Padmi

Public Key Infrastructure (PKI) Engineer

BangalorePosted 2 months ago
CybersecurityMid-levelFull Time; Regular
Apply at Asian Hires

Opens the source posting on shine.com

Source description

About the role

View original

Job Location - Bangalore About the Role A PKI / ADCS Engineer is responsible for designing, deploying, and managing enterprise Public Key Infrastructure including Root CA, Intermediate CA, and Issuing CA servers while ensuring secure certificate issuance and validation processes. The role involves hands-on management of Microsoft ADCS components such as NDES (SCEP), CEP/CES services, and integration with Active Directory for auto-enrollment and authentication. Responsibilities The engineer must manage complete certificate lifecycle activities including certificate request, issuance, renewal, revocation, and troubleshooting of certificate-related issues across users, systems, and applications.Strong understanding of certificate store architecture and certificate chain validation is required to ensure trust relationships within enterprise environments.The role requires implementation and maintenance of Certificate Policy (CP) and Certification Practice Statement (CPS) aligned to organizational security standards and compliance requirements.The candidate should also manage CRL infrastructure including base CRL and delta CRL, ensuring proper publication and accessibility via CDP and AIA locations.The engineer should possess strong knowledge of cryptographic principles including asymmetric and symmetric encryption, hashing, and digital signatures along with practical understanding of PKCS standards, Cryptographic Service Providers (CSP), and Key Storage Providers (KSP).The role involves supporting SSL/TLS certificates across internal and external applications and ensuring adherence to industry standards like X.509 and TLS protocols.Strong troubleshooting skills are required for resolving issues related to certificate enrollment, chain errors, CRL accessibility, and authentication failures.The candidate must have good understanding of Active Directory including Group Policy, auto-enrollment configuration, and integration with PKI services for enterprise identity and access management.The role includes ensuring PKI high availability, fault tolerance, and disaster recovery by implementing proper backup, restore, and redundancy mechanisms across CA servers and related infrastructure.The engineer should work on operational support, monitoring PKI health, performing RCA for incidents, and maintaining documentation for PKI processes and environments. Qualifications Thorough understanding of TCP/IP networking & Information SecurityExperience in installing & administering Proxy (Zscaler), AntiVirus/EDROptional skills include experience with Linux-based certificate management, OpenSSL tools, cloud PKI platforms (Azure/AWS), and HSM integration for secure key management. Required Skills Strong understanding of certificate store architecture and certificate chain validation, cryptographic principles, and Active Directory. Preferred Skills Experience with Linux-based certificate management, OpenSSL tools, cloud PKI platforms (Azure/AWS), and HSM integration for secure key management. Pay range and compensation package Upto 25 LPA (Based on Interview and Experience) Equal Opportunity Statement We are committed to diversity and inclusivity in our hiring practices. Job Location - Bangalore About the Role A PKI / ADCS Engineer is responsible for designing, deploying, and managing enterprise Public Key Infrastructure including Root CA, Intermediate CA, and Issuing CA servers while ensuring secure certificate issuance and validation processes. The role involves hands-on management of Microsoft ADCS components such as NDES (SCEP), CEP/CES services, and integration with Active Directory for auto-enrollment and authentication. Responsibilities The engineer must manage complete certificate lifecycle activities including certificate request, issuance, renewal, revocation, and troubleshooting of certificate-related issues across users, systems, and applications.Strong understanding of certificate store architecture and certificate chain validation is required to ensure trust relationships within enterprise environments.The role requires implementation and maintenance of Certificate Policy (CP) and Certification Practice Statement (CPS) aligned to organizational security standards and compliance requirements.The candidate should also manage CRL infrastructure including base CRL and delta CRL, ensuring proper publication and accessibility via CDP and AIA locations.The engineer should possess strong knowledge of cryptographic principles including asymmetric and symmetric encryption, hashing, and digital signatures along with practical understanding of PKCS standards, Cryptographic Service Providers (CSP), and Key Storage Providers (KSP).The role involves supporting SSL/TLS certificates across internal and external applications and ensuring adherence to industry standards like X.509 and TLS protocols.Strong troubleshooting skills are required for resolving issues related to certi

One address, no account. We’ll tell you when matching roles go live.

More at Asian Hires

Related open roles

View all roles