An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Alike Thoughts in Pune/Chennai seeks a Senior Security Engineer specializing in PKI cryptography to lead certificate lifecycle management, cryptographic services automation, and operational support. You will implement designs, resolve complex certificate issues, and contribute to post-quantum readiness under security architecture leadership.
You will administer PKI services, manage CA/RA, HSM integrations, OCSP/CRL, and TLS deployments; build automation with PowerShell, Python, and IaC,
Job Title Senior Security Engineer PKI Cryptography L3
This is a handson technical role requiring experience in enterprise PKI certificate lifecycle management cryptographic services automation and operational support The position supports internal and external PKI services implements approved designs resolves complex certificate issues and contributes to postquantum readiness activities under the direction of security architecture leaders
Work Location Pune or Chennai
Shift Timings Flexible to support 24x7 global teams planned maintenance oncall coverage and critical escalations
Administer maintain monitor and troubleshoot internal and external PKI services and enterprise certificate lifecycle platforms
Implement approved designs and standards for Certificate Authorities Registration Authorities HSM integrations certificate repositories OCSP CRL and related components
Perform certificate enrollment approval issuance deployment renewal rotation revocation ownership updates inventory and expiration remediation
Support public and private TLS client authentication code signing device workload and machine identity certificate use cases
Investigate certificate failures trust chain issues TLS configuration keystores OCSP CRL private key handling and interoperability problems
Build and support certificate automation using ACME APIs agents agentless methods PowerShell Python and infrastructureascode tools
Assist application infrastructure and cloud teams with onboarding to centralized certificate management and approved selfservice capabilities
Support integrations with DigiCert Trust Lifecycle Manager Microsoft AD CS Azure AWS Kubernetes key vaults secrets platforms CICD pipelines monitoring and ServiceNow
Support HSM and cloud KMS activities including key generation access control rotation backup recovery and operational monitoring
Apply approved algorithms key sizes certificate profiles TLS settings and key lifecycle requirements
Contribute to TLS modernization and remediation of weak unsupported expired or noncompliant cryptographic configurations
Research NIST postquantum standards vendor capabilities hybrid cryptographic approaches and platform readiness
Support proofs of concept and pilots for hybrid or quantumresistant PKI certificates signing key management and secure communications
Document compatibility findings migration dependencies implementation steps operating procedures support runbooks and recovery procedures
Support incidents problems changes maintenance activities audit evidence collection control testing risk remediation and security exceptions
Work Experience Minimum 10 years of experience in information security infrastructure systems engineering or security engineering including at least 5 years supporting PKI certificate management key management or related security technologies
Education Bachelors degree in computer science cybersecurity engineering information technology or a related field or equivalent practical experience
Strong practical knowledge of X509 certificates TLS certificate chains trust stores enrollment renewal revocation OCSP CRL keystores and private key handling
Handson experience with DigiCert Trust Lifecycle Manager Microsoft AD CS cloud certificate services or comparable PKI technologies
Experience troubleshooting PKI and certificate issues in onpremises and cloud environments
Experience with ACME APIs PowerShell Python infrastructure as code CICD or other automation technologies
Experience supporting Azure AWS Kubernetes key vaults secrets management HSM cloud KMS or related platforms
Working knowledge of ITIL practices change management incident management technical documentation and ServiceNow
Ability to independently manage assigned technical deliverables and communicate clearly with global technical teams
Familiarity with TLS 13 code signing digital signing machine identity NonHuman Identity security and certificate discovery tools
Awareness of NIST postquantum cryptography standards hybrid cryptography cryptoagility Cryptographic Bill of Materials concepts and migration planning
Experience with cryptographic inventory compliance monitoring policy validation audit support or disaster recovery testing
Relevant security cloud PKI automation or vendor certifications
Strong communication skills Clearly communicate technical findings actions risks and status to team members and partner teams
Analytical and troubleshooting mindset Identify root causes evaluate evidence and follow structured troubleshooting and remediation steps
Ownership and reliability Manage assigned work through completion