HamburgerMenu
hirist

PKI Engineer - Active Directory

Hrizen
Any Location
8 - 11 Years

Posted on: 09/07/2025

Job Description

Job Description :

We are looking for an experienced PKI Engineer with deep expertise in Public Key Infrastructure, certificate lifecycle management, and security architecture. The role requires hands-on experience in PKI tools and protocols, scripting, and working in hybrid cloud environments. The ideal candidate will play a key role in designing, implementing, and maintaining secure identity and encryption solutions for enterprise environments.


Responsibilities :

- Deploy and manage PKI infrastructure, including CA setup, certificate template creation, and full certificate lifecycle management.


- Implement and support CLM (Certificate Lifecycle Management) solutions and HSM (Hardware Security Modules).

- Work on PKI products such as Keyfactor, EJBCA, Auto Enrolment, and related orchestration services.

- Develop high-level architecture diagrams with a focus on PKI and security components.

- Integrate and manage federation, ADFS, Azure AD, identity synchronization, and networking on Azure.

- Work with NDES, Active Directory Certificate Services, Azure AD, and Active Directory.

- Create custom automation workflows using PowerShell and REST APIs for certificate and identity operations.


Requirements :


- Strong working knowledge of PKI management, certificate lifecycle, and CA deployments.


- Hands-on experience with CLM tools and HSMs.


- Exposure to PKI solutions such as Keyfactor, EJBCA, Auto Enrolment, and orchestration services.


- Solid understanding of Azure, including identity sync, federation, and ADFS.

- Experience with architecture diagramming and PKI-focused system designs.

- Familiarity with NDES, AD CS, Azure AD, and Active Directory environments.

- Working knowledge of SSO, SAML, and claims-based authentication.

- Proficiency in PowerShell scripting and automation workflows.

- Understanding of role-based access controls in Windows and Linux environments.


Desired Skills :


- Experience with SCEP, ACME, CMP, or EST certificate protocols.


- Hands-on with EJBCA in real-world implementations.


- Exposure to IAM technologies and identity governance systems.

- Experience in Linux/Unix operating systems.

- Familiarity with ITSM platforms such as ServiceNow or BMC Remedy.


info-icon

Did you find something suspicious?