Certificate Lifecycle/ PKI Engineer - Venafi Exp. (1152667)

The Judge Group

Chicago (IL)

On-site

USD 150,000 - 160,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical benefits
Dental coverage
Vision coverage
Retirement plan
Paid time off

Job summary

The Judge Group is seeking an experienced PKI Engineer with Venafi expertise to lead identity and access security initiatives in a hybrid Chicago-based team. You will manage PKI, TLS certificates, and automation across Azure, Kubernetes, and cloud services, delivering scalable, zero-trust security solutions.

Five-plus years in PKI and three-plus years with Venafi are expected, along with strong troubleshooting, communication, and stakeholder management skills.

Qualifications

  • 5+ years of experience supporting PKI, TLS Certificates, or Certificate Lifecycle Management.
  • 3+ years of hands-on Venafi administration and engineering experience.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Excellent communication and stakeholder management skills.

Responsibilities

  • Lead Identity centric Workforce Security team to develop authentication and access management solutions.
  • Drive the development of identity solutions, access patterns, modern security protocols, practicing Zero trust, least privileged, defense in depth principles.
  • Good understanding of AI concepts, patterns and impact on identity and access management domain.
  • Participate in AI adoption with Identity focus, knowledge of Entra ID agentic Identity, authentication flows and patterns.
  • Review and provide feedback on Identity and access management related security solutions proposed by stakeholders.
  • In-depth knowledge on Entra ID, EPM, Sentinel, Azure, AWS Security.
  • Knowledge on Okta, PingFederate, Entitlement management solutions.
  • Strong knowledge on Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, CA policies, Kerberos, LDAP, Identity Federations, etc.
  • Experience in providing security solutions for Java microservices, React frontends, and mobile apps on Azure.
  • Hands-on experience in JWT, session handling, Code signing, TLS/SSL, API Security, application registration and integration scenarios.
  • Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, App Gateways, NSGs, App Proxy, Radius clusters, CDN.
  • Understanding CIEM to manage entitlements and risky combinations.
  • Threat modeling concepts and methodologies familiarization.
  • OWASP security practices and cloud security basics.
  • End-to-end workforce cybersecurity expertise across identity, MFA, SSO, Secrets management, RBAC, and Privileged Identity Management.

Skills

PKI & Cryptography
Venafi Expertise
TLS/SSL
X.509 Certificates
Public Key Infrastructure
HSM
Certificate Lifecycle Management
DevOps & Automation
Azure
Kubernetes
Windows IIS
Automation
Python
Azure Key Vault

Tools

Venafi TPP

Job description

PKI Engineer with Venafi Expertise

Location: Chicago, IL, USA

Salary: $150,000.00 USD Annually - $160,000.00 USD Annually

Remote:

Fulltime:

  • Linux/Unix

5+ years of experience supporting PKI, TLS Certificates, or Certificate Lifecycle Management.

