PKI Venafi Architect
IT · Full-time
Remote
USD 160k-165k / year
PKI Venafi Architect
Location: Remote (U.S.)
Salary: $160,000 - $165,000 Base Salary
Employment Type: Full-Time
About the Opportunity
We are seeking an experienced PKI Venafi Architect to lead enterprise-wide Public Key Infrastructure (PKI), certificate lifecycle management, and machine identity security initiatives. This role will be responsible for architecting, deploying, and optimizing secure PKI environments while driving automation and governance across enterprise applications, cloud platforms, and security ecosystems.
The ideal candidate will possess deep expertise in Venafi Trust Protection Platform (TPP), PKI architecture, certificate lifecycle management, cryptographic controls, and cloud security solutions.
Key Responsibilities
PKI & Security Architecture
- Design, implement, and maintain enterprise PKI architecture, including:
- Root Certificate Authorities (CA)
- Issuing CAs
- Certificate Revocation Lists (CRL)
- Online Certificate Status Protocol (OCSP)
- Hardware Security Modules (HSM)
- Trust frameworks
- Develop certificate governance standards, policies, and cryptographic control frameworks.
- Architect scalable, highly available PKI and Certificate Lifecycle Management (CLM) solutions.
- Drive enterprise machine identity and certificate management strategy.
Venafi Platform Architecture
- Design, administer, and optimize Venafi Trust Protection Platform (TPP).
- Define onboarding standards, workflows, discovery jobs, reporting, policy management, and access controls.
- Architect integrations between Venafi and enterprise applications, cloud platforms, and security tools.
- Lead platform upgrades, enhancements, and performance optimization initiatives.
Certificate Lifecycle Automation
- Architect and implement automated certificate provisioning, renewal, and deployment solutions.
- Build automation frameworks utilizing:
- Venafi APIs
- vCert
- PowerShell
- Python
- Ansible
- GitHub Actions
- Azure DevOps
- CI/CD Pipelines
- Drive enterprise adoption of certificate lifecycle automation.
Application & Cloud Integration
- Lead onboarding of enterprise applications into CLM services.
- Support certificate deployment and automation across:
- Windows Server
- Linux/Unix
- IIS
- Apache
- Tomcat
- WebLogic
- Kubernetes
- Azure
- AWS
- F5 Load Balancers
- Kafka
- Solace
- PingFederate
- Provide architectural guidance and troubleshooting support for complex certificate and trust-related issues.
Governance & Compliance
- Ensure compliance with:
- NIST
- PCI-DSS
- SOX
- ISO 27001
- FedRAMP
- Internal security standards
- Conduct cryptographic risk assessments and certificate posture reviews.
- Define certificate ownership and governance processes.
- Support audit and regulatory compliance initiatives.
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field.
- 10+ years of Information Security experience.
- 5+ years of hands-on PKI architecture experience.
- 5+ years working with Venafi Trust Protection Platform.
- Expertise in:
- PKI
- X.509 Certificates
- TLS/SSL
- Certificate Lifecycle Management (CLM)
- CRL/OCSP
- Hardware Security Modules (HSM)
- Digital Signatures
- Cryptographic Key Management
- Experience designing PKI solutions within Azure and AWS environments.
- Strong scripting and automation skills using PowerShell and Python.
Preferred Qualifications
- CISSP, CISM, CCSP, or similar cybersecurity certification.
- Venafi Certified Professional or Venafi Certified Architect certification.
- Experience with:
- Keyfactor
- DigiCert
- Entrust
- Microsoft ADCS
- HashiCorp Vault
- Azure Key Vault
- AWS Certificate Manager
- Previous experience within banking, financial services, insurance (BFSI), or other highly regulated industries.
Technical Skills
PKI & Cryptography
- PKI Architecture
- X.509 Certificates
- TLS/SSL
- PKCS Standards
- Digital Signatures
- HSM Integration
- CRL / OCSP
Venafi
- Venafi Trust Protection Platform (TPP)
- Venafi TLS Protect
- Certificate Discovery
- Policy Management
- Workflow Automation
- Reporting & Governance
Cloud & DevOps
- Microsoft Azure
- AWS
- Kubernetes
- GitHub Actions
- Azure DevOps
- CI/CD Pipelines
- Infrastructure as Code (IaC)
Programming & Automation
- PowerShell
- Python
- REST APIs
- Ansible
Leadership Expectations
- Serve as the organization's PKI and Machine Identity subject matter expert.
- Provide technical leadership and guidance to engineering and operations teams.
- Develop enterprise PKI roadmaps and modernization strategies.
- Mentor junior engineers and establish certificate lifecycle management best practices.
- Drive Zero Trust and identity-centric security initiatives.
Apply today to join a team focused on securing enterprise identities, automating certificate management, and modernizing PKI infrastructure.