23 Aug
|
3 Point HRM
|
Gurugram
23 Aug
3 Point HRM
Gurugram
Job Title: Cloud Solutions Engineer / PKI
Location : Gurugram
Shift : 3 PM - 10 PM, hybrid
Role Summary
Join the Cloud Solutions Team as a Cloud Solutions Engineer / PKI responsible for designing, engineering, and operating enterprise public key infrastructure (PKI) and the complete digital certificate lifecycle. You will own certificate discovery, issuance, deployment, renewal, expiration monitoring, revocation, inventory, audit, and automation, the critical infrastructure that protects secure communications, applications, and trusted identities across hybrid cloud and on-premises environments. Working with the Senior Cloud Solutions Manager, you will build and maintain the systems, automation, and processes that ensure every certificate in the enterprise is managed, monitored, and rotated reliably and securely.
Core Responsibilities
- Own the complete digital certificate lifecycle across the enterprisediscovery, inventory, requests, validation, issuance, enrollment, deployment, renewal, expiration monitoring, revocation, replacement, retirement, and audit reporting.
- Architect and administer certificate authorities, certificate templates, enrollment policies, trust chains, certificate stores, and role-based access controls in accordance with enterprise security standards and compliance requirements.
- Engineer and maintain automation for certificate discovery, enrollment, issuance, deployment, renewal, expiration alerting, revocation, inventory reconciliation, and compliance reporting using PowerShell, APIs, or workflow orchestration across cloud and on-premises platforms.
- Integrate PKI across the enterprise, provisioning certificates to Azure Key Vault, Microsoft 365, Exchange Online, Windows servers, network devices, load balancers, applications, and services that depend on TLS certificates, code signing, digital identities, and secure machine-to-machine communication.
- Monitor PKI health, certificate expiration, and security events; diagnose and resolve trust, chain, enrollment, revocation, and TLS issues; perform root-cause analysis to prevent certificate outages and security incidents.
- Maintain PKI documentation, operating procedures, certificate standards, ownership records, disaster recovery processes, audit evidence, and access controls aligned with organizational security and compliance requirements.
- Serve as the subject matter expert for all certificate and PKI issues; provide tier 2 and tier 3 escalation support and implement preventive improvements based on incident analysis.
Required Expertise
- 5+ years of hands-on experience designing, engineering, and operating enterprise PKI, including certificate authorities, certificate lifecycle platforms, enrollment systems, trust chains, certificate stores, renewal automation, revocation management, monitoring, troubleshooting, access controls, and audit requirements.
- Deep proficiency with PowerShell and/or Python for PKI automation, scripting, API integration, and workflow orchestration.
- Expert-level understanding of cryptography fundamentals, including asymmetric encryption, digital signatures, X.509 certificate formats (DER, PEM, PKCS#12), certificate chains, trust models, TLS/SSL protocols, and certificate validation.
- Demonstrated experience with enterprise certificate lifecycle management platforms (DigiCert, Entrust, Venafi, or similar) for certificate issuance, renewal, revocation, and inventory tracking.
- Proficiency deploying and managing certificates across diverse platformsWindows infrastructure, load balancers, web services, directory services, Azure Key Vault, and applications.
- Robust analytical, troubleshooting, and root-cause analysis skills with the ability to diagnose complex certificate, trust chain, and TLS issues independently.
- Understanding of security standards and compliance frameworks relevant to PKI (SOC 2, ISO 27001, FIPS 140-2, etc.) and certificate management audit requirements.
Preferred Credentials & Experience
- Published or recognized expertise in PKI, demonstrated through technical blogs, certifications (such as CCSK, KCSA, or vendor-specific PKI certifications), or open-source PKI contributions.
- Familiarity with IETF RFC standards for PKI (5280, 6125, 7925, 8446, etc.) and advanced certificate standards.
- Experience with Certificate Transparency, OCSP, CRL management, and certificate validation strategies.
- Experience with Azure Key Vault, AWS Certificate Manager, or other cloud PKI/secrets platforms.
- Experience with Docker, Kubernetes, or container certificate provisioning and rotation.
- Hands-on familiarity with Microsoft Active Directory Certificate Services (AD CS), including enterprise certificate authority architecture, certificate templates, enrollment and auto-enrollment policies, role-based administration, certificate issuance and revocation, CRL and OCSP configuration, trust-chain management, security hardening, auditing, backup and recovery, troubleshooting, and integration with Windows, Azure, network devices, applications, and automated certificate lifecycle workflows.
- Experience designing and implementing end-to-end certificate automation using PowerShell, Python, REST APIs, ACME, or workflow orchestration tools to automate certificate discovery, requests, approvals, enrollment, issuance, deployment, renewal, rotation, revocation, expiration alerting, inventory reconciliation, ownership tracking, and compliance reporting across cloud and on-premises environments.
- Experience implementing enterprise-wide certificate scanning and discovery across cloud and on-premises infrastructure, including servers, applications, websites, APIs, load balancers, network devices, containers, and cloud services, with the ability to identify unknown or unmanaged certificates, capture certificate metadata and ownership, detect expiration and configuration risks, reconcile findings with the authoritative inventory, and automate alerts, remediation workflows, and compliance reporting.
- Understanding of hardware security modules (HSM) and certificate storage best practices.
Team Environment You will join a Cloud Solutions Team with deep expertise in enterprise PKI and certificate lifecycle management. This is a specialist role focused on the people, processes, and automation that keep certificates provisioned, deployed, and rotated reliably across the organization. Success requires disciplined engineering, comprehensive automation, meticulous documentation, continuous learning in PKI technologies, and an unwavering commitment to preventing certificate outages, expiration incidents, and security gaps.
You will be the go-to expert for all things certificate-related.
Regards,
Jolly Nayak
3POINTHRM
📌 Cloud Solutions Engineer / PKI (Gurugram)
🏢 3 Point HRM
📍 Gurugram