Certificate Lifecycle/ PKI Engineer - Venafi Exp.

The Judge Group
The Judge Group

Full-time

Remote

Posted on Sep 17, 2026

PKI Engineer with Venafi Expertise

Remote

Fulltime

o 5+ years of experience supporting PKI, TLS Certificates, or Certificate Lifecycle Management.

3+ years of hands-on Venafi administration and engineering experience

· PKI & Cryptography

o Public Key Infrastructure (PKI)

o X.509 Certificates

o TLS/SSL

o Certificate Authorities (CA)

o Certificate Revocation Lists (CRL)

o OCSP

o Key Management

o Hardware Security Modules (HSM)

o Code Signing Certificates

o Root and Intermediate CA Management

· Venafi Expertise

o Venafi Trust Protection Platform (TPP)

o Venafi SaaS

o Certificate Discovery

o Certificate Automation o Venafi APIs

o Adaptable Apps

o Native Drivers

o Reporting and Governance

o Certificate Lifecycle Workflows

· Platforms & Integrations

o Windows IIS

o Linux/Unix

o Microsoft Azure

o Azure Key Vault

o Kubernetes

o F5 Load Balancers

o Apache

o Tomcat

o WebLogic

o Kafka

o Solace

o Ping Federate

o ServiceNow Integrations

· DevOps & Automation

o GitHub Actions

o Azure DevOps

o CI/CD Pipelines

o PowerShell

o Python

o REST APIs

o Ansible

o Infrastructure Automation

· Security Domains

o Authentication

o Authorization

o Identity & Access Management

o Secrets Management

o Zero Trust Principles

o Cloud Security

o Security Monitoring

· Strong understanding of PKI architecture and certificate lifecycle processes.

· Experience implementing certificate automation patterns and DevSecOps integrations.

· Experience supporting enterprise-scale certificate environments.

· Strong troubleshooting, analytical, and problem-solving skills.

· Excellent communication and stakeholder management skills.

Roles & Responsibilities

• Lead Identity centric Workforce Security team to develop authentication and access management solutions

• Drive the development of identity solutions, access patterns, modern security protocols, practicing Zero trust, least privileged, defense in depth principles

• Good understanding of AI concepts, Patterns and impact on identity and access management domain

• Participate and engage in AI adoption with Identity focus, knowledge and understanding of Entra ID agentic Identity, authentication flows and Patterns

• Review and provide feedback on Identity and access management related security solutions proposed by stakeholders and can provide consultation to the partners and IT Management

• In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, AWS Security

• Knowledge on Okta, PingFederate, Entitlement management solutions

• Strong knowledge on Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, Conditional access policies, MFA, Ker beros, LDAP, Identity Federations etc.

• Experience in providing security solutions for Java based Micro services, React based frontends and Android/iOS based mobile applications on the Azure

• Hands-of experience in JWT, session handling, Code signing, Certificate authentication, TLS/SSL, API Security, Application registration, application integration scenarios etc.

• Awareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc.

• Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure smooth remediation of toxic combinations, high risk entitlements etc.

• Understanding and application of threat modeling concepts and methodologies

• Understanding of Applications security, OWASP standards, security best practices, browser compatibilities/storages/cookies

• Acts as Workforce cybersecurity expert to in solutions spanning end user computing, proxy solutions, MFA, SSO, conditional accesses, Passwordless, Yubikey, bio-metric solutions, identity and governance scenarios, Secrets Management, automation, role based access control, Privileged identity management, Just in time accesses etc.

• Participates in solutions to support- token handling, OIDC/ OAuth flows, authorization patterns, identity federation, cloud architectures, cryptography, cloud native services, cloud security etc.

• Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, privileged access management etc.

• Ability to support operations in troubleshooting complex identity scenarios with hands-on experience on Sentinel/KQL/Audit logs etc.

• Good understanding of concepts related to docker Security, container orchestrations/Kubernetes

Comprehensive benefits package including medical, dental, and vision coverage, retirement savings plan with company contribution, paid time off, holidays, and opportunities for professional growth and career development. Additional benefits and perks will be discussed during the interview process.

By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively “Judge”) to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.

Apply now