Certificate Lifecycle/ PKI Engineer with Venafi Expertise
Lead workforce identity security initiatives, strengthening authentication, access management, Zero Trust, and enterprise cybersecurity solutions.
09th October, 2026
Job Description
Roles & Responsibilities
1. Identity-Centric Workforce Security
Lead the Identity-Centric Workforce Security team to develop authentication and access management solutions.
Drive the development of identity solutions, access patterns, and modern security protocols, practising Zero Trust, least privilege, and defence-in-depth principles.
Act as a Workforce Cybersecurity expert in solutions spanning end-user computing, proxy solutions, MFA, SSO, conditional access, passwordless authentication, YubiKey, biometric solutions, identity and governance scenarios, secrets management, automation, role-based access control, Privileged Identity Management, just-in-time access, etc.
2. AI Adoption and Identity Security
Demonstrate a good understanding of AI concepts, patterns, and their impact on the Identity and Access Management domain.
Participate in and contribute to AI adoption with an identity focus, including knowledge and understanding of Entra ID agentic identity, authentication flows, and patterns.
3. Identity & Access Management Solutions
Review and provide feedback on Identity and Access Management-related security solutions proposed by stakeholders, and provide consultation to partners and IT management.
Demonstrate in-depth knowledge and experience of Entra ID, EPM, Sentinel, Azure, and AWS Security.
Demonstrate knowledge of Okta, PingFederate, and entitlement management solutions.
Demonstrate strong knowledge of identity management on Azure AD, including OAuth, OIDC, SAML, SSO, MFA, Conditional Access Policies, Kerberos, LDAP, identity federation, etc.
Participate in solutions supporting token handling, OIDC/OAuth flows, authorisation patterns, identity federation, cloud architectures, cryptography, cloud-native services, and cloud security.
4. Application & API Security
Provide security solutions for Java-based microservices, React-based frontends, and Android/iOS-based mobile applications on Azure.
Apply hands-on experience in JWT, session handling, code signing, certificate authentication, TLS/SSL, API security, application registration, and application integration scenarios.
Demonstrate awareness of API Management, firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, RADIUS clusters, CDN, etc.
Demonstrate an understanding of application security, OWASP standards, security best practices, browser compatibility, storage, and cookies.
5. Cloud Security & Access Governance
Demonstrate a good understanding of Cloud Infrastructure Entitlement Management (CIEM) solutions to ensure smooth remediation of toxic combinations, high-risk entitlements, etc.
Demonstrate a deeper understanding of cloud security areas such as policies, RBAC, activities, identities, and Privileged Access Management.
Apply threat modelling concepts and methodologies.
Demonstrate an understanding of Docker security and container orchestration/Kubernetes.
6. Security Operations & Troubleshooting
- Support operations by troubleshooting complex identity scenarios, with hands-on experience using Sentinel, KQL, audit logs, etc.
Qualifications
Bachelor of Computer Science
Must-Have Technical/Functional Skills
1. PKI & Cryptography
Public Key Infrastructure (PKI)
X.509 Certificates
TLS/SSL
Certificate Authorities (CA)
Certificate Revocation Lists (CRL)
OCSP
Key Management
Hardware Security Modules (HSM)
Code Signing Certificates
Root and Intermediate CA Management
2. Venafi Expertise
Venafi Trust Protection Platform (TPP)
Venafi SaaS
Certificate Discovery
Certificate Automation
Venafi APIs
Adaptable Apps
Native Drivers
Reporting and Governance
Certificate Lifecycle Workflows
3. Platforms & Integrations
Windows IIS
Linux/Unix
Microsoft Azure
Azure Key Vault
Kubernetes
F5 Load Balancers
Apache
Tomcat
WebLogic
Kafka
Solace
Ping Federate
ServiceNow Integrations
4. DevOps & Automation
GitHub Actions
Azure DevOps
CI/CD Pipelines
PowerShell
Python
REST APIs
Ansible
Infrastructure Automation
5. Security Domains
Authentication
Authorization
Identity & Access Management
Secrets Management
Zero Trust Principles
Cloud Security
Security Monitoring
6. Additional Technical Requirements
Strong understanding of PKI architecture and certificate lifecycle processes.
Experience implementing certificate automation patterns and DevSecOps integrations.