate CA, CRL, OCSP, HSM, Code Signing, Cryptography, Key Management, Certificate Authentication
Venafi: Venafi TPP, Venafi Trust Protection Platform, Venafi SaaS, Venafi TLS Protect, Certificate Discovery, Certificate Automation, Certificate Lifecycle Management, Venafi APIs, vCert, Adaptable Apps, Native Drivers, Policy Management, Reporting, Governance
Automation: PowerShell, Python, Ansible, REST APIs, GitHub Actions, Azure DevOps, CI/CD, DevSecOps, Infrastructure Automation
Platforms: Windows, IIS, Linux, Unix, Apache, Tomcat, WebLogic, Kubernetes, F5, Kafka, Solace, PingFederate, ServiceNow
Cloud: Microsoft Azure, Azure Key Vault, AWS, Cloud Security, Cloud IAM
Identity: Microsoft Entra ID, Azure AD, IAM, SSO, MFA, Passwordless, OAuth, OIDC, SAML, JWT, RBAC, PIM, PAM, CIEM, Entitlement Management, Identity Federation
Security: Zero Trust, Least Privilege, Defense in Depth, Secrets Management, API Security, OWASP, Threat Modeling, Security Monitoring, Microsoft Sentinel, KQL
Ideal Candidate Profile
The ideal candidate is a PKI Engineer / Venafi Engineer with strong hands-on experience in enterprise certificate management and automation.
The candidate should be able to manage the complete certificate lifecycle:
Certificate Discovery → Inventory → Policy → Application Onboarding → Provisioning → Deployment → Monitoring → Renewal → Revocation → Governance
Strong candidates will also understand how PKI and machine identity integrate with IAM, cloud security, DevSecOps, application security, and Zero Trust architectures.
Core Dice Search Keywords
PKI Engineer, PKI Security Engineer, PKI Administrator, PKI Architect, Venafi Engineer, Venafi Administrator, Venafi TPP Engineer, Venafi Developer, Venafi Consultant, Certificate Management Engineer, Certificate Lifecycle Management, CLM, Machine Identity, Machine Identity Management, Public Key Infrastructure, PKI, X.509, TLS, SSL, Certificate Authority, CA, Root CA, Intermediate CA, CRL, OCSP, HSM, Hardware Security Module, Cryptography, Code Signing, Certificate Authentication, Venafi TPP, Venafi Trust Protection Platform, Venafi SaaS, Venafi TLS Protect, Certificate Discovery, Certificate Automation, Venafi API, vCert, Adaptable Apps, Native Drivers, Certificate Provisioning, Certificate Renewal, Certificate Deployment, Certificate Governance, Azure Key Vault, Microsoft Azure, AWS, Kubernetes, IIS, Windows Server, Linux, Apache, Tomcat, WebLogic, F5, Kafka, Solace, PingFederate, ServiceNow, PowerShell, Python, Ansible, REST API, GitHub Actions, Azure DevOps, CI/CD, DevSecOps, IAM, Identity and Access Management, Microsoft Entra ID, Azure AD, Okta, OAuth, OIDC, SAML, SSO, MFA, Passwordless, RBAC, PIM, PAM, CIEM, Zero Trust, Secrets Management, Cloud Security, API Security, Microsoft Sentinel, KQL, OWASP, Machine Identity Security.
Similar jobs
- IS
Automation Controls Engineer
NewINSPYR Solutions
Houston, TX🇺🇸On-site16 hours agoRoboticsAutoCADPLC Programming+1Engineering - PT
Senior Virtual Desktop Engineer
NewPhoenix Technology Partners, LLC
New York, NY🇺🇸Hybrid16 hours agoEngineering - AC
REQ : Safety Engineer - Autonomous Machinery II-III in Mendon/Logan, Utah (Onsite)
NewAita Consulting Services,Inc.
Mendon, UT🇺🇸On-site16 hours agoEngineering - HU
Kafka Admin/Engineer
NewHUMAC INC.
New York, NY🇺🇸On-site16 hours agoEngineering - GI
Senior Financial Messaging & Middleware Engineer
NewGalaxy i Technologies, Inc.
Dallas, TX🇺🇸Hybrid16 hours agoEngineering - TC
RPA UiPath Engineer
NewTECHNEPTUNE CONSULTING INC
Charlotte, NC🇺🇸Hybrid16 hours agoAgileEngineering