30 Jul
|
GRM Technologies
|
Tamil Nadu
30 Jul
GRM Technologies
Tamil Nadu
About the Role
We are seeking an experienced Senior PKI & HSM Architect to join our Cyber Security team and lead the implementation, administration, and operational management of enterprise Public Key Infrastructure (PKI) environments.
The ideal candidate will possess solid expertise in Keyfactor EJBCA Enterprise, Keyfactor Command (Certificate Lifecycle Management), Thales Luna HSM, and Utimaco CryptoServer HSM, with hands-on experience delivering highly available, secure, and compliant PKI solutions for enterprise, government, banking, telecom, or critical infrastructure environments.
This role involves designing, implementing, maintaining, and supporting mission-critical PKI environments while ensuring compliance with global security standards and industry best practices.
Key Responsibilities
Public Key Infrastructure (PKI)
- Design, implement, configure, and maintain enterprise PKI environments using Keyfactor EJBCA Enterprise.
- Deploy and administer Root CA, Issuing CA, Registration Authority (RA), Validation Authority (VA), OCSP Responders, and CRL Distribution services.
- Configure Certificate Profiles, End Entity Profiles, Approval Profiles, Publishers, Authentication Modules, and Role-Based Access Control (RBAC).
- Manage the complete certificate lifecycle, including issuance, renewal, suspension, revocation, archival, and expiration management.
- Configure and maintain High Availability (HA) and Disaster Recovery (DR) PKI environments.
- Perform PKI upgrades, migrations, patch management, backup, restoration, and performance optimization.
Certificate Lifecycle Management (CLM)
- Install, configure, and administer Keyfactor Command.
- Implement certificate discovery, enrollment, renewal, revocation, automation, and lifecycle management.
- Configure certificate management protocols, including ACME, SCEP, EST, CMP, and REST APIs.
- Integrate certificate lifecycle management with enterprise applications, Active Directory, cloud platforms, DevOps pipelines, and network devices.
- Monitor certificate inventory and ensure proactive renewal and compliance across the enterprise.
Hardware Security Modules (HSM)
- Deploy, configure, and administer Thales Luna Network HSM and Utimaco CryptoServer HSM.
- Configure HSM partitions, security policies, client authentication,
backup, replication, firmware upgrades, and high availability.
- Manage cryptographic keys throughout their lifecycle, including generation, storage, backup, recovery, rotation, archival, and secure destruction.
- Conduct Root CA and Issuing CA key ceremonies following industry best practices and compliance requirements.
- Perform HSM health monitoring, capacity planning, troubleshooting, and operational support.
Security Operations
- Monitor PKI infrastructure availability, performance, and security.
- Perform incident response, troubleshooting, root cause analysis, and problem resolution.
- Participate in change management, production releases, maintenance windows, and disaster recovery testing.
- Maintain operational documentation, runbooks, SOPs, and knowledge base articles.
Compliance & Governance
Ensure PKI environments comply with applicable industry standards and regulatory requirements, including:
- RFC 5280
- RFC 3647
- CAB Forum Baseline Requirements
- WebTrust for Certification Authorities
- ETSI EN 319 Series
- eIDAS
- ISO/IEC 27001
- NIST SP 800-53
- NIST SP 800-57
- FIPS 140-2 / FIPS 140-3
Required Technical Skills
PKI Platforms
- Keyfactor EJBCA Enterprise
- Keyfactor Command (Certificate Lifecycle Management)
- Microsoft Active Directory Certificate Services (ADCS)
Hardware Security Modules
- Thales Luna Network HSM
- Utimaco CryptoServer HSM
- PKCS#11 Integration
- Java Cryptography Extension (JCE)
Operating Systems
- Red Hat Enterprise Linux
- Rocky Linux
- Ubuntu Linux
- Windows Server
Databases
- PostgreSQL
- Oracle
- Microsoft SQL Server
Web & Middleware
- WildFly
- Apache HTTP Server
- NGINX
Scripting & Automation
- Bash
- PowerShell
- Python
Infrastructure
- DNS
- TCP/IP
- TLS/SSL
- LDAP
- Load Balancers
- Reverse Proxies
- VMware
- Microsoft Azure
- Amazon Web Services (AWS)
Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, Engineering, or a related discipline.
- 510+ years of hands-on experience in Enterprise PKI administration and engineering.
- Strong experience implementing and supporting Keyfactor EJBCA Enterprise and Keyfactor Command.
- Hands-on experience with Thales Luna HSM and Utimaco CryptoServer HSM.
- Experience in designing High Availability and Disaster Recovery PKI architectures.
- Strong understanding of PKI, X.509 certificates, cryptographic protocols, certificate lifecycle management, and enterprise security architecture.
Preferred Certifications
- Keyfactor EJBCA Certified Engineer
- Keyfactor Command Administrator
- Thales Luna HSM Certification
- Utimaco CryptoServer Certification
- CISSP
- CISM
- CISA
- RHCE
- Microsoft Azure Security Engineer
- AWS Security Specialty
Preferred Industry Experience
Experience in one or more of the following sectors will be an advantage:
- Government & National PKI Programs
- Banking & Financial Services
- Telecommunications
- Healthcare
- Critical Infrastructure
- Qualified Trust Service Providers (QTSP)
- Digital Identity & Trust Services
- Cloud Security
- Smart City Programs
Travel Requirement
The successful candidate should be flexible to travel locally and internationally as required to support client engagements, solution implementation, system commissioning, operational support, knowledge transfer, and other project-related activities.
What We Offer
- Opportunity to work on large-scale national and enterprise PKI implementations.
- Exposure to cutting-edge cybersecurity, digital identity, and cryptographic technologies.
- Collaborative work environment with highly experienced cybersecurity professionals.
- Competitive salary and benefits package.
- Professional development and certification opportunities.
- Long-term career growth within a rapidly expanding cybersecurity organization.
Apply Now
If you are passionate about Public Key Infrastructure, cryptography, certificate lifecycle management, and enterprise security, we invite you to join our team and contribute to the delivery of secure, resilient, and scalable PKI solutions for mission-critical environments.
📌 Senior PKI & HSM Engineer (Keyfactor EJBCA, Command CLM) (Tamil Nadu)
🏢 GRM Technologies
📍 Tamil Nadu