The Role
Lead vulnerability management and PKI operations across hybrid infrastructure. Manage CrowdStrike vulnerability workflows, risk-based prioritization, remediation strategy, dashboards, and legacy-system risk. Own enterprise SSL/TLS certificate lifecycle management, PKI automation, monitoring, internal CA architecture, cryptography, and machine identity practices. Partner with infrastructure and cloud teams to drive remediation, automate ITSM workflows, and reduce security and certificate-related operational risk.
Summary Generated by Built In
Position Overview:
We are looking for a hands-on Security Engineer to lead vulnerability management and PKI operations within the Information Security Operations team. This role will engineer the vulnerability management lifecycle across our data center, endpoint, and cloud VM environments, driving remediation through strategic partnerships with infrastructure teams. In addition, the role will oversee Enterprise Machine Identity, managing the lifecycle of public-facing and internal SSL/TLS certificates while championing automation to eliminate manual toiland prevent certificate-related outages.
The ideal candidate brings deep expertise in Risk-Based Vulnerability Management (RBVM) using platforms like Crowdstrike, understands complex patching cycles across hybrid infrastructure, and is well-versed in automated certificate lifecycle management using tools like Sectigo or DigiCert. A strong technical foundation in modern internal CA/PKI architecture and cryptography principles is required
We are looking for a hands-on Security Engineer to lead vulnerability management and PKI operations within the Information Security Operations team. This role will engineer the vulnerability management lifecycle across our data center, endpoint, and cloud VM environments, driving remediation through strategic partnerships with infrastructure teams. In addition, the role will oversee Enterprise Machine Identity, managing the lifecycle of public-facing and internal SSL/TLS certificates while championing automation to eliminate manual toiland prevent certificate-related outages.
The ideal candidate brings deep expertise in Risk-Based Vulnerability Management (RBVM) using platforms like Crowdstrike, understands complex patching cycles across hybrid infrastructure, and is well-versed in automated certificate lifecycle management using tools like Sectigo or DigiCert. A strong technical foundation in modern internal CA/PKI architecture and cryptography principles is required
Job Responsibilities:
Vulnerability & Exposure Management
Engineer and mature the Crowdstrike Vulnerability Management platform, optimizing scan coverage, asset tagging, credential management, and API integrations.
Champion Risk-Based Vulnerability Management (RBVM) by contextualizing
vulnerabilities with threat intelligence (e.g., CISA KEV, EPSS, CVSS) to prioritize
remediation of high-risk assets.
Partner closely with infrastructure and cloud teams to drive remediation within established SLAs, transforming monthly patch meetings into data-driven risk discussions.
Design and maintain automated reporting dashboards and KPIs/KRIs to track scan health, remediation velocity, and overall risk reduction.
Formulate and drive the remediation strategy for End-of-Life (EOL) systems, acting as a primary advisor on legacy system risk mitigation.
Engineer and mature the Crowdstrike Vulnerability Management platform, optimizing scan coverage, asset tagging, credential management, and API integrations.
Champion Risk-Based Vulnerability Management (RBVM) by contextualizing
vulnerabilities with threat intelligence (e.g., CISA KEV, EPSS, CVSS) to prioritize
remediation of high-risk assets.
Partner closely with infrastructure and cloud teams to drive remediation within established SLAs, transforming monthly patch meetings into data-driven risk discussions.
Design and maintain automated reporting dashboards and KPIs/KRIs to track scan health, remediation velocity, and overall risk reduction.
Formulate and drive the remediation strategy for End-of-Life (EOL) systems, acting as a primary advisor on legacy system risk mitigation.
PKI, Cryptography & Machine Identity Management
Lead the Enterprise Certificate Lifecycle Management (CLM) strategy:
o Oversee issuance, renewals, and revocation of SSL/TLS certificates,ensuring
zero unplanned downtime due to expirations.
Lead the Enterprise Certificate Lifecycle Management (CLM) strategy:
o Oversee issuance, renewals, and revocation of SSL/TLS certificates,ensuring
zero unplanned downtime due to expirations.
o Drive PKI automation initiatives (e.g., utilizing ACME, SCEP, or REST APIs) to
transition from manual ServiceNow requests to zero-touch provisioning.
Architect and maintain proactive, continuous monitoring and alerting for all managed internal and public-facing certificates.
Manage certificate issuance processes through root authorities like DigiCert (including specialized certs like Verified Mark Certificates/VMC).
Act as the Subject Matter Expert (SME) for internal Certificate Authority (CA)
architecture, advising on cryptography best practices, key generation, and secure secrets management.
transition from manual ServiceNow requests to zero-touch provisioning.
