Certificate Lifecycle/ PKI Engineer with Venafi Expertise

Tata Consultancy Services

Chicago (IL)

On-site

USD 120,000 - 130,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Discretionary annual incentive
Comprehensive medical coverage
401K plan

Job summary

Tata Consultancy Services is seeking a security-focused professional in Chicago to lead an Identity-centric Workforce Security team. You will develop authentication and access management solutions, and shape identity patterns and modern security protocols including Zero Trust principles.

The role requires deep PKI knowledge, enterprise-scale certificate management, and collaboration with IT Management to drive secure adoption across platforms such as Azure, AWS, and on-prem environments.

Qualifications

  • Strong PKI and certificate lifecycle knowledge.
  • Experience with certificate automation patterns and DevSecOps integrations.
  • Experience supporting enterprise-scale certificate environments.

Responsibilities

  • Lead Identity centric Workforce Security team to develop authentication and access management solutions.
  • Drive development of identity solutions, access patterns, and modern security protocols including Zero Trust.

Skills

PKI & Cryptography
Identity & Access Management
Cloud Security
OAuth/OIDC/SAML
JWT/Token handling
Zero Trust
Entra ID/Azure AD
Security in CI/CD
Kubernetes
Threat modeling

Education

Bachelor of Computer Science

Tools

Venafi
Okta
PingFederate
Azure/AWS Security
CI/CD Tools

Job description

  • Strong understanding of PKI architecture and certificate lifecycle processes.
  • Experience implementing certificate automation patterns and DevSecOps integrations.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Excellent communication and stakeholder management skills.
  • Lead Identity centric Workforce Security team to develop authentication and access management solutions
  • Drive the development of identity solutions, access patterns, modern security protocols, practicing Zero trust, least privileged, defense in depth principles
  • Good understanding of AI concepts, Patterns and impact on identity and access management domain
  • Participate and engage in AI adoption with Identity focus, knowledge and understanding of Entra ID agentic Identity, authentication flows and Patterns
  • Review and provide feedback on Identity and access management related security solutions proposed by stakeholders and can provide consultation to the partners and IT Management
  • In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, AWS Security
  • Knowledge on Okta, PingFederate, Entitlement management solutions
  • Strong knowledge on Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, Conditional access policies, MFA, Ker beros, LDAP, Identity Federations etc.
  • Experience in providing security solutions for Java based Micro services, React based frontends and Android/iOS based mobile applications on the Azure
  • Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc.
  • Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure smooth remediation of toxic combinations, high risk entitlements etc.
  • Understanding and application of threat modeling concepts and methodologies
  • Acts as Workforce cybersecurity expert to in solutions spanning end user computing, proxy solutions, MFA, SSO, conditional accesses, Passwordless, Yubikey, bio-metric solutions, identity and governance scenarios, Secrets Management, automation, role based access control, Privileged identity management, Just in time accesses etc.
  • Participates in solutions to support- token handling, OIDC/ OAuth flows, authorization patterns, identity federation, cloud architectures, cryptography, cloud native services, cloud security etc.
  • Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, privileged access management etc.
  • Ability to support operations in troubleshooting complex identity scenarios with hands-on experience on Sentinel/KQL/Audit logs etc.
  • Good understanding of concepts related to docker Security, container orchestrations/Kubernetes
Job Description
Must Have Technical/Functional Skills
  • PKI & Cryptography
  • Public Key Infrastructure (PKI)
  • X.509 Certificates
  • TLS/SSL
  • Certificate Authorities (CA)
  • Certificate Revocation Lists (CRL)
  • OCSP
  • Key Management
  • Hardware Security Modules (HSM)
  • Code Signing Certificates
  • Root and Intermediate CA Management
  • Venafi Expertise
  • Venafi Trust Protection Platform (TPP)
  • Venafi SaaS
  • Certificate Discovery
  • Certificate Automation o Venafi APIs
  • Adaptable Apps
  • Native Drivers
  • Reporting and Governance
  • Certificate Lifecycle Workflows
  • Platforms & Integrations
  • Windows IIS
  • Linux/Unix
  • Microsoft Azure
  • Azure Key Vault
  • Kubernetes
  • F5 Load Balancers
  • Apache
  • Tomcat
  • WebLogic
  • Kafka
  • Solace
  • Ping Federate
  • ServiceNow Integrations
  • DevOps & Automation
  • GitHub Actions
  • Azure DevOps
  • CI/CD Pipelines
  • PowerShell
  • Python
  • REST APIs
  • Ansible
  • Infrastructure Automation
  • Security Domains
  • Authentication
  • Authorization
  • Identity & Access Management
  • Secrets Management
  • Zero Trust Principles
  • Cloud Security
  • Security Monitoring
  • Strong understanding of PKI architecture and certificate lifecycle processes.
  • Experience implementing certificate automation patterns and DevSecOps integrations.
  • Experience supporting enterprise-scale certificate environments.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Excellent communication and stakeholder management skills.
Roles & Responsibilities
  • Lead Identity centric Workforce Security team to develop authentication and access management solutions
  • Drive the development of identity solutions, access patterns, modern security protocols, practicing Zero trust, least privileged, defense in depth principles
  • Good understanding of AI concepts, Patterns and impact on identity and access management domain
  • Participate and engage in AI adoption with Identity focus, knowledge and understanding of Entra ID agentic Identity, authentication flows and Patterns
  • Review and provide feedback on Identity and access management related security solutions proposed by stakeholders and can provide consultation to the partners and IT Management
  • In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, AWS Security
  • Knowledge on Okta, PingFederate, Entitlement management solutions
  • Strong knowledge on Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, Conditional access policies, MFA, Ker beros, LDAP, Identity Federations etc.
  • Experience in providing security solutions for Java based Micro services, React based frontends and Android/iOS based mobile applications on the Azure
  • Hands-of experience in JWT, session handling, Code signing, Certificate authentication, TLS/SSL, API Security, Application registration, application integration scenarios etc.
  • Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc.
  • Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure smooth remediation of toxic combinations, high risk entitlements etc.
  • Understanding and application of threat modeling concepts and methodologies
  • Understanding of Applications security, OWASP standards, security best practices, browser compatibilities/storages/cookies
  • Acts as Workforce cybersecurity expert to in solutions spanning end user computing, proxy solutions, MFA, SSO, conditional accesses, Passwordless, Yubikey, bio-metric solutions, identity and governance scenarios, Secrets Management, automation, role based access control, Privileged identity management, Just in time accesses etc.
  • Participates in solutions to support- token handling, OIDC/ OAuth flows, authorization patterns, identity federation, cloud architectures, cryptography, cloud native services, cloud security etc.
  • Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, privileged access management etc.
  • Ability to support operations in troubleshooting complex identity scenarios with hands-on experience on Sentinel/KQL/Audit logs etc.
  • Good understanding of concepts related to docker Security, container orchestrations/Kubernetes
TCS Employee Benefits Summary
  • Discretionary Annual Incentive.
  • Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans.
  • Family Support: Maternal & Parental Leaves.
  • Insurance Options: Auto & Home Insurance, Identity Theft Protection.
  • Convenience & Professional Growth: Commuter Benefits & Certification & Training Reimbursement.
  • Time Off: Vacation, Time Off, Sick Leave & Holidays.
  • Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing.
  • Salary Range: $120,000 - $130,000 a year
Qualifications:

