Wipro

PKI Certificate Lifecycle Management Engineer

Wipro

Greater Melbourne Area · Full Time

Be the first to apply

Experience
Any
Salary
—
Openings
1
Posted
3 days ago
Work mode
In office
Education
Bachelor's degree
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role Overview

The PKI Certificate Lifecycle Management (CLM) Engineer / Architect will lead the design, deployment, and ongoing administration of enterprise Public Key Infrastructure (PKI) and certificate lifecycle management solutions. This role is a key contributor to a multi-phase PKI enhancement project focused on deploying DigiCert One (SaaS) to enhance certificate governance, automation, and compliance organization-wide. The engineer will collaborate with security, infrastructure, and application teams throughout the program's duration and will provide business-as-usual and operational support after the platform goes live.

Key Duties

  • Lead configuration, enablement, and operational management of PKI CLM solutions within a SaaS environment.
  • Design and set up DigiCert One environments, including account configuration and tenant setup.
  • Deploy and administer the DigiCert One Trust Lifecycle Manager (TLM) for issuing, renewing, and revoking certificates.
  • Develop and manage enterprise PKI and Certificate Lifecycle platforms to ensure secure issuance and revocation of certificates.
  • Design, deploy, and manage Hardware Security Module (HSM) solutions to securely generate, store, backup, recover, and protect cryptographic keys.
  • Integrate DigiCert One, PKI platforms, and certificate authorities with HSM infrastructure ensuring compliance with corporate security policies.
  • Manage full HSM lifecycle operations including provisioning, clustering, firmware updates, key ceremonies, backup, escrow, and disaster recovery.
  • Ensure cryptographic keys for certificate authorities, code signing, mutual TLS and other security services are guarded using industry standards.
  • Troubleshoot and resolve issues related to HSM performance, incidents, and system integrations.
  • Administer and support ongoing availability of certificate management across the enterprise.
  • Create and update PKI policies, standards, and operational procedures aligned with security controls and compliance demands.
  • Collaborate with application, infrastructure, and security teams for certificate-based authentication and encryption solutions.
  • Execute certificate lifecycle operations including key management, rotation, and expiration.
  • Monitor PKI system performance, availability, and security status; troubleshoot and resolve certificate outages and configuration faults.
  • Maintain thorough documentation including runbooks and operational guides for PKI services.
  • Ensure adherence to internal security standards and regulatory requirements for cryptography and certificates.
  • Support audits, security reviews, and risk assessments related to PKI and certificate usage.
  • Provide expert guidance on PKI best practices and current industry standards.

Required Knowledge and Experience

  • Deep expertise in Public Key Infrastructure and Certificate Lifecycle Management operations.
  • Practical experience with DigiCert One platform, including Trust Lifecycle Manager.
  • Extensive experience managing the full lifecycle of digital certificates (issuance, renewal, revocation, expiration).
  • Strong understanding of X.509 certificates, TLS/SSL protocols, cryptographic algorithms, and key pairs.
  • Experience supporting large-scale PKI environments spanning hybrid (on-premises and cloud) infrastructures.
  • Knowledge of certificate discovery, automation techniques, and governance frameworks.
  • Advanced troubleshooting skills relating to certificate issues affecting applications and infrastructure.
  • Proficiency in Windows and Linux operating systems within secure contexts.
  • Comprehensive understanding of security controls, encryption standards, and compliance frameworks related to PKI.
  • Extensive hands-on experience managing Hardware Security Modules and enterprise key management.
  • Track record implementing HSM-backed PKI environments for Root and Intermediate Certificate Authorities and lifecycle platforms.
  • Expertise in HSM operations including key generation, secure storage, backup, recovery, partition management, and cryptographic processes.
  • Experience integrating PKI systems (such as DigiCert One, Microsoft ADCS, Entrust) with HSM technologies.
  • Knowledge of cryptographic standards and compliance related to HSM usage.
  • Experience handling operational support and troubleshooting for enterprise HSM infrastructure.

Education and Certifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or closely related fields, or equivalent practical experience.
  • Preferred certifications include DigiCert Certified Professional or any PKI-related certification.
  • Additional certifications such as Microsoft, AWS, or Azure security certifications with PKI focus, CompTIA Security+, CISSP, CISM, or CCSP are advantageous.

Preferred Skills

  • Experience using certificate automation tools, programming with PowerShell, Python, and utilizing REST APIs.
  • Familiarity with cryptographic standards and guidelines from bodies such as NIST, ISO, and CIS.
  • Experience supporting certificate-based authentication for various applications, devices, and services.
  • Exposure to vulnerability management, encryption compliance, or zero-trust frameworks.
  • Ability to collaborate effectively with cross-functional teams encompassing application, infrastructure, and security areas.
  • Proficiency with enterprise HSM platforms such as Thales Luna, Entrust nShield, Utimaco, AWS CloudHSM, Azure Managed HSM, or similar technologies.
  • Experience conducting CA key ceremonies, secure key transfers, and PKI disaster recovery with HSM-protected keys.
  • Knowledge of FIPS 140-2/140-3 validated cryptographic modules and regulations concerning key protection.

Minimum education

Bachelor's Degree

🤖
Online · instant AI help
Broxer