Participates in the following areas in the deployment and integration of relevant tool sets:
Primary (must have any 2):
Certificate Management (AppViewX)
Secrets Management (HashiCorp Vault)
Secondary (valuable to have):
CyberArk (Privileged Access Management)
Identity Services (Sailpoint)
Single Sign On (Ping Identity)
Database Access Monitoring (Imperva)
Hardware Security Modules (Thales Payshield HSM/Luna HSM)
Cipher Trust Manager (CTM) and CTVL (Tokenization Engine)
Detailed requirement for Primary toolset AppViewX
Certificate Lifecycle Management: Expert-level knowledge of automated renewal, revocation, and provisioning.
Protocol Understanding: Deep comprehension of SSL/TLS, SSH, X.509 certificates, CSR generation, and Public Key Infrastructure (PKI) hierarchies.
CA Integration: Hands-on experience integrating and managing external and internal Certificate Authorities (e.g., Microsoft CA, Venafi, DigiCert, Entrust)
OS & Platforms: Robust command of Linux and Windows Server administration.
Scripting Languages: Proficiency in Python and REST APIs for creating custom integrations and automating manual workflows.
Network Infrastructure: Basic understanding of Load Balancers, Firewalls, and Web Servers (e.g., F5 BIG-IP, NGINX, Apache, IIS) to which certificates are deployed.
Detailed requirement for Primary toolset – HashiCorp
Design, implement and sustain a centralized secrets management system using HashiCorp Vault
Installation and Operationalization of HashiCorp Vault and Consul/Raft storage components both OnPrem and Cloud
Hands on experience in HashiCorp Vault integration with target application for secrets management using wide-ranging auth methods – LDAP, AppRole, Kubernetes
Experienced as a security professional in installing, managing & monitoring of HashiCorp Vault
Hands on experience in configuration and migration of storage from Consult to Raft (Integrated storage)
I