PKI Engineer managing internal and external certificate authorities for U.S. Bank. Focusing on certificate management and security best practices across various platforms.
Responsibilities
Manage internal Certificate Authority (Active Directory Certificate Services) including, but not limited to, certificate templates, issuing and revocation of internal certificates, PKI administration, automated certificate issuance for server certificates, client certificates, SMIME certificates, and Code Signing certificates.
Maintain Certificate Revocation List (CRL) distribution servers critical to the entire enterprise environment.
Maintain NDES/SCEP protocol servers critical to certificate distribution for corporate Apple/Mac workstations.
Manage external Certificate Authority (DigiCert CA) including issuing and revocation of externally signed certificates, and Domain Control Validation (DCV) process.
Provide necessary mentoring and training to all certificate owners regarding maintaining certificate security and industry level best practices.
Identify and manage all server (machine) SSH keys on an enterprise level and scope a multi-year project to replace these never expiring credentials with short-lived SSH certificates.
Maintain the life cycle, manage alerting, and potential automation of certificates used by machines.
Design, document, and implement operating procedures that include systematic processes and delegation for the machine identity lifecycle and maintenance tasks.
Requirements
Preferred Bachelor’s degree in Information Technology/Security, and/or 4-6 years of equivalent work experience (Helpdesk, System Administration, Middleware) with a minimum of 1-3 years of experience as it relates to PKI administration, certificate management using Venafi, with working knowledge of mTLS, SSO, LDAP/Kerberos integrations or equivalent knowledge/experience.
Machine Identity Management goes beyond a solid understanding of Public Key Infrastructure (PKI) administration – which is a basic requirement. This is the next level knowledge or evolution of the inner workings of Machine Identities including, but not limited, to SSH keys, SSH certificates, JWT,JWE, SPIFEE,SPIRE, and other forms of machine identity and access controls.
Strong proficiency in cryptography, cryptographic standards, risk base compliance, and zero-trust.
Knowledge of x509 standards as it relates to digital certificates, SSH keys, and PKI administration.
Working knowledge of authentication and authorization through multifactor (MFA), Mutual TLS (mTLS), single sign-on (SSO), and LDAP/Kerberos integrations using certificates.
Working knowledge of Windows PowerShell scripting used for certificate automation and processing.
Experience with Certificate Management solutions including Venafi, API integrations with Venafi, alerting and automation, and integrations with various other software solutions for certificate issuance and monitoring.
Troubleshooting certificate configuration and TLS issues.
Benefits
Healthcare (medical, dental, vision)
Basic term and optional term life insurance
Short-term and long-term disability
Pregnancy disability and parental leave
401(k) and employer-funded retirement plan
Paid vacation (from two to five weeks depending on salary grade and tenure)
Up to 11 paid holiday opportunities
Adoption assistance
Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
Building Engineer implementing net - zero sustainability strategies in a fast - growing real estate technology startup. Collaborating with Data Science to analyze energy - saving retrofit recommendations.
ASIC Design Engineer on the STA team at Cisco developing extraction and STA flow methodologies to improve performance. Collaborating with Physical Design team for advancements in ASIC and optical technology.
Lead Engineer driving continuous improvement in Ryder's operations through data - driven CI and engineering methodologies. Managing high - impact projects to enhance performance in safety, quality, cost, and delivery.
Engineer responsible for the design and modeling of Wagabox solutions to convert waste methane into renewable natural gas. Collaborating with engineering firms and ensuring compliance with North American standards.
Senior Consultant delivering end - to - end data - driven solutions utilizing Palantir Foundry. Collaborating with stakeholders and taking ownership of technical solution design and implementation.
Business Resumption Engineer supporting incident response for cyber insurance clients globally. Collaborating with teams on recovery of systems during cyber incidents.
Software Engineer developing software for complex machines with robotics in the horticulture sector. Collaborating with the RD&E team to innovate and standardize automation solutions.
Ingénieur Automatisme responsable de la conformité des systèmes automatisés chez Knauf. Mission de conception, développement et maintenance de solutions industrielles.
Project Engineer overseeing the efficient delivery of capital programmes across Anglian Water's assets. Collaborating with various teams to ensure project compliance and stakeholder engagement.
Senior Water Resources Engineer joining Calgary team to support hydrologic analysis and hydraulic design. Leading project teams and ensuring project milestones are met with technical expertise.