Lead Identity Engineer - PKI / Venafi

Bangalore, Karnataka, India
Full Time
Experienced

About the Role:

The PKI / Venafi Engineer is responsible for the administration, support, and optimization of Public Key Infrastructure (PKI) services and certificate lifecycle management platforms. This role focuses on managing digital certificates, supporting cryptographic services, maintaining PKI environments, and ensuring secure certificate operations across enterprise systems. The engineer will work closely with internal teams and external partners to provide operational support, troubleshooting, automation, and continuous improvement of PKI and Venafi services.

What You'll Do:

  • Manage and support enterprise PKI environments, including Microsoft Active Directory Certificate Services (ADCS) and certificate lifecycle management platforms such as Venafi.
  • Handle day-to-day certificate management operations, including certificate issuance, renewal, revocation, replacement, and expiration management.
  • Monitor PKI systems, certificate inventories, and platform health to ensure service availability and compliance.
  • Troubleshoot certificate-related issues across Windows, Linux, and application environments.
  • Support certificate installation activities and provide guidance to application and infrastructure teams.
  • Maintain and troubleshoot Venafi workflows, integrations, and ServiceNow-related certificate processes.
  • Create, manage, and publish certificate templates within Microsoft ADCS environments.
  • Monitor certificate expiration schedules and proactively coordinate renewals with stakeholders.
  • Review PKI audit requirements, identify security risks, and implement remediation actions.
  • Support and maintain HSM-integrated PKI environments and cryptographic infrastructure.
  • Assist with external certificate management, S/MIME certificates, and code-signing certificate operations.
  • Collaborate with internal teams and external vendors to ensure seamless integration and operation of PKI services.
  • Develop and maintain operational procedures, technical documentation, and user guides related to PKI systems and certificate management.
  • Participate in incident, problem, and change management activities while adhering to organizational standards and security policies.
What You Bring:
  • 4-7 years of experience supporting Public Key Infrastructure (PKI) environments.
  • Solid understanding of PKI concepts including digital certificates, digital signatures, certification authorities, CRLs, OCSP, NDES, certificate templates, and encryption technologies (symmetric, asymmetric, and hybrid encryption).
  • Hands-on experience with Microsoft Active Directory Certificