PKI Certificate Lifecycle Management Engineer
Greater Melbourne Area · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 3 days ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
The PKI Certificate Lifecycle Management (CLM) Engineer / Architect will lead the design, deployment, and ongoing administration of enterprise Public Key Infrastructure (PKI) and certificate lifecycle management solutions. This role is a key contributor to a multi-phase PKI enhancement project focused on deploying DigiCert One (SaaS) to enhance certificate governance, automation, and compliance organization-wide. The engineer will collaborate with security, infrastructure, and application teams throughout the program's duration and will provide business-as-usual and operational support after the platform goes live.
Key Duties
- Lead configuration, enablement, and operational management of PKI CLM solutions within a SaaS environment.
- Design and set up DigiCert One environments, including account configuration and tenant setup.
- Deploy and administer the DigiCert One Trust Lifecycle Manager (TLM) for issuing, renewing, and revoking certificates.
- Develop and manage enterprise PKI and Certificate Lifecycle platforms to ensure secure issuance and revocation of certificates.
- Design, deploy, and manage Hardware Security Module (HSM) solutions to securely generate, store, backup, recover, and protect cryptographic keys.
- Integrate DigiCert One, PKI platforms, and certificate authorities with HSM infrastructure ensuring compliance with corporate security policies.
- Manage full HSM lifecycle operations including provisioning, clustering, firmware updates, key ceremonies, backup, escrow, and disaster recovery.
- Ensure cryptographic keys for certificate authorities, code signing, mutual TLS and other security services are guarded using industry standards.
- Troubleshoot and resolve issues related to HSM performance, incidents, and system integrations.
- Administer and support ongoing availability of certificate management across the enterprise.
- Create and update PKI policies, standards, and operational procedures aligned with security controls and compliance demands.
- Collaborate with application, infrastructure, and security teams for certificate-based authentication and encryption solutions.
- Execute certificate lifecycle operations including key management, rotation, and expiration.
- Monitor PKI system performance, availability, and security status; troubleshoot and resolve certificate outages and configuration faults.
- Maintain thorough documentation including runbooks and operational guides for PKI services.
- Ensure adherence to internal security standards and regulatory requirements for cryptography and certificates.
- Support audits, security reviews, and risk assessments related to PKI and certificate usage.
- Provide expert guidance on PKI best practices and current industry standards.
Required Knowledge and Experience
- Deep expertise in Public Key Infrastructure and Certificate Lifecycle Management operations.
- Practical experience with DigiCert One platform, including Trust Lifecycle Manager.
- Extensive experience managing the full lifecycle of digital certificates (issuance, renewal, revocation, expiration).
- Strong understanding of X.509 certificates, TLS/SSL protocols, cryptographic algorithms, and key pairs.
- Experience supporting large-scale PKI environments spanning hybrid (on-premises and cloud) infrastructures.
- Knowledge of certificate discovery, automation techniques, and governance frameworks.
- Advanced troubleshooting skills relating to certificate issues affecting applications and infrastructure.
- Proficiency in Windows and Linux operating systems within secure contexts.
- Comprehensive understanding of security controls, encryption standards, and compliance frameworks related to PKI.
- Extensive hands-on experience managing Hardware Security Modules and enterprise key management.
- Track record implementing HSM-backed PKI environments for Root and Intermediate Certificate Authorities and lifecycle platforms.
- Expertise in HSM operations including key generation, secure storage, backup, recovery, partition management, and cryptographic processes.
- Experience integrating PKI systems (such as DigiCert One, Microsoft ADCS, Entrust) with HSM technologies.
- Knowledge of cryptographic standards and compliance related to HSM usage.
- Experience handling operational support and troubleshooting for enterprise HSM infrastructure.
Education and Certifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or closely related fields, or equivalent practical experience.
- Preferred certifications include DigiCert Certified Professional or any PKI-related certification.
- Additional certifications such as Microsoft, AWS, or Azure security certifications with PKI focus, CompTIA Security+, CISSP, CISM, or CCSP are advantageous.
Preferred Skills
- Experience using certificate automation tools, programming with PowerShell, Python, and utilizing REST APIs.
- Familiarity with cryptographic standards and guidelines from bodies such as NIST, ISO, and CIS.
- Experience supporting certificate-based authentication for various applications, devices, and services.
- Exposure to vulnerability management, encryption compliance, or zero-trust frameworks.
- Ability to collaborate effectively with cross-functional teams encompassing application, infrastructure, and security areas.
- Proficiency with enterprise HSM platforms such as Thales Luna, Entrust nShield, Utimaco, AWS CloudHSM, Azure Managed HSM, or similar technologies.
- Experience conducting CA key ceremonies, secure key transfers, and PKI disaster recovery with HSM-protected keys.
- Knowledge of FIPS 140-2/140-3 validated cryptographic modules and regulations concerning key protection.
Minimum education
Bachelor's Degree