01 Oct
|
Atos
|
Bengaluru
Work Location - Mumbai & Bangalore
Role & responsibilities
Must have skills
- Architected and productised identity or PKI services (reference architecture, platform evaluation and selection, service definition), not implementation only
- PKI at design depth: X.509/RFC 5280, CA hierarchy design, certificate profiles, CP/CPS, revocation (CRL/OCSP), audit frameworks (WebTrust, ETSI)
- HSM and key custody: PKCS#11, FIPS 140-3, and hands-on participation in a witnessed key ceremony
- Enrolment and renewal protocols: ACME, EST, SCEP, CMP, Microsoft auto-enrolment
- Microsoft AD CS, plus at least one of EJBCA, Entrust, DigiCert
- CLM platforms: Idira Certificate Manager (formerly Venafi), Keyfactor, AppViewX, DigiCert Trust Lifecycle Manager
- Workload identity: SPIFFE/SPIRE, Kubernetes service account tokens, cluster-to-cloud identity federation (IRSA, Azure Workload Identity, GKE), mTLS and service mesh
- Kubernetes at administrator depth and cloud IAM (Azure, AWS, GCP)
- Machine identity governance: service accounts, managed identities, service principals, OAuth application grants, API keys; ownership inference and scope reduction
- Post-quantum cryptography and cryptographic inventory: NIST FIPS 203/204/205, hybrid certificates, migration planning, crypto-agility
Preferred candidate profile
Positive to have
- IDnomic experience
- Machine identity governance platforms (Cisco/Astrix, Entro, Natoma, Oasis, SailPoint or Saviynt non-human identity)
- Cryptographic discovery tooling (Keyfactor/InfoSec Global, SandboxAQ)
- Secrets management platforms (Vault, Akeyless) at the integration boundary
📌 Machine Identity Service Architect (Bengaluru)
🏢 Atos
📍 Bengaluru