- Company Name
- InfiCare Inc.
- Job Title
- PKI Architect
- Job Description
-
**Job title:** PKI Architect
**Role Summary:**
Design, implement, and manage enterprise Public Key Infrastructure (PKI) solutions. Lead integration with identity management, authentication, and secure communication systems. Govern certificate policies, key management, and compliance with regulatory standards. Provide technical leadership and mentoring on PKI best practices.
**Expectations:**
- 7+ years in cybersecurity, 3+ years focused on PKI architecture and implementation.
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- Strong knowledge of cryptographic protocols (TLS/SSL, S/MIME, IPsec), X.509 certificates, and key lifecycle.
- Experience with PKI platforms (Microsoft AD CS, Venafi, DigiCert, Entrust, Keyfactor) and HSMs.
**Key Responsibilities:**
- Architect scalable PKI solutions aligned with enterprise security requirements.
- Lead deployment and integration of PKI with IAM, authentication, and secure communications.
- Define and enforce certificate policies, key usage standards, and lifecycle processes.
- Manage root and subordinate CAs, including HSM configuration and maintenance.
- Ensure compliance with NIST, ISO, GDPR, and other relevant regulations.
- Collaborate with cybersecurity, infrastructure, and application teams to embed PKI into broader security architecture.
- Conduct risk assessments and recommend improvements to PKI processes and technologies.
- Mentor engineering teams on PKI design, implementation, and operational best practices.
**Required Skills:**
- Cryptography and security protocols (TLS/SSL, S/MIME, IPsec).
- PKI administration (certificate issuance, revocation, renewal).
- PKI tools and platforms (Microsoft AD CS, Venafi, DigiCert, Entrust, Keyfactor).
- Hardware Security Modules (HSMs), smart cards, secure key storage.
- Integration with Identity and Access Management (IAM) systems.
- Strong analytical, documentation, and communication abilities.
**Required Education & Certifications:**
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- Certifications such as CISSP, CISM, or vendor‑specific PKI certifications are preferred.
- Experience with cloud PKI services (AWS Certificate Manager, Azure Key Vault) and DevSecOps automation is a plus.