The candidate will be responsible for managing enterprise PKI platforms, automating certificate lifecycle processes, supporting code-signing solutions, and driving strategic PKI modernization initiatives across on-premises and cloud environments.
The role requires hands-on expertise in Microsoft ADCS, Venafi, Sectigo CLM, cloud-native certificate management, and associated cryptographic technologies. The individual should be capable of independently driving projects end-to-end with minimal supervision while collaborating effectively with technical and business stakeholders.
What You'll Do:- Manage and support enterprise Public Key Infrastructure (PKI) environments.
- Install, configure, upgrade, and maintain Microsoft Active Directory Certificate Services (ADCS) Certification Authorities.
- Manage Root CA, Issuing CA, CRL Distribution Points (CDP), OCSP Responders, NDES, Certificate Templates, and Registration Authorities.
- Perform certificate issuance, renewal, revocation, replacement, and lifecycle management activities.
- Monitor PKI infrastructure health, availability, performance, and security.
- Handle day-to-day PKI operational activities and service requests.
- Troubleshoot certificate enrollment, renewal, installation, and trust-chain-related issues across various platforms.
- Support cryptographic controls and ensure PKI environments comply with organizational security standards.
- Manage enterprise Certificate Lifecycle Management (CLM) platforms including:
- Venafi TLS Protect
- Sectigo Certificate Manager / CLM
- AppViewX (desirable)
- Design and implement automated certificate lifecycle management processes.
- Manage and support automation initiatives associated with shorter certificate validity periods (45-day certificate lifecycle and future industry requirements).
- Monitor certificate expirations and proactively coordinate renewals to prevent service outages.
- Reduce manual certificate management activities through workflow automation and orchestration.
- Administer and maintain Venafi platform components.
- Configure certificate policies, workflows, application integrations, and automated enrolment processes.
- Troubleshoot Venafi platform and integration issues.
- Implement certificate discovery, inventory management, and compliance monitoring.
- Onboard applications and infrastructure components into Venafi-managed certificate automation frameworks.
- Develop and deploy certificate lifecycle automation using Venafi APIs, workflows, and integrations.
- Integrate Venafi with cloud, container, DevOps, and enterprise platforms.
- Design and implement enterprise code-signing solutions.
- Integrate Venafi Code Signing capabilities with development and CI/CD platforms.
- Support code-signing certificates, signing workflows, key protection, and audit requirements.
- Collaborate with development teams to secure software build and release processes.
- Support S/MIME certificate management and email encryption initiatives.
- Implement and manage certificate automation for cloud and containerized environments.
- Integrate Sectigo CLM and Venafi with:
- Kubernetes
- AWS Certificate Manager (ACM)
- Cloud-native services
- Load balancers
- Application gateways
- Service meshes
- Support certificate management across hybrid cloud environments.
- Enable automated certificate provisioning, rotation, and renewal for cloud-native applications.
- Support and administration of:
- Microsoft ADCS PKI Clusters
- Entrust HSM
- Venafi Platform
- Sectigo CLM
- OCSP Responders
- Certificate Templates
- NDES Infrastructure
- S/MIME Solutions
- External Certificate Authorities
- Code Signing Infrastructure
- Entrust Products
- Sectigo Products
- Other cryptographic and certificate management solutions
- Review PKI audit findings and compliance requirements.
- Identify PKI risks, vulnerabilities, and remediation actions.
- Conduct security assessments of PKI infrastructure and applications.
- Participate in cyber security incident response involving certificates and cryptographic systems.
- Ensure compliance with organizational policies, industry standards, and regulatory requirements.
- Identify and remediate self-signed, expired, rogue, and non-compliant certificates.
- Drive certificate governance, risk reduction, and PKI security improvements.
- Address certificate-related vulnerabilities and strengthen cryptographic controls.
- Provide L2/L3 support for PKI and certificate management platforms.
- Troubleshoot:
- Certificate enrollment failures
- Trust chain issues
- Certificate renewals
- TLS/SSL configuration issues
- Application integration problems
- Venafi and Sectigo platform issues
- ServiceNow workflow issues
- Support certificate deployment and installation activities across Windows and Linux platforms.
- Lead PKI and certificate automation projects from initiation to completion.
- Act as a technical lead for onboarding applications and services to PKI platforms.
- Drive transformation initiatives related to certificate automation, code signing, and cloud certificate management.
- Coordinate with infrastructure, application, cloud, DevOps, and security teams.
- Manage project timelines, risks, dependencies, and stakeholder communications.
- Demonstrate ownership and accountability for deliverables.
- Operate independently with minimal supervision and follow-up.
- Drive continuous improvement initiatives across PKI services.
- Create and maintain:
- Operational procedures
- Architecture documentation
- Technical runbooks
- Standard operating procedures (SOPs)
- Knowledge articles
- Disaster recovery documentation
- Provide knowledge transfer sessions and technical guidance to team members.
- 5+ years of PKI and Certificate Lifecycle Management experience.
- Experience installing, configuring, and managing Microsoft Certificate Authorities.
- Hands-on experience managing Venafi and/or Sectigo CLM platforms.
