*Must be local to the East Coast. They will be looking for this person to ocassionally travel to there office in Bloomfield, CT.*
This Sr. PKI Engineer will be a member of the Infrastructure Security Engineering team responsible for managing and maintaining global PKI infrastructure.
Required Skills & Qualifications
- 8-10+ years’ experience in infrastructure security with deep expertise in PKI and certificate authority management
- Strong experience with Venafi, DigiCert or Entrust/Centigo platforms
- HSMs (Hardware Security Modules) to securely store cryptographic keys
- Microsoft Active Directory Certificate Services (ADCS)
- Management of certificate authorities and trust hierarchies
- Scripting languages (PowerShell, Python) for automation
- Deep understanding of TLS/SSL, encryption standards, and certificate lifecycle management
- Ability to operate in a regulated enterprise environment with high availability and compliance requirements
Responsibilities
- Manage and maintain PKI infrastructure, including certificate authorities (CAs) and hardware security modules (HSMs)
- Oversee certificate lifecycle operations—issuance, renewal, revocation, and automation of 57,000+ enterprise certificates
- Configure and manage Venafi (or similar tooling like DigiCert or Entrust/Centigo) for certificate orchestration and automation
- Support and maintain Active Directory Certificate Services (ADCS) and related Microsoft PKI components
- Automate certificate renewals and integrate tooling with internal applications and service management systems
- Provide subject matter expertise to developers and security engineers regarding encryption, key management, and certificate best practices
- Monitor compliance with internal policies and external standards for cryptographic management
- Troubleshoot complex PKI and certificate-related issues in production and non-production environments