Provide deep subject matter expertise for Public Key Infrastructure certificate lifecycle management and cryptographic services operations
Key Responsibilities
- Assess current PKIcertificate lifecycle processes tools inventories dependencies and operational pain points
- Design and support certificate lifecycle operational processes including request issuance renewal revocation inventory and expiry management
- Review CA hierarchy certificate profiles key protection patterns ownership models and control gaps
- Define operational runbooks exception handling escalation paths and reporting metrics for certificate management
- Work with application infrastructure and security teams to remediate expired weak or noncompliant certificates
- Provide guidance on automation opportunities across discovery renewal and reporting workflows
- Support audit compliance and risk reporting related to cryptographic controls
Primary Skills
- PKI and certificate lifecycle management
- Certificate inventory renewal and expiry operations
- CA hierarchy certificate profiles and key management fundamentals
- Hardware security module key protection concepts
- Cryptographic controls and encryption governance
- Operational runbook development
Secondary Skills
- Venafi DigiCert Microsoft CA Entrust or equivalent CLM platforms
- TLSSSL mTLS and application certificate dependency analysis
- Scriptingautomation for certificate reporting
- ITSM workflow integration
- PCI DSS NIST and regulatory control awareness
- Audit evidence and KPI reporting
Experience Qualifications
- 5-8 years in cybersecurityinfrastructure security with solid PKIcertificate lifecycle experience
- Prior experience in regulated enterprise environments preferred
- CISSP CISM Security cloud security or vendor PKI certifications preferred