PKI Engineer managing internal and external certificate authorities for U.S. Bank. Focusing on certificate management and security best practices across various platforms.
Responsibilities
Manage internal Certificate Authority (Active Directory Certificate Services) including, but not limited to, certificate templates, issuing and revocation of internal certificates, PKI administration, automated certificate issuance for server certificates, client certificates, SMIME certificates, and Code Signing certificates.
Maintain Certificate Revocation List (CRL) distribution servers critical to the entire enterprise environment.
Maintain NDES/SCEP protocol servers critical to certificate distribution for corporate Apple/Mac workstations.
Manage external Certificate Authority (DigiCert CA) including issuing and revocation of externally signed certificates, and Domain Control Validation (DCV) process.
Provide necessary mentoring and training to all certificate owners regarding maintaining certificate security and industry level best practices.
Identify and manage all server (machine) SSH keys on an enterprise level and scope a multi-year project to replace these never expiring credentials with short-lived SSH certificates.
Maintain the life cycle, manage alerting, and potential automation of certificates used by machines.
Design, document, and implement operating procedures that include systematic processes and delegation for the machine identity lifecycle and maintenance tasks.
Requirements
Preferred Bachelor’s degree in Information Technology/Security, and/or 4-6 years of equivalent work experience (Helpdesk, System Administration, Middleware) with a minimum of 1-3 years of experience as it relates to PKI administration, certificate management using Venafi, with working knowledge of mTLS, SSO, LDAP/Kerberos integrations or equivalent knowledge/experience.
Machine Identity Management goes beyond a solid understanding of Public Key Infrastructure (PKI) administration – which is a basic requirement. This is the next level knowledge or evolution of the inner workings of Machine Identities including, but not limited, to SSH keys, SSH certificates, JWT,JWE, SPIFEE,SPIRE, and other forms of machine identity and access controls.
Strong proficiency in cryptography, cryptographic standards, risk base compliance, and zero-trust.
Knowledge of x509 standards as it relates to digital certificates, SSH keys, and PKI administration.
Working knowledge of authentication and authorization through multifactor (MFA), Mutual TLS (mTLS), single sign-on (SSO), and LDAP/Kerberos integrations using certificates.
Working knowledge of Windows PowerShell scripting used for certificate automation and processing.
Experience with Certificate Management solutions including Venafi, API integrations with Venafi, alerting and automation, and integrations with various other software solutions for certificate issuance and monitoring.
Troubleshooting certificate configuration and TLS issues.
Benefits
Healthcare (medical, dental, vision)
Basic term and optional term life insurance
Short-term and long-term disability
Pregnancy disability and parental leave
401(k) and employer-funded retirement plan
Paid vacation (from two to five weeks depending on salary grade and tenure)
Up to 11 paid holiday opportunities
Adoption assistance
Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
Engineer managing electrical and instrumentation engineering projects at Takasaki plant. Responsible for planning, execution and law compliance of projects.
IT Engineer in a hybrid role supporting energy system applications with a focus on Oracle databases. Collaborating in a team to ensure smooth IT operations and user support.
Project Engineer overseeing facility upgrades and new builds at Reckitt. Ensuring timely delivery and operational readiness while maintaining safety and compliance standards.
GPU Performance Engineer optimizing modern workloads to enhance performance of Intel's Graphics Processing Units. Collaborating with architects on rendering techniques and graphics optimization.
Software Engineer ensuring high availability of middleware applications at Bancolombia. Responsible for full lifecycle of middleware applications and providing user support.
SCADA Engineer leading PLC programming and system standardization initiatives at HF Sinclair, focusing on ensuring operational efficiency in energy production across multiple locations.
Stage ingénieur en environnement au sein des Laboratoires Chemineau, évaluation de l'impact environnemental et gestion des rejets. Collaboration avec le Directeur HSSE sur des projets majeurs.
Senior Protection Relay & Metering Engineer providing technical expertise in renewable energy operations. Supporting and optimizing AES Clean Energy operational performance of a fleet of renewables across the US.
Senior SCADA Engineer designing and maintaining SCADA systems for North American AES Clean Energy operations. Collaborating with teams to ensure reliable data acquisition and process control while optimizing performance.
Engineer providing engineering and technical support for Lilly's global packaging operations. Analyzing workflows and processes to improve quality and efficiency in packaging procedures.