Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Global NTT in Singapore seeks an experienced PKI Engineer to own the enterprise Public Key Infrastructure, ensuring high availability, integrity, and security across certificate issuance workflows. You will manage Microsoft ADCS, cloud certificate platforms, and HSMs, and automate lifecycle pipelines with Python, PowerShell, or Shell scripting, supporting TLS 1.3 adoption and audits.
Collaborate with IT ops and development teams to integrate automated enrollment into CI/CD and strengthen
Global NTT is seeking an experienced PKI Engineer to join our team in Singapore and drive certificate lifecycle management, cryptographic security, and PKI modernization initiatives. In this specialized security role, you will play a critical part in protecting enterprise infrastructure, managing complex public key infrastructures, and enforcing robust cryptographic controls across multi-platform environments. You will collaborate closely with cross-functional IT and cybersecurity teams to automate certificate provisioning, eliminate service outages caused by expired certificates, and ensure adherence to rigorous compliance frameworks. Ideal candidates bring deep expertise in X.509 standards, enterprise Certificate Authorities, hardware security modules, and scripting automation, coupled with a strong background in financial services or large-scale enterprise security operations.
As a PKI Engineer at Global NTT, you will take full ownership of the enterprise Public Key Infrastructure, ensuring high availability, integrity, and security across all certificate issuance and validation workflows. Your day-to-day responsibilities encompass managing Microsoft ADCS, cloud-based certificate management platforms, and Hardware Security Modules (HSMs) to safeguard sensitive cryptographic keys. You will architect and implement automated certificate lifecycle pipelines using Python, PowerShell, or Shell scripting to streamline issuance, renewal, revocation, and expiration tracking across servers, applications, middleware, databases, APIs, and network devices. You will act as the technical subject matter expert for troubleshooting complex certificate errors, trust-chain failures, and TLS handshake anomalies. Furthermore, you will support strategic security modernization programs, including TLS 1.3 adoption, cryptographic algorithm upgrades, and comprehensive audits to meet regulatory compliance standards.
Salary/Rate: Competitive and commensurate with experiencen.
Deadline: Open until filled.
Notice Period: As per candidate availability.
Contract Duration: 1 Year Renewable Contract.