- Experience implementing certificate automation solutions.
- Experience supporting enterprise code-signing infrastructure.
- Experience integrating certificate management solutions with cloud and container platforms.
- Experience executing PKI transformation and automation projects.
- Strong understanding of:
- Public Key Infrastructure (PKI)
- X.509 Digital Certificates
- Digital Signatures
- Symmetric Encryption
- Asymmetric Encryption
- Hybrid Encryption Models
- Certificate Authorities (CA)
- Registration Authorities (RA)
- CRL
- OCSP
- NDES
- Certificate Templates
- TLS/SSL Protocols
- HSM Technologies
- Microsoft ADCS Administration.
- Venafi TLS Protect.
- Sectigo Certificate Manager (CLM).
- AppViewX (preferred).
- Entrust HSM.
- Code Signing Solutions.
- S/MIME Support.
- Windows Server Administration.
- Linux Server Administration.
- PowerShell Scripting.
- REST APIs.
- Automation Frameworks.
- Kubernetes Certificate Management.
- AWS Certificate Manager (ACM).
- ServiceNow.
- Self-driven and highly motivated.
- Ability to work independently with minimal supervision.
- Strong ownership mindset and accountability.
- Excellent stakeholder management skills.
- Strong project management and coordination capabilities.
- Excellent written and verbal communication skills.
- Strong analytical and problem-solving abilities.
- Proven ability to drive projects end-to-end and deliver results.
- Ability to communicate effectively with both technical and non-technical audiences.
- Venafi Certified Professional.
- Microsoft Certified: Windows Server / Security Certifications.
- CISSP.
- CompTIA Security+.
- Certified Information Security Manager (CISM).
Simeio has over 650 talented employees across the globe. We have offices in USA (Atlanta HQ and Texas), India, Canada, Costa Rica and UK.
Founded in 2007, and now backed by private equity company ZMC, Simeio is recognized as a top IAM provider by industry analysts.
Alongside Simeio’s identity orchestration tool ‘Simeio IO’ - Simeio also partners with industry leading IAM software vendors to provide access management, identity governance and administration, privileged access management and risk intelligence services across on-premise, cloud, and hybrid technology environments.
Simeio provides services to numerous Fortune 1000 companies across all industries including financial services, technology, healthcare, media, retail, public sector, utilities and education.
Diversity & InclusionSimeio is an equal opportunity employer. If you require assistance with completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our recruitment team - [email protected].
Thank you.
About Your ApplicationWe carefully review every application we receive. If your skills and experience match our needs, we’ll be in touch. If you don’t hear from us within 10 days, please don’t be discouraged. We may retain your application for future opportunities. We also encourage you to check our careers page for other openings.
Skills Required
- 4-7 years of experience supporting Public Key Infrastructure environments
- Understanding of PKI concepts, digital certificates, digital signatures, certification authorities, CRLs, OCSP, NDES, certificate templates, and encryption technologies
- Hands-on experience with Microsoft Active Directory Certificate Services
- Experience administering certificate lifecycle management platforms such as Venafi and/or AppViewX
- Prior L1/L2 operational support experience in PKI and certificate management environments
- Understanding of certificate lifecycle processes including issuance, renewal, revocation, expiration management, and deployment
- Experience troubleshooting certificate installation and configuration issues across enterprise applications and servers
- Hands-on experience with Windows and Linux server certificate configuration, deployment, and troubleshooting
- Experience supporting enterprise cryptographic products and solutions
- Familiarity with ServiceNow workflows and IT service management processes
- Understanding of PKI auditing, risk assessment, security controls, and compliance requirements
- Strong analytical, troubleshooting, and problem-solving skills
- Excellent verbal and written communication skills with technical and non-technical stakeholders
- Experience with Entrust HSM administration and support
- Experience managing ADCS PKI clusters
- Knowledge of S/MIME implementation and support
- Experience with code-signing certificate management
- Familiarity with external Certificate Authorities such as Entrust and Sectigo
- Exposure to PKI automation and scripting using PowerShell
- Relevant security, PKI, or Microsoft certifications
What We Do
Customers of all sizes globally rely on Simeio to help secure their organizations. An innovative and industry leader, Simeio offers professional services, Identity and Access Management (IAM) managed services and Identity as a Service (IDaaS). Its full range of services is powered by an industry-first IAM Virtualization Platform delivered via Simeio's Identity SOC. Simeio's Identity SOC is the first and only solution of its kind designed specifically to operate, monitor, and defend complex multi-vendor IAM infrastructures and deliver actionable business intelligence. Simeio's client base is expanding as interest in identity and access management and IT governance, risk and compliance grows across all sectors. Headquartered in Atlanta, Georgia, Simeio has operations in India, the United Kingdom, Europe, across North America, South America and Canada. We are a cutting-edge growing company with a strong dedication to our employees and their opportunity for growth and success. Simeio offers a state-of-the-art technology office with plans for continued growth and expansion. Our company culture is crucial to those driven for success with an entrepreneurial spirit, solution oriented, and individual contributors, as well as, team players.






