Padmi

Microsoft ADCS Administrator - Associate Architect III - BF

HyderabadPosted 3 months ago
Infrastructure And DatabasesMid-level
Apply at Legato

Opens the source posting on naukri.com

Source description

About the role

View original

Position Title: Microsoft ADCS Administrator - Associate Architect III Job Family: IFT > IT Architecture Job Title Associate Architect III Requirement Type Full-Time Employee Job Location Bangalore / Hyderabad / Gurugram Requirement Level Associate Architect Hiring Manager Associate Director Infra Operations Primary Skill Microsoft ADCS Administrator Business Security Technology Services Skill Category Super Super Niche JOB POSITION Carelon Global Solutions India is seeking an Associate Architect III. A Microsoft Microsoft ADCS (Active Directory Certificate Services) Administrator to support our enterprise Public Key Infrastructure (PKI). You ll be responsible for operating and hardening Active Directory Certificate Services, maintaining certificate lifecycle processes, and partnering with security, identity, and infrastructure teams to ensure certificates are reliable, compliant, and automation friendly. JOB RESPONSIBILITY Administer and support Microsoft ADCS environments (Enterprise/Standalone CAs, Subordinate CAs, issuing CAs). Manage certificate lifecycle: issuance, renewal, revocation, CRLs, OCSP, key archival/recovery (as applicable). Operate and troubleshoot certificate templates, auto-enrollment, enrollment agents, and Group Policy based deployment. Maintain CA health and availability: monitoring, capacity planning, patching, service recovery, and performance tuning. Manage and secure CA private keys, including HSM integration, key ceremonies, and backup/restore procedures. Publish and validate CRL/AIA locations; ensure proper distribution and client retrieval across networks. Implement and maintain PKI policies and standards aligned with security and compliance requirements. Integrate ADCS with enterprise platforms (examples: Windows authentication, IIS, NPS/RADIUS, VPN, Wi-Fi 802.1X, Intune/MDM, SCEP/NDES, load balancers, Linux services as needed). Support certificate needs for internal services (TLS/SSL), code signing, device certs, and user certs. Create automation for certificate operations using PowerShell (and/or other tooling), and document operational runbooks. Participate in audits, incident response, vulnerability remediation, and continuous improvement for PKI controls. Provide Tier 3 support and root-cause analysis for certificate-related outages and authentication issues. QUALIFICATION Hands-on experience administering Microsoft ADCS/PKI in an enterprise environment. Strong knowledge of X.509, certificate chains, SANs, EKUs, CRL/OCSP, key usage, and common TLS pitfalls. Experience with certificate templates, auto-enrollment, and GPO configuration. Proficiency with PowerShell for administration, reporting, and automation. Solid Windows Server administration skills (patching, services, event logs, troubleshooting). Understanding of security best practices (least privilege, separation of duties, key protection, auditing). Ability to document architecture, SOPs, and troubleshooting guides. EXPERIENCE Bachelor s degree or equivalent ~5 years of experience administrating ADCS SKILLS AND COMPETENCIES Strong troubleshooting and systems thinking; comfortable diagnosing certificate weirdness across apps and networks. High attention to detail and change management discipline (PKI changes can have high impact). Clear communicator who can translate PKI concepts for non-PKI stakeholders. Nice to Have: Experience with NDES/SCEP, Intune certificate profiles, JAMF, or other MDM integrations. HSM experience (Thales, Entrust, Utimaco, etc.) and formal key ceremony procedures. Familiarity with PKI design patterns (offline root CA, subordinate issuing CAs, HA/DR strategies). Experience with Azure/Entra ID adjacent identity services, hybrid identity environments, and cloud certificate use cases. Exposure to vulnerability/compliance frameworks (CIS, NIST, ISO 27001). Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

One address, no account. We’ll tell you when matching roles go live.

More at Legato

Related open roles

View all roles