Senior Certificate Automation Engineer

Raiserecruiting — Canada · Posted ~5 hours ago

Senior Contract Hybrid $79.56/hr-$93.91/hr

Skills

Certificate lifecycle management Automation SSL certificate management Certificate issuance Certificate renewal Certificate deployment Certificate rotation Certificate revocation Machine identity security Venafi SSL/TLS Certificate lifecycle automation

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A Senior Certificate Automation Engineer role focused on designing and implementing automated lifecycle management for enterprise SSL certificates. Responsibilities include certificate issuance, renewal, deployment, rotation and revocation, eliminating manual processes, supporting certificate rotation across production environments, and strengthening machine identity security.

Highlights

Senior contract role with strong remote flexibility, hourly compensation, and a focus on automating enterprise certificate lifecycle management, reducing manual processes, and improving machine identity security.

Description

Location: Toronto, ON – (Remote/Hybrid) – Onsite Wednesdays & Open to fully remote.Pay Rate: $79.56/hr - $93.91/hrContract End Date: December 31, 2026- Option to extend based on project requirements, funding, and performance. We at Raise are hiring a Senior Certificate Automation Engineer for one of our top clients. After establishing themselves as an industry leader, they’re now expanding their team to meet rising demand. We’re hiring right now; if you’re interested, apply below for your chance to join a great place to work. Responsibilities Certificate Lifecycle Automation Design, develop, and implement automated certificate lifecycle management solutions.Build automation for certificate issuance, renewal, deployment, rotation, and revocation.Support enterprise SSL certificate rotation initiatives across production and non-production environments.Identify and eliminate manual certificate management processes through automation. Machine Identity Security & Venafi Engineering Support and enhance CyberArk Machine Identity Security (Venafi) capabilities.Develop integrations between certificate management platforms and enterprise systems.Implement reusable onboarding and automation patterns for application teams.Improve certificate visibility, compliance, governance, and operational efficiency. Platform Integration Engineering Design and implement certificate management integrations with enterprise platforms, including: F5AkamaiAWS Certificate Manager (ACM)Amazon EKS / KubernetesMicrosoft GraphHashiCorp VaultContainer platforms and cloud-native workloadsAdditional enterprise applications and infrastructure services HashiCorp Vault Automation Develop certificate automation solutions leveraging HashiCorp Vault PKI capabilities.Build and enhance integrations between Vault and enterprise applications.Create automated certificate issuance and rotation workflows.Support onboarding of applications to Vault-based certificate management services. Application Onboarding & Support Partner with application and infrastructure teams to implement certificate automation solutions.Provide technical guidance, troubleshooting, onboarding support, and best practices.Develop technical documentation, implementation guides, and operational runbooks.Lead knowledge-sharing and enablement sessions for stakeholders. Engineering & Delivery Develop automation using scripting, APIs, Infrastructure-as-Code, and DevOps practices.Participate in Agile delivery processes including backlog refinement, estimation, sprint planning, and implementation activities.Contribute to platform resiliency, monitoring, operational support, and continuous improvement initiatives. Must Have Requirements Technical Experience: 5+ years of experience in Security Engineering, Infrastructure Engineering, Platform Engineering, or related disciplines.Strong experience with PKI, SSL/TLS certificates, and certificate lifecycle management.Venafi/CyberArk Machine Identity Security. Hands-on experience with CyberArk Machine Identity Security (Venafi) or equivalent certificate management platforms.Experience implementing certificate automation at enterprise scale.Strong knowledge of cryptography principles, certificate trust chains, and machine identity security.Platform & Cloud Experience: Hands-on experience with several of the following:AWS Certificate Manager (ACM)Amazon EKS / KubernetesMicrosoft GraphF5 Load BalancersAkamaiAzure and/or AWS cloud servicesREST APIs and platform integrationsAutomation & DevOps: Experience with:PythonPowerShellTerraformAnsibleGitCI/CD pipelinesInfrastructure as CodeAPI-based automationInfrastructure SkillsLinux and Windows administrationNetworking fundamentalsTLS/SSL protocols, including ACMELoad balancers and reverse proxiesKubernetes and container platformsMonitoring and logging solutions Preferred Qualifications Experience with HashiCorp Vault PKI Secrets Engine.Experience supporting large-scale certificate management programs.Experience working in Agile delivery environments.Security certifications such as CISSP, CCSP, Security+, GIAC, or equivalent.Experience supporting enterprise security platforms and cloud-native technologies. Education Bachelor Science degree in computer science. TLS/SSL certificate lifecycle workflows Top 3 Skills CyberArk Machine Identity Security (formerly Venafi) / Certificate Management- managing certificate lifecycles and integrations with platforms such as HashiCorp Vault, Akamai, and other enterprise systems. Understanding of certificate workflows and automation processes.Scripting and Automation- scripting skills using Python, JavaPKI / Certificate Lifecycle Knowledge- how certificates work, including SSL/TLS, PKI concepts, certificate issuance, renewal, deployment, and operational workflows. Looking for meaningful work? We can help! Raise is an established hiring firm with over 65 years of experience. We believe strongly in making the world a better place through work, which is why we’re a certified B Corporation and donate 10% of our profits to charity. We strive to build teams that reflect the diversity of the communities we work in. We encourage all qualified applicants to apply, including people from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with visible/nonvisible disabilities. We have a dedicated webpage for accommodations where you can learn more about what we offer and request accommodation: https://raise.jobs/accommodations/ In order to submit candidates for roles, our clients will sometimes require personal information to confirm the identity of applicants and their legal status to work. Raise will never ask you for personal or banking information unless you have been selected for a job. If you are ever unsure about the legitimacy of this or another job posting by Raise (or have any other questions), please contact us at +1 800-567-9675 or hello@raiserecruiting.com #FIN24