- Design and maintain enterprise PKI architecture, including Root CA, Issuing CA, CRL, OCSP, HSM, and trust frameworks.
- Develop certificate governance standards, policies, and cryptographic control frameworks.
- Architect highly available and resilient PKI and CLM platforms.
- Drive enterprise machine identity and certificate management strategy.
- Design and administer Venafi Trust Protection Platform (TPP).
- Define onboarding standards, workflows, policies, reporting, discovery jobs, and access models.
- Architect integrations between Venafi and enterprise applications, cloud services, and security platforms.
- Lead Venafi platform upgrades, enhancements, and optimization initiatives.
Job Description
Must Have Technical/Functional Skills
PKI & Security Architecture
- Design and maintain enterprise PKI architecture, including Root CA, Issuing CA, CRL, OCSP, HSM, and trust frameworks.
- Develop certificate governance standards, policies, and cryptographic control frameworks.
- Architect highly available and resilient PKI and CLM platforms.
- Drive enterprise machine identity and certificate management strategy.
- Design and administer Venafi Trust Protection Platform (TPP).
- Define onboarding standards, workflows, policies, reporting, discovery jobs, and access models.
- Architect integrations between Venafi and enterprise applications, cloud services, and security platforms.
- Lead Venafi platform upgrades, enhancements, and optimization initiatives.
Venafi Platform Architecture
- Design and administer Venafi Trust Protection Platform (TPP).
- Define onboarding standards, workflows, policies, reporting, discovery jobs, and access models.
- Architect integrations between Venafi and enterprise applications, cloud services, and security platforms.
- Lead Venafi platform upgrades, enhancements, and optimization initiatives.
Roles & Responsibilities
Certificate Lifecycle Automation
- Architect automated certificate provisioning and renewal solutions.
- Design automation frameworks using:
- Venafi APIs
- vCert
- PowerShell
- Python
- Ansible
- GitHub Actions
- Azure DevOps o CI/CD pipelines
- Drive adoption of certificate automation across enterprise application portfolios.
- Application & Cloud Integration
- Lead application onboarding into CLM services.
- Support certificate deployment and automation across:
- Windows Server
- Linux/Unix
- IIS
- Apache o Tomcat o WebLogic
- Kubernetes
- Azure
- AWS
- F5 Load Balancers
- Kafka
- Solace
- PingFederate
- Provide architecture guidance and troubleshooting support for complex trust and certificate-related issues.
Governance & Compliance
- Ensure compliance with NIST, PCI-DSS, SOX, ISO 27001, FedRAMP, and enterprise security standards.
- Conduct cryptographic risk assessments and certificate posture reviews.
- Define certificate ownership models and governance processes.
- Support audits and regulatory compliance activities
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related discipline.
- 10+ years of Information Security experience.
- 5+ years of hands-on PKI architecture experience.
- 5+ years of Venafi Trust Protection Platform experience.
- Strong expertise in:
- X.509 Certificates
- TLS/SSL
- PKI
- CLM o CRL/OCSP
- HSM Technologies
- Digital Signatures
- Cryptographic Key Management
- Experience designing PKI solutions in Azure and AWS environments.
- Strong scripting skills using PowerShell and Python.
Preferred Qualifications
- CISSP, CISM, CCSP, or equivalent certification.
- Venafi Certified Professional/Architect certification.
- Experience with:
- Keyfactor
- DigiCert
- Entrust
- Microsoft ADCS
- HashiCorp Vault
- Azure Key Vault
- AWS Certificate Manager
- Experience operating in BFSI or other highly regulated environments.
Technical Skills PKI & Cryptography
- PKI Architecture
- X.509 Certificates
- TLS/SSL
- PKCS Standards
- Digital Signatures
- HSM Integration
- CRL / OCSP Venafi
- Venafi TPP
- Venafi TLS Protect
- Certificate Discovery
- Policy Management
- Workflow Automation
- Reporting & Governance Cloud & DevOps
- Azure
- AWS
- Kubernetes
- GitHub Actions
- Azure DevOps
- CI/CD Pipelines
- Infrastructure as Code Programming & Automation
- PowerShell
- Python
- REST APIs
- Ansible Leadership Expectations
- Serve as the PKI and Machine Identity SME.
- Provide technical leadership to engineering and operations teams.
- Develop enterprise PKI roadmaps and modernization strategies.
- Mentor engineers and establish best practices for certificate lifecycle management.
- Drive Zero Trust and identity-centric security initiatives.
TCS Employee Benefits Summary
- Discretionary Annual Incentive.
- Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans.
- Family Support: Maternal & Parental Leaves.
- Insurance Options: Auto & Home Insurance, Identity Theft Protection.
- Convenience & Professional Growth: Commuter Benefits & Certification & Training Reimbursement.
- Time Off: Vacation, Time Off, Sick Leave & Holidays.
- Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing.
- Salary Range: $120,000 - $130,000 a year
Qualifications:
BACHELOR OF COMPUTER SCIENCE