Certificate MGMT or Microsoft PKI Engineer

Reposted 2 Days Ago
Be an Early Applicant
Hiring Remotely in Metro Manila, PHL
Remote
Senior level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
The Role
The role involves managing PKI infrastructure, overseeing certificate lifecycle operations, automating processes, integrating with platforms, and ensuring compliance with industry standards.
Summary Generated by Built In
Requisition Number: 2352031
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
Positions in this function design, engineer, and manage the organization's infrastructure and operational platforms. From a cloud services model, this includes services commonly thought of as IaaS and PaaS and their underlying foundational components. Additionally, this function also has responsibility for traditional enterprise infrastructure and operational platforms such as email, file transfer, and collaboration technologies, among others. This role must understand functional and non-functional requirements to ensure they can be achieved through system design and engineering to meet the needs of the customers. Work closely with business and technology stakeholders to develop roadmaps for their respective technology portfolios, resolve cross-system and domain dependencies, ensure effective integration among the services offered to the end customer, and efficient usage of infrastructure and operational platforms. Monitor technological advancements and industry trends to influence company standards and ensure that solutions are continuously improved and maintained through product management practices, including recommendations to invest in a solution or retirement of redundant or out-of-date systems. Understand the interactions between systems, the applications and services hosted, and evaluate the impact of changes and additions. Perform analysis on existing systems to ensure performance and reliability, enhance scalability, meet security requirements, and interoperable and maintainable technology portfolio.
Primary Responsibilities:
  • Certificate & PKI Administration
    • Administer and support enterprise PKI infrastructure, including Root and Issuing CAs.
    • Manage certificate issuance, renewal, revocation, and retirement for:
      • Internal server certificates
      • External/public TLS certificates
      • Load balancers, proxies, and gateways
      • Application and service certificates
    • Maintain certificate templates, enrollment policies, and validity standards.
    • Operate and monitor CRL, OCSP, and certificate distribution endpoints.
    • Perform routine PKI health checks, audits, and lifecycle reviews.
  • Certificate Lifecycle Operations
    • Proactively monitor certificate expiration across environments and prevent outages.
    • Execute planned certificate rotations with zero or minimal downtime.
    • Respond to certificate-related incidents, including expired, misconfigured, or revoked certificates.
    • Maintain certificate inventory, ownership metadata, and renewal methods.
    • Support external CA interactions for publicly trusted certificates (e.g., domain validation, reissuance).
  • Automation & Operational Enablement
    • Leverage existing automation tools and platforms to streamline:
      • Certificate renewals
      • Certificate deployment to servers, load balancers, and platforms
    • Perform light scripting (PowerShell, shell, or Python) for:
      • Operational automation
      • Reporting
      • Certificate discovery
    • Work with automation and platform teams to integrate certificate management into:
      • Infrastructure workflows
      • Load balancer or ingress updates
    • Maintain and execute runbooks for automated and manual certificate processes.
    • Note: This role does not require building complex applications or frameworks. Automation is focused on operational reliability and efficiency, not software development.
  • Compute & Platform Integration
    • Install, update, and maintain certificates on:
      • Windows and Linux servers
      • Web servers (IIS, Apache, Nginx)
      • Reverse proxies and load balancers (F5, HAProxy, Citrix, etc.)
    • Support certificate needs for:
      • Virtual machines
      • Container platforms (Kubernetes, OpenShift - operational use)
      • Cloud workloads
    • Coordinate with network and security teams to implement TLS standards and policies.
  • Governance, Risk & Compliance
    • Ensure certificates meet enterprise standards for:
      • Key sizes
      • Algorithms
      • Validity periods
      • Naming conventions and SAN rules
    • Support audits and compliance activities (SOX, PCI, ISO, internal security reviews).
    • Maintain documentation for PKI architecture, renewal processes, and operational procedures.
  • Analyzes and investigates
  • Provides explanations and interpretations within area of expertise
  • Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so

