D

PKI Engineer

Distrovia LinkedIn
São PauloPlenoCLT3 dias atrás

Salário Estimado

R$ 9.360,00 - R$ 14.040,00

Tecnologias

0de 100

Ótimo

Score da Vaga

Descrição da Vaga

PKI JDSummary~We are looking for a PKI/CLM Engineer with hands-on experience in ADCS, AWS ACM, and Venafi to design, implement, and manage enterprise PKI and Certificate Lifecycle Management services.


The role includes certificate automation, policy enforcement, infrastructure and application integration, and ensuring compliance with security and audit standards.


Required skills include CRL and OCSP maintenance, AWS Key Vault, cloud and hybrid environments, and PowerShell scripting for automation.


Roles Responsibilities~ -Manage enterprise PKI infrastructure including Root and Issuing Certificate.


Responsibilities~ Manage certificate lifecycle activities~ issuance, renewal, revocation, rekey, rollover, and retirement.


Configure and maintain Offline Root CA, Issuing CAs, certificate templates/profiles, and policy constraints.


Manage CRL/OCSP publishing and ensure high availability.


Maintain PKI documentation aligned with standards like CP/CPS, operational runbooks, and SOPs.


Support audits and compliance requirements, including CAB Forum standards.


Manage and monitor PKI/HSM operations end-to-end, including health checks, backups, configurations, and policies.


Implement and maintain processes for managing internal and external certificate lifecycles.


Monitor certificates for expiration, perform timely renewals, and revoke compromised or obsolete certificates.


Possess strong technical expertise in Microsoft Active Directory Certificate Services (ADCS), including OCSP, CRLs, certificate templates, key archival, and NDES/SCEP.


Proficient in scripting and automation, especially PowerShell, with the ability to integrate PKI solutions across platforms such as network devices, load balancers, and Windows/Linux environments.


Have solid understanding of cryptography and encryption standards, including TLS, X.509, RSA/ECC, CSRs, and secure key management with HSMs and TPMs.


Hands-on experience with cloud-based certificate and key management; strong troubleshooting skills; exposure to AWS ACM/PCA, Venafi tools, and relevant security or PKI certifications is advantageous.


Assist with enterprise-wide certificate lifecycle tasks, including requests, issuance, renewal, and revocation.


Maintain and update inventories of machine identities, including certificates, keys, and service credentials.


Assist in identifying orphaned, expired, or misconfigured machine identities.


Monitor adherence to governance controls and escalate exceptions or risks.


Maintain accurate certificate inventory records, including ownership, purpose, and expiration dates.


Identify and report at-risk certificates, including expired, soon-to-expire, weak cryptography, or unknown owners.


Assist with certificate issuance requests and validate required information.


Demonstrate experience managing enterprise-scale PKI environments across on-premises and cloud platforms, including lifecycle management and automation (e.g., Venafi Trust Protection Platform).


Possess strong technical expertise in Microsoft Active Directory Certificate Services (ADCS), including OCSP, CRLs, certificate templates, key archival, and NDES/SCEP.


Knowledge of AD, DNS, IAM operations, and CyberArk Privilege Cloud is beneficial.


Required Skills~ Microsoft ADCS SCEP AWS PCA Venafi HSM & Encryption PKI & Certificate Management.


AD (Good to have) CyberArk (Good to have)#MatchpointWe may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses.


These tools assist our recruitment team but do not replace human judgment.


Final hiring decisions are ultimately made by humans.


If you would like more information about how your data is processed, please contact us.

Vagas Semelhantes

RemotoSão PauloOntem

R$ 9k - 14k/mês

PlenoCLT

About UsVisa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid.At Visa, ...

R$ 7k - 11k/mês

PlenoCLT

DescriptionWiFi has become a critical component to every home worldwide. eero, an Amazon Company, is the first product to deliver a whole home WiFi experience using mesh technology to make sure you never have to worry about connectivity ever again. We believe customers' deserve the best connectivity...

Y

Software Developer - Remote

YO IT ConsultingLinkedIn
RemotoBrazilOntem

R$ 7k - 11k/mês

PlenoCLT

Job Title: Software DeveloperJob Type: ContractLocation: RemoteJob SummaryJoin our customers team as a Software Developer, where innovation, ownership, and technical expertise drive every project. You’ll collaborate with a dynamic and diverse team to design, develop, and deliver robust solutions usi...

C

Cloud Security Engineer

ClicksignLinkedIn
RemotoBrazil3 dias atrás

R$ 7k - 11k/mês

PlenoCLT

Sobre a ClicksignSomos uma empresa brasileira líder em assinaturas eletrônicas. Em essência, facilitamos relações entre pessoas e empresas no ambiente digital. Por trás da nossa tecnologia de ponta e foco em segurança, temos a missão de fazer o mundo crescer, tornando as relações digitais cada vez m...

Interessado nesta vaga?

Candidatar-se

Você será redirecionado para o site original

Informações

NívelPleno
ContratoCLT
LocalSão Paulo
RemotoNão
MoedaBRL
Publicada3 dias atrás
FonteLinkedIn

Análise de Vaga com IA

Estimativa salarial, match de tecnologias e análise de requisitos feitos com Inteligência Artificial

Quer se preparar melhor? Pratique entrevistas com IA no Recrutadoria ou melhore suas habilidades no BitMentor

← Voltar às Vagas