
Innocore
Actively Hiring
- B2B
- Early StageStartup in initial stages
Public Key Infrastructure (PKI) & Encryption Engineer
- |3 years of exp
- |Contract
Posted: 4 days ago• Recruiter recently active
Job Location
Remote Work Policy
In office
Visa Sponsorship
Not Available
RelocationAllowed
Skills
Python
Nginx
DevOps
IIS
REST APIs
PKI
Azure
PowerShell
AWS
f5
Hashicorp Vault
DigiCert
Tls/ssl
Venafi
Azure Key Vault
Infrastructure As Code (IaC)
Sectigo
Keyfactor
ACME
X.509 Certificates
Certificate Renewal
Microsoft ADCS
Certificate Rotation
Certificate Authorities (CA)
Certificate Issuance
Certificate Enrollment
Certificate Revocation
Platform-Specific APIs
About the job
Responsibilities:
- Design, implement, and support enterprise PKI and X.509 certificate infrastructure, including Certificate Authorities (CA), certificate issuance, enrollment, renewal, rotation, revocation, and TLS/SSL certificate management.
- Administer and integrate enterprise certificate lifecycle management platforms such as Keyfactor, Venafi, DigiCert, Sectigo, and Microsoft ADCS across application, infrastructure, and cloud environments.
- Develop PowerShell and Python automation using REST APIs, ACME, and platform-specific APIs to automate certificate discovery, provisioning, renewal, rotation, revocation, compliance monitoring, and reporting.
- Perform root cause analysis and troubleshooting of certificate, TLS/SSL, encryption, trust-chain, authentication, and connectivity issues across systems such as F5, NGINX, IIS, and enterprise applications.
- Design secure, scalable PKI and encryption solutions across Azure/AWS and on-premises environments, leveraging Azure Key Vault, HashiCorp Vault, infrastructure-as-code, and DevOps practices where applicable.
- Partner with Security, Infrastructure, Cloud, and DevOps teams to establish certificate security standards, encryption controls, automation, monitoring, technical risk mitigation, and reusable PKI solutions while reducing technical debt and operational overhead.
Requirements:
- 3–5+ years of hands-on experience in PKI, certificate management, encryption, cybersecurity, or related infrastructure engineering.
- Strong knowledge of PKI architecture, X.509 certificates, TLS/SSL, certificate chains, CA/RA concepts, certificate issuance, renewal, rotation, and revocation.
- Experience with enterprise Certificate Lifecycle Management (CLM) platforms such as Keyfactor, Venafi, DigiCert, Sectigo, or Microsoft ADCS.
- Strong scripting and automation skills using PowerShell and/or Python, including REST APIs and certificate-management automation.
- Experience troubleshooting TLS/SSL, certificate trust, authentication, encryption, and connectivity issues across enterprise infrastructure and applications.
- Understanding of cloud security, DevOps, CI/CD, Infrastructure as Code (IaC), secrets management, and automated certificate deployment.
Education:
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering or a related field.
About the company
- B2B
- Early StageStartup in initial stages