PKI and Certificate Lifecycle Engineer

Tata Consultancy Services — United States · Posted ~8 hours ago

Full-time Visa History ✓

Skills

PKI Cryptography X.509 certificates TLS/SSL Certificate Authorities CRL OCSP Key management HSM Certificate lifecycle management Venafi Certificate automation REST APIs Infrastructure automation CI/CD Cloud security Identity and access management X.509 Azure Kubernetes Python PowerShell Ansible

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A large enterprise technology environment is seeking a PKI and Certificate Lifecycle Engineer with strong expertise in certificate security and automation. You will manage certificate authorities, X.509 certificates, cryptographic keys, automated certificate workflows, and integrations across cloud, application, identity, and DevOps infrastructure.

Highlights

Specialized security engineering role with deep exposure to PKI, certificate automation, cryptography, cloud security, and infrastructure automation. Provides the opportunity to work across enterprise security platforms, certificate lifecycle workflows, and modern DevOps environments.

Description

Job Description Must Have Technical/Functional Skills PKI & CryptographyPublic Key Infrastructure (PKI)X.509 CertificatesTLS/SSLCertificate Authorities (CA)Certificate Revocation Lists (CRL)OCSPKey ManagementHardware Security Modules (HSM)Code Signing CertificatesRoot and Intermediate CA Management Venafi ExpertiseVenafi Trust Protection Platform (TPP)Venafi SaaSCertificate DiscoveryCertificate Automation o Venafi APIsAdaptable AppsNative DriversReporting and GovernanceCertificate Lifecycle Workflows Platforms & IntegrationsWindows IISLinux/UnixMicrosoft AzureAzure Key VaultKubernetesF5 Load BalancersApacheTomcatWebLogicKafkaSolacePing FederateServiceNow Integrations DevOps & AutomationGitHub ActionsAzure DevOpsCI/CD PipelinesPowerShellPythonREST APIsAnsibleInfrastructure Automation Security DomainsAuthenticationAuthorizationIdentity & Access ManagementSecrets ManagementZero Trust PrinciplesCloud SecuritySecurity Monitoring Strong understanding of PKI architecture and certificate lifecycle processes. Experience implementing certificate automation patterns and DevSecOps integrations. Experience supporting enterprise-scale certificate environments. Strong troubleshooting, analytical, and problem-solving skills. Excellent communication and stakeholder management skills. Roles & Responsibilities Lead Identity centric Workforce Security team to develop authentication and access management solutions Drive the development of identity solutions, access patterns, modern security protocols, practicing Zero trust, least privileged, defense in depth principles Good understanding of AI concepts, Patterns and impact on identity and access management domain Participate and engage in AI adoption with Identity focus, knowledge and understanding of Entra ID agentic Identity, authentication flows and Patterns Review and provide feedback on Identity and access management related security solutions proposed by stakeholders and can provide consultation to the partners and IT Management In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, AWS Security Knowledge on Okta, PingFederate, Entitlement management solutions Strong knowledge on Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, Conditional access policies, MFA, Ker beros, LDAP, Identity Federations etc. Experience in providing security solutions for Java based Micro services, React based frontends and Android/iOS based mobile applications on the Azure Hands-of experience in JWT, session handling, Code signing, Certificate authentication, TLS/SSL, API Security, Application registration, application integration scenarios etc. Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc. Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure smooth remediation of toxic combinations, high risk entitlements etc. Understanding and application of threat modeling concepts and methodologies Understanding of Applications security, OWASP standards, security best practices, browser compatibilities/storages/cookies Acts as Workforce cybersecurity expert to in solutions spanning end user computing, proxy solutions, MFA, SSO, conditional accesses, Passwordless, Yubikey, bio-metric solutions, identity and governance scenarios, Secrets Management, automation, role based access control, Privileged identity management, Just in time accesses etc. Participates in solutions to support- token handling, OIDC/ OAuth flows, authorization patterns, identity federation, cloud architectures, cryptography, cloud native services, cloud security etc. Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, privileged access management etc. Ability to support operations in troubleshooting complex identity scenarios with hands-on experience on Sentinel/KQL/Audit logs etc. Good understanding of concepts related to docker Security, container orchestrations/Kubernetes TCS Employee Benefits Summary Discretionary Annual Incentive. Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans. Family Support: Maternal & Parental Leaves. Insurance Options: Auto & Home Insurance, Identity Theft Protection. Convenience & Professional Growth: Commuter Benefits & Certification & Training Reimbursement. Time Off: Vacation, Time Off, Sick Leave & Holidays. Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing. Salary Range: $120,000 - $130,000 a year Qualifications: BACHELOR OF COMPUTER SCIENCE