Architect and maintain proactive, continuous monitoring and alerting for all managed internal and public-facing certificates.
Manage certificate issuance processes through root authorities like DigiCert (including specialized certs like Verified Mark Certificates/VMC).
Act as the Subject Matter Expert (SME) for internal Certificate Authority (CA)
architecture, advising on cryptography best practices, key generation, and secure secrets management.
Basic Qualifications:
5+ years of experience in IT security or infrastructure, with a specialized focus on vulnerability risk management and PKI operations.
Hands-on administrative experience with Crowdstrike Falcon Spotlight, Qualys, or similar enterprise-grade exposure management platforms.
Deep experience managing SSL/TLS certificates via platforms like Sectigo, DigiCert, or Venafi, with a strong track record of automating certificate deployments.
Solid understanding of vulnerability prioritization frameworks, infrastructure patching lifecycles, and integration with ITSM tools (e.g., ServiceNow/Jira for automated ticketing).
Strong technical grasp of internal PKI/CA principles, modern cryptography, and machine identity best practices.
Proven ability to influence cross-functional technical teams, driving remediation efforts without direct authority.
Excellent technical documentation and communication skills, capable of translating technical vulnerabilities into business risk.
Hands-on administrative experience with Crowdstrike Falcon Spotlight, Qualys, or similar enterprise-grade exposure management platforms.
Deep experience managing SSL/TLS certificates via platforms like Sectigo, DigiCert, or Venafi, with a strong track record of automating certificate deployments.
Solid understanding of vulnerability prioritization frameworks, infrastructure patching lifecycles, and integration with ITSM tools (e.g., ServiceNow/Jira for automated ticketing).
Strong technical grasp of internal PKI/CA principles, modern cryptography, and machine identity best practices.
Proven ability to influence cross-functional technical teams, driving remediation efforts without direct authority.
Excellent technical documentation and communication skills, capable of translating technical vulnerabilities into business risk.
Preferred Skills:
Experience integrating Vulnerability Management or PKI workflows with
orchestration/automation tools (e.g., Python, PowerShell, Ansible, or SOAR platforms).
Experience with External Attack Surface Management (EASM) or Cloud Security
Posture Management (CSPM) tools.
Advanced understanding of EOL system risk mitigation (network segmentation, virtual
patching).
Security certifications such as CISSP, CISM, GIAC (e.g., GSEC, GCIA), or specific
vendor certifications.
Bachelor's degree in Cybersecurity, Information Technology, or a related field
orchestration/automation tools (e.g., Python, PowerShell, Ansible, or SOAR platforms).
Experience with External Attack Surface Management (EASM) or Cloud Security
Posture Management (CSPM) tools.
Advanced understanding of EOL system risk mitigation (network segmentation, virtual
patching).
Security certifications such as CISSP, CISM, GIAC (e.g., GSEC, GCIA), or specific
vendor certifications.
Bachelor's degree in Cybersecurity, Information Technology, or a related field
We are proud to offer a competitive salary alongside a strong insurance package. We pride ourselves on the growth of our employees, offering extensive learning and development resources
Skills Required
- 5+ years of experience in IT security or infrastructure, specializing in vulnerability risk management and PKI operations
- Hands-on administrative experience with CrowdStrike Falcon Spotlight, Qualys, or similar enterprise exposure management platforms
- Deep experience managing SSL/TLS certificates using Sectigo, DigiCert, Venafi, or similar platforms
- Experience automating certificate deployments
- Understanding of vulnerability prioritization frameworks and infrastructure patching lifecycles
- Experience integrating security workflows with ITSM tools such as ServiceNow or Jira
- Strong understanding of internal PKI and Certificate Authority principles, modern cryptography, and machine identity best practices
- Ability to influence cross-functional technical teams and drive remediation without direct authority
- Strong technical documentation and communication skills, including translating vulnerabilities into business risk
- Experience integrating vulnerability management or PKI workflows with Python, PowerShell, Ansible, or SOAR platforms
- Experience with External Attack Surface Management or Cloud Security Posture Management tools
- Advanced understanding of end-of-life system risk mitigation, including network segmentation and virtual patching
- Security certification such as CISSP, CISM, GIAC, GSEC, or GCIA
- Bachelor's degree in Cybersecurity, Information Technology, or a related field
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Simfluent builds and operates global capability centers for modern enterprises. It creates fully integrated hubs that function as permanent extensions of clients’ businesses, with capabilities spanning engineering and platforms, cloud, architecture, product, data, and AI. Through greenfield, build-operate-transfer, and hybrid models, Simfluent helps organizations scale technology delivery while preserving quality, culture, strategic alignment, and local control, with predictable execution at enterprise scale.