3+ years of hands-on Venafi administration and engineering experience

  • PKI & Cryptography
  • Public Key Infrastructure (PKI)
  • X.509 Certificates
  • TLS/SSL
  • Certificate Authorities (CA)
  • Certificate Revocation Lists (CRL)
  • OCSP
  • Key Management
  • Hardware Security Modules (HSM)
  • Code Signing Certificates
  • Root and Intermediate CA Management
  • Venafi Expertise
  • Venafi Trust Protection Platform (TPP)
  • Venafi SaaS
  • Certificate Discovery
  • Certificate Automation o Venafi APIs
  • Adaptable Apps
  • Native Drivers
  • Reporting and Governance
  • Certificate Lifecycle Workflows
  • Platforms & Integrations
  • Windows IIS
  • Linux/Unix
  • Microsoft Azure
  • Azure Key Vault
  • Kubernetes
  • F5 Load Balancers
  • Apache
  • Tomcat
  • WebLogic
  • Kafka
  • Solace
  • Ping Federate
  • ServiceNow Integrations
  • DevOps & Automation
  • GitHub Actions
  • Azure DevOps
  • CI/CD Pipelines
  • PowerShell
  • Python
  • REST APIs
  • Ansible
  • Infrastructure Automation
  • Security Domains
  • Authentication
  • Authorization
  • Identity & Access Management
  • Secrets Management
  • Zero Trust Principles
  • Cloud Security
  • Security Monitoring
  • Strong understanding of PKI architecture and certificate lifecycle processes.
  • Experience implementing certificate automation patterns and DevSecOps integrations.
  • Experience supporting enterprise-scale certificate environments.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Excellent communication and stakeholder management skills.
Roles & Responsibilities
  • Lead Identity centric Workforce Security team to develop authentication and access management solutions
  • Drive the development of identity solutions, access patterns, modern security protocols, practicing Zero trust, least privileged, defense in depth principles
  • Good understanding of AI concepts, Patterns and impact on identity and access management domain
  • Participate and engage in AI adoption with Identity focus, knowledge and understanding of Entra ID agentic Identity, authentication flows and Patterns
  • Review and provide feedback on Identity and access management related security solutions proposed by stakeholders and can provide consultation to the partners and IT Management
  • In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, AWS Security
  • Knowledge on Okta, PingFederate, Entitlement management solutions
  • Strong knowledge on Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, Conditional access policies, MFA, Ker beros, LDAP, Identity Federations etc.
  • Experience in providing security solutions for Java based Micro services, React based frontends and Android/iOS based mobile applications on the Azure
  • Hands-of experience in JWT, session handling, Code signing, Certificate authentication, TLS/SSL, API Security, Application registration, application integration scenarios etc.
  • Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc.
  • Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure smooth remediation of toxic combinations, high risk entitlements etc.
  • Understanding and application of threat modeling concepts and methodologies
  • Understanding of Applications security, OWASP standards, security best practices, browser compatibilities/storages/cookies
  • Acts as Workforce cybersecurity expert to in solutions spanning end user computing, proxy solutions, MFA, SSO, conditional accesses, Passwordless, Yubikey, bio-metric solutions, identity and governance scenarios, Secrets Management, automation, role based access control, Privileged identity management, Just in time accesses etc.
  • Participates in solutions to support- token handling, OIDC/ OAuth flows, authorization patterns, identity federation, cloud architectures, cryptography, cloud native services, cloud security etc.
  • Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, privileged access management etc.
  • Ability to support operations in troubleshooting complex identity scenarios with hands‑of experience on Sentinel/KQL/Audit logs etc.
  • Good understanding of concepts related to docker Security, container orchestrations/Kubernetes

Comprehensive benefits package including medical, dental, and vision coverage, retirement savings plan with company contribution, paid time off, holidays, and opportunities for professional growth and career development. Additional benefits and perks will be discussed during the interview process.

Contact: ssharma17@judge.com

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Job Title: Certificate Lifecycle/ PKI Engineer with Venafi Expertise
Job Title: Certificate Lifecycle/ PKI Engineer with Venafi Expertise

Themesoft Inc • Chicago (IL)

On-site
USD 120,000 - 160,000
Certificate Lifecycle/ PKI Engineer with Venafi Expertise
Certificate Lifecycle/ PKI Engineer with Venafi Expertise

Tata Consultancy Services • Chicago (IL)

On-site
USD 120,000 - 130,000
Discretionary annual incentive
Comprehensive medical coverage
401K plan
PKI Venafi Architect
PKI Venafi Architect

Tata Consultancy Services • Chicago (IL)

On-site
USD 120,000 - 130,000
Discretionary bonus
Medical coverage
Parental leave
+3
PKI Venafi Architect
PKI Venafi Architect

Siri InfoSolutions Inc • United States

Hybrid
USD 120,000 - 180,000
PKI & Venafi Engineer: TLS, Certificate Automation & IAM
PKI & Venafi Engineer: TLS, Certificate Automation & IAM

The Judge Group • Chicago (IL)

On-site
USD 150,000 - 160,000
Medical benefits
Dental coverage
Vision coverage
+2
PKI Venafi Architect
PKI Venafi Architect

Vaarida Technologies LLC • Chicago (IL)

On-site
USD 150,000 - 210,000
PKI and Certificate Cybersecurity Engineer
PKI and Certificate Cybersecurity Engineer

Request Technology, LLC • Austin (TX)

On-site
USD 140,000 - 190,000
Senior PKI & Venafi Engineer — Certificate Lifecycle
Senior PKI & Venafi Engineer — Certificate Lifecycle

Themesoft Inc • Chicago (IL)

On-site
USD 120,000 - 160,000
PKI Cyber Security at Atlanta, GA
PKI Cyber Security at Atlanta, GA

VOLTO Consulting • Atlanta (GA)

Hybrid
USD 140,000 - 190,000
PKI Engineer - Active TS/SCI With CI Poly
PKI Engineer - Active TS/SCI With CI Poly

ENS Solutions, LLC • Riverdale Park (MD)

On-site
USD 120,000 - 150,000
Medical/Dental/Vision coverages
401k from day 1
PTO + 11 holidays
+5