Required Qualifications:
  • Undergraduate degree or equivalent experience.
  • 5+ years in compute, infrastructure, or systems administration
  • 3+ years hands on experience managing PKI and certificate services
  • 3+ years hands on experience managing certificates and PKI in production environments
  • Proven experience supporting infrastructure platforms at scale
  • Solid operational experience with:
    • Certificate issuance and renewals
    • Internal and external certificates
    • Enterprise infrastructure environments
    • Technical Skills (Administrator-Level)
  • Experience administering Microsoft AD CS and/or enterprise PKI tools.
  • Hands on experience deploying certificates to:
    • Windows/Linux servers
    • IIS, Apache, Nginx
    • Load balancers or reverse proxies
  • Hands on administration of:
    • Microsoft AD CS or similar PKI platforms
    • Windows and Linux server environments
  • Experience managing certificates on:
    • Web servers (IIS, Apache, Nginx)
    • Load balancers or reverse proxies
  • Solid understanding of:
    • X.509 certificates
    • TLS / HTTPS
    • Certificate chains and trust models
    • Certificate chaining and trust relationships
  • Familiarity with certificate tooling such as:
    • Venafi, Keyfactor, AppViewX, DigiCert, Sectigo (any one or more)
  • Working knowledge of:
    • PowerShell and/or basic Python or shell scripting
    • ITSM tools (e.g., ServiceNow)
    • Basic scripting for administrative automation
  • Familiarity with enterprise certificate platforms (any of):
    • Venafi
    • Keyfactor
    • AppViewX
    • DigiCert / Sectigo

Preferred Qualifications:
  • Experience with cloud certificate services (AWS ACM, Azure Key Vault Certificates).
  • Operational experience with Kubernetes certificates (supporting cert manager or ingress certs)
  • Experience using ITSM tools (ServiceNow or similar)
  • Exposure to Kubernetes certificate administration (cert-manager from an ops perspective).
  • Exposure to cloud compute certificate services (AWS ACM, Azure Key Vault Certificates)
  • Background supporting regulated or audited environments
  • Familiarity with:
    • HSM-backed key storage
    • Code-signing certificates
    • Device or service identity certificates
  • Security or infrastructure certifications

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
Optum is a drug-free workplace. © 2026 Optum Global Solutions (Philippines) Inc. All rights reserved.

Skills Required

  • Undergraduate degree or equivalent experience
  • 5+ years in compute, infrastructure, or systems administration
  • 3+ years managing PKI and certificate services
  • 3+ years managing certificates and PKI in production environments
  • Experience administering Microsoft AD CS and/or enterprise PKI tools
  • Hands on experience deploying certificates to Windows/Linux servers
  • Solid understanding of X.509 certificates and TLS/HTTPS
  • Familiarity with certificate tooling such as Venafi or Keyfactor

What the Team is Saying

Optum Compensation & Benefits Highlights

  • Healthcare Strength Health coverage offers multiple plan types with employer HSA contributions, in‑network preventive care at 100%, and included 24/7 virtual visits, alongside dental and vision options. This breadth allows predictable copay choices or tax‑advantaged HSA designs to fit different usage needs.
  • Retirement Support Retirement programs include a 401(k) with employer match eligibility and full vesting over time plus an Employee Stock Purchase Plan at a discount. Together these elements support long‑term savings and ownership.
  • Parental & Family Support Family supports include six weeks paid parental leave, paid caregiver leave, adoption assistance, and subsidized Bright Horizons back‑up care. Emotional well‑being resources like a premium Calm subscription and a 24/7 EAP complement these supports.

Optum Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Eden Prairie, MN
160,000 Employees
Year Founded: 2011

What We Do

Optum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.

Gallery

Gallery
Gallery
Gallery

Optum Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Optum has three workplace models that balance the needs of the business and the responsibilities of each role. These models, core on‑site (5 days/week), hybrid (4 days/week) and telecommute or fully remote, vary by country, role and location.

Typical time on-site: Not Specified
HQEden Prairie, MN
Philippines
Ann Arbor, MI
Atlanta, GA
Baltimore, MD
Belfast, GB
Bengaluru, India
Chennai, India
Dallas, TX
Detroit, MI
Hartford, CT
Houston, TX
Hyderabad, India
Jacksonville, FL
Las Vegas, NV
Louisville, KY
Madison, WI
Minneapolis, MN
Nashville, TN
New Delhi, India
Philadelphia, PA
Phoenix, AZ
Pune, India
Raleigh, NC
San Diego, CA
Washington, DC
Learn more

Similar Jobs

Optum Logo Optum

Machine Learning Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Remote
Metro Manila, PHL
160000 Employees

Optum Logo Optum

Azure Local HCI and Wintel Admin

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Remote
Metro Manila, PHL
160000 Employees

Optum Logo Optum

Consultant

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Remote
Metro Manila, PHL
160000 Employees

Optum Logo Optum

Security Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Remote
Metro Manila, PHL
160000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account