At EY, we’re all in to shape your future with confidence.We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.Join EY and help to build a better working world.
Managed Service – IAM MS – PKI (MS PKI / Venafi) Staff
The Security Analyst / Security Senior Analyst role will be primarily responsible for supporting the enterprise Public Key Infrastructure (PKI) systems, with a core focus on Microsoft Active Directory Certificate Services (ADCS) and Venafi Trust Protection Platform. This role involves collaboration with application owners, security leads, and infrastructure teams to ensure the secure issuance, lifecycle management, and compliance of digital certificates across the organization
Key Requirements / Responsibilities:
- Assist in day-to-day operations of Microsoft PKI infrastructure, including the Root CA and Issuing CAs.
- Support certificate lifecycle management processes using Venafi, including discovery, issuance, renewal, and revocation.
- Manage certificate templates, CRL distribution, AIA locations, and related configurations for ADCS.
- Help automate certificate operations using PowerShell or Venafi workflows.
- Troubleshoot certificate enrollment issues across various platforms (Windows, Linux, network devices).
- Monitor PKI system health, certificate expiration, and potential vulnerabilities.
- Collaborate with application and platform teams to onboard services into Venafi for automated certificate management.
- Ensure compliance with cryptographic policies and audit requirements related to key usage and certificate issuance.
- Provide operational support during certificate-related incidents and outages.
- Participate in security assessments and internal audits involving PKI controls.
Relationships:
Education:
Bachelor or college degree in related field or equivalent work experience
Work Experience:
2-4 Years’ Experience
Skills Expertise
- Strong understanding of Microsoft PKI (ADCS), including Root and Issuing CA management, templates, key archival, and CRL management.
- Hands-on experience with Venafi Trust Protection Platform for certificate lifecycle automation.
- Familiarity with TLS/SSL certificate standards (X.509), key algorithms, and security best practices.
- Understanding of certificate-based authentication mechanisms and their integration with enterprise platforms.
- Basic scripting knowledge (e.g., PowerShell) for certificate automation and reporting.
- Experience integrating Venafi with load balancers, web servers, and applications.
- Good troubleshooting skills for resolving certificate errors and enrollment failures.
- Effective communication and collaboration skills to engage with internal and external stakeholders.
- Strong attention to detail and documentation practices for audit readiness and governance.
Good to have:
- Familiarity with Key Management concepts, digital signatures, and HSMs.
- Knowledge of integrating PKI with platforms like ADFS, Azure AD, or VPN appliances.
- Understanding of Certificate Policy and Certificate Practice Statements (CP/CPS).
Certification:
- Azure Fundamental (Az-900) (Good to have)
- Venafi Certified Administrator (Good to have)
- Microsoft Identity and Access Administrator (Sc-300) (Good to have)
Work Requirements:
- Willingness to be on call support engineer and work occasional overtime as required
- Willingness to work in 24*7 rotational shifts as required
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.