Job Description
We’re looking for an experienced PKI Engineer who is responsible for the engineering, operation, and continuous improvement of SAS’s Public Key Infrastructure (PKI) services. You will be responsible for the day-to-day reliability, security, and automation of certificate lifecycle services that support internal and external platforms, applications, devices, and integrations.
This position works closely with Identity, Infrastructure, Operations, Application, and Hosting teams to ensure secure machine identity, encryption, and trust across on-premises and cloud environments, while operating within established enterprise architectures and security standards.
Primary Responsibilities
- Engineer, operate, and maintain ownership and usage of public, trusted certificate services.
- Engineer, operate, and maintain private enterprise PKI services, including Issuing CAs, certificate templates, enrollment services, CRLs, and OCSP responders
- Perform certificate lifecycle management activities: issuance, renewal, revocation, expiration monitoring,
and troubleshooting across both public and private services.
- Support certificate-based authentication for users, servers, applications, APIs, services, and devices
- Identify & Educate the stakeholders with appropriate certificate requirements
- Ensure high availability, backup, and recovery for PKI components.
- Implement and maintain certificate automation using approved tools, platforms and common standards (e.g., ServiceNow, DigiCert, ACME)
- Develop and maintain automation standards regarding integrations to reduce manual certificate operations
- Partner with DevOps and Platform teams to integrate PKI into CI/CD pipelines and infrastructure workflows
- Provide consistent direction and drive accountability to align with the SAS PKI program.
- Apply approved PKI security standards, CA hardening standards, and access controls
- Support compliance with SAS security standards, NIST guidance, applicable regulatory re
📌 PKI Engineer (Pune)
🏢 SAS
📍 Pune