BACHELOR OF COMPUTER SCIENCE

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. PKI Security Engineer
Sr. PKI Security Engineer

Tata Consultancy Services • Atlanta (GA)

On-site
USD 100,000 - 120,000
Discretionary incentive
Medical coverage
Dental & Vision
+6
Entra ID Team Lead
Entra ID Team Lead

Tata Consultancy Services • Chicago (IL)

On-site
USD 120,000 - 130,000
Discretionary incentive
Medical coverage
Parental leaves
+5
AI Identity Architect
AI Identity Architect

Tata Consultancy Services • Chicago (IL)

On-site
USD 130,000 - 140,000
Discretionary Annual Incentive
Comprehensive Medical Coverage
Family Support
+4
Senior Security Engineer
Senior Security Engineer

SHEIN • Los Angeles (CA)

On-site
USD 120,000 - 160,000
Bonus and RSU eligibility
Healthcare benefits
401(k) Savings Plan with company match
+2
Cloud Security & Automation Engineer (IaC Lead)
Cloud Security & Automation Engineer (IaC Lead)

Tata Consultancy Services • Irving (TX)

On-site
USD 110,000 - 135,000
Discretionary incentive
Medical coverage
Parental leave
+12
IAM/PAM Architect
IAM/PAM Architect

Tata Consultancy Services • New York (NY)

On-site
USD 120,000 - 130,000
Discretionary Annual Incentive
Medical Coverage
Parental Leaves
+3
Entra ID Engineer
Entra ID Engineer

Tata Consultancy Services • Indianapolis (IN)

On-site
USD 110,000 - 130,000
Discretionary Annual Incentive
Comprehensive Medical Coverage
Family Leave
+7
Entra ID Engineer
Entra ID Engineer

Tata Consultancy Services • Chicago (IL)

On-site
USD 120,000 - 130,000
Annual incentive
Medical coverage
401K plan
+2
Ping security Analyst
Ping security Analyst

Tata Consultancy Services • Seattle (WA)

On-site
USD 120,000 - 150,000
Annual incentive
Medical coverage
Parental leaves
+3
Senior Network Security Engineer
Senior Network Security Engineer

Ignite IT, LLC • Suitland (MD)

On-site
USD 100,000 - 130,000
Health insurance
Flexible schedule
401(k) matching
+2