10 - 15 years
35 - 40 Lacs
Posted:1 day ago|
Platform:
Hybrid
Full Time
Manage certificate lifecycle operations including issuance, renewal, revocation, and cross-certification within complex CA hierarchies.
Overall - At least 8+ years of experience in performing Digital Certificate Management Operations including:
Advanced understanding of X.509 certificates, CRLs, OCSP, and complex CA hierarchies (root, intermediate, issuing).
Expertise in certificate lifecycle management at scale, cross-certification, and trust model architectures.
Strong cryptographic knowledge including symmetric/asymmetric encryption, digital signatures, and hashing algorithms.
Proven experience with key management policies covering generation, escrow, rotation, and secure destruction.
Demonstrated ability to lead complex PKI operations and guide junior team members.
Excellent collaboration skills working with security, DevOps, infrastructure, and application teams.
Operationalize secure PKI systems integrated with IAM, SSO, MFA, and compliant with standards such as NIST, FIPS 140-2, and ISO 27001.
In-depth knowledge of networking protocols relevant to certificate distribution and validation: SSH, TLS/SSL, HTTPS, S/MIME, IPsec, VPNs, DNS, LDAP, HTTP.
Proven experience leveraging automation for certificate lifecycle management using scripting tools like PowerShell and Python
Hands-on experience with OpenSSL, Keytool, Certutil.
Familiarity with Microsoft AD CS, KeyFactor, Venafi, HashiCorp Vault, and EJBCA.
Experience managing Hardware Security Modules (HSMs) such as Thales and SafeNet.
ACME protocol for automated certificate lifecycle management
Maintain thorough logging and auditing of all certificate operations for security and compliance purposes.
Proven ability to troubleshoot complex certificate-related issues across diverse platforms.
Strong documentation skills to support audit readiness and operational transparency.
Python with libraries like cryptography, pyOpenSSL, requests, subprocess for PKI automation and API integration.
PowerShell for Windows PKI environments (e.g., AD CS).
Bash scripting for Linux-based PKI tools and OpenSSL automation.
Java for working with PKI tools such as EJBCA and integrations like HashiCorp Vault.
Other automation tools: Ansible, Terraform, and CI/CD systems (GitHub Actions, Jenkins).
RESTful API integrations for DigiCert, HashiCorp Vault, and ACME protocol platforms.
Randstad
Upload Resume
Drag or click to upload
Your data is secure with us, protected by advanced encryption.
Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.
We have sent an OTP to your contact. Please enter it below to verify.
Practice Python coding challenges to boost your skills
Start Practicing Python NowHyderabad, Bengaluru
35.0 - 40.0 Lacs P.A.
Kolkata, Hyderabad, Pune, Ahmedabad, Chennai, Bengaluru, Delhi / NCR, Mumbai (All Areas)
20.0 - 35.0 Lacs P.A.
5.0 - 7.0 Lacs P.A.
5.0 - 7.0 Lacs P.A.
4.0 - 6.0 Lacs P.A.
8.5 - 9.5 Lacs P.A.
Hyderabad, Bengaluru
15.0 - 25.0 Lacs P.A.
Hyderabad, Bengaluru
35.0 - 40.0 Lacs P.A.
Gurugram
3.6 - 4.8 Lacs P.A.
3.0 - 7.2 Lacs P.A.