PKI Engineer managing internal and external certificate authorities for U.S. Bank. Focusing on certificate management and security best practices across various platforms.
Responsibilities
Manage internal Certificate Authority (Active Directory Certificate Services) including, but not limited to, certificate templates, issuing and revocation of internal certificates, PKI administration, automated certificate issuance for server certificates, client certificates, SMIME certificates, and Code Signing certificates.
Maintain Certificate Revocation List (CRL) distribution servers critical to the entire enterprise environment.
Maintain NDES/SCEP protocol servers critical to certificate distribution for corporate Apple/Mac workstations.
Manage external Certificate Authority (DigiCert CA) including issuing and revocation of externally signed certificates, and Domain Control Validation (DCV) process.
Provide necessary mentoring and training to all certificate owners regarding maintaining certificate security and industry level best practices.
Identify and manage all server (machine) SSH keys on an enterprise level and scope a multi-year project to replace these never expiring credentials with short-lived SSH certificates.
Maintain the life cycle, manage alerting, and potential automation of certificates used by machines.
Design, document, and implement operating procedures that include systematic processes and delegation for the machine identity lifecycle and maintenance tasks.
Requirements
Preferred Bachelor’s degree in Information Technology/Security, and/or 4-6 years of equivalent work experience (Helpdesk, System Administration, Middleware) with a minimum of 1-3 years of experience as it relates to PKI administration, certificate management using Venafi, with working knowledge of mTLS, SSO, LDAP/Kerberos integrations or equivalent knowledge/experience.
Machine Identity Management goes beyond a solid understanding of Public Key Infrastructure (PKI) administration – which is a basic requirement. This is the next level knowledge or evolution of the inner workings of Machine Identities including, but not limited, to SSH keys, SSH certificates, JWT,JWE, SPIFEE,SPIRE, and other forms of machine identity and access controls.
Strong proficiency in cryptography, cryptographic standards, risk base compliance, and zero-trust.
Knowledge of x509 standards as it relates to digital certificates, SSH keys, and PKI administration.
Working knowledge of authentication and authorization through multifactor (MFA), Mutual TLS (mTLS), single sign-on (SSO), and LDAP/Kerberos integrations using certificates.
Working knowledge of Windows PowerShell scripting used for certificate automation and processing.
Experience with Certificate Management solutions including Venafi, API integrations with Venafi, alerting and automation, and integrations with various other software solutions for certificate issuance and monitoring.
Troubleshooting certificate configuration and TLS issues.
Benefits
Healthcare (medical, dental, vision)
Basic term and optional term life insurance
Short-term and long-term disability
Pregnancy disability and parental leave
401(k) and employer-funded retirement plan
Paid vacation (from two to five weeks depending on salary grade and tenure)
Up to 11 paid holiday opportunities
Adoption assistance
Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
Senior EC&I Engineer providing engineering support and guidance to maintenance and operations teams at various sites. Leading projects and ensuring compliance with industry standards in a hybrid model.
Enterprise Configuration Engineer leading operations in pre - stage environment at CDW. Collaborating with technical leads and training others to enhance skills in enterprise configurations.
Process & Controls Engineer supporting production optimization and quality improvement for Proliant Dairy. Collaborating across teams to enhance manufacturing efficiency and regulatory compliance.
Data Center Facilities Engineer maintaining operational and regulatory integrity of data center systems. Ensuring reliability and efficiency of critical facility operations.
Junior Food Process Engineer at Mondelēz International developing process designs and specifications for innovation and productivity projects. Collaborating with cross - functional teams to deliver consumer - centric solutions.
EHS Safety Engineer managing Health & Safety programs for Applied Materials in Agrate, Italy. Collaborating with teams to ensure compliance with safety regulations and continuously improve safety performance.
Camera Framework Engineer designing and developing Vehicle OS Media Framework for various applications. Involved in maintaining and optimizing camera services in autonomous vehicle technology.
Senior Systems Citrix Engineer providing technical solutions for Citrix environments at Datacom. Collaborating with teams to deliver Citrix technology - based support and engaging in projects for customers.
Mobility Engineer responsible for operational support of customer systems and solutions at Datacom. Collaborating with teams to enhance customer environments and ensure satisfaction while following best practices.
IT System Engineer responsible for infrastructure and virtualization solutions at NetPlans. Collaboration with experts in server, storage, and backup systems for diverse projects.