What are the responsibilities and job description for the Certificate Lifecycle / PKI Engineer with Venafi Expertise position at Northern Base?
Hiring Alert | Certificate Lifecycle / PKI Engineer with Venafi Expertise
Location: Chicago, IL (Remote)
Employment Type: Full-Time
Experience Required: 8–15 Years
Must-Have Skills:
- Public Key Infrastructure (PKI) and Cryptography
- X.509 Certificates, TLS/SSL, Certificate Authorities
- CRL, OCSP, Key Management, and HSM
- Root and Intermediate CA Management
- Code Signing Certificates
- Venafi Trust Protection Platform (TPP)
- Venafi SaaS and Certificate Discovery
- Certificate Automation and Lifecycle Workflows
- Venafi APIs, Adaptable Apps, and Native Drivers
- Certificate Reporting and Governance
- Windows IIS, Linux/Unix, Apache, Tomcat, WebLogic
- Microsoft Azure and Azure Key Vault
- Kubernetes and F5 Load Balancers
- ServiceNow Integrations
- GitHub Actions, Azure DevOps, and CI/CD Pipelines
- PowerShell, Python, REST APIs, and Ansible
- Identity and Access Management (IAM)
- Authentication, Authorization, and Secrets Management
- Zero Trust and Cloud Security
Preferred Experience:
- Entra ID / Azure AD
- Microsoft Entra Permissions Management (EPM)
- Microsoft Sentinel and KQL
- AWS Security
- Okta and PingFederate
- OAuth, OIDC, SAML, SSO, MFA, and Conditional Access
- JWT and Session Management
- API Security and Application Registration
- CIEM and Privileged Identity Management
- Threat Modeling and OWASP
- Docker and Kubernetes Security
- Kafka and Solace
- Java Microservices and React Applications
- Azure Application Gateway, WAF, NSGs, DLP, VPN, DNS, and CDN
- Infrastructure and Security Automation
Key Responsibilities:
- Lead identity-centric workforce security initiatives focused on authentication and access management
- Develop identity solutions using Zero Trust, least privilege, and defense-in-depth principles
- Design and implement certificate lifecycle and PKI automation solutions
- Support Entra ID identity, authentication flows, and modern identity patterns
- Review and provide security guidance on identity and access management solutions
- Troubleshoot complex identity and certificate-related issues using Sentinel, KQL, audit logs, and platform tools
- Support OAuth/OIDC flows, authorization patterns, identity federation, cryptography, and cloud-native security
- Develop security solutions for microservices, frontend, and mobile applications
- Support code signing, certificate authentication, TLS/SSL, API security, and application integrations
- Contribute to CIEM, RBAC, PAM, JIT access, secrets management, and identity governance solutions
- Apply threat modeling, application security, and OWASP security practices
- Support container and Kubernetes security initiatives
- Collaborate with stakeholders and provide security consultation to IT management and technology teams
Education:
- Bachelor's Degree in Computer Science or related field preferred