- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
We are looking for a seasoned PKI Engineer to create, manage, and support Public Key Infrastructure (PKI) environments in Singapore. This position involves overseeing the entire lifecycle of digital certificates, managing cryptographic technologies, automating PKI tasks, ensuring security compliance, and integrating PKI systems with enterprise applications.
Key Responsibilities
- Architect, deploy and maintain PKI infrastructure components including Certification Authority (CA), Registration Authority (RA), and certificate management platforms.
- Oversee the full digital certificate lifecycle such as issuance, renewal, revocation, replacement, and monitoring of expirations.
- Implement and support SSL/TLS certificates across a variety of systems including servers, applications, databases, APIs, middleware, and networking devices.
- Handle cryptographic key management, hardware security modules (HSMs), certificate inventory tracking, and compliance reporting.
- Develop automation workflows for certificate provisioning and renewals utilizing scripting, APIs, and other tools.
- Integrate PKI solutions with critical enterprise platforms including monitoring tools, IT service management, security frameworks, and secrets management systems.
- Diagnose and resolve issues related to certificates, authentication, encryption, and trust chains.
- Ensure PKI governance by maintaining standards, procedural documentation, and fulfilling audit obligations.
- Contribute to modernization projects involving advanced protocols like TLS 1.3 and Post-Quantum Cryptography preparedness.
Required Qualifications and Skills
- Extensive knowledge of PKI concepts including X.509 certificates, CA/RA roles, Certificate Revocation Lists (CRL), Online Certificate Status Protocol (OCSP), and SSL/TLS technologies.
- Experience working with PKI and Certificate Lifecycle Management platforms such as Microsoft Active Directory Certificate Services (ADCS), DigiCert, Entrust, Keyfactor, Venafi, or AppViewX.
- Familiarity with cryptographic standards including RSA, Elliptic Curve Cryptography (ECC), AES, SHA-2 and SHA-3 hashing algorithms, along with TLS protocols 1.2 and 1.3.
- Practical exposure to both Windows and Linux server environments.
- Proficiency in scripting languages such as PowerShell, Python, or shell scripting for automation tasks.
- Understanding of hardware security modules (HSMs), role-based access control (RBAC), security policies, and compliance auditing.
- Experience integrating PKI with enterprise infrastructure and security applications.
- Background in cybersecurity or infrastructure security related to PKI.
Preferred Qualifications
- Industry certifications like CISSP, CISM, Security+, or PKI-specific credentials.
- Expertise in certificate lifecycle management and automation tools.
- Experience working in regulated environments or managing large-scale enterprise PKI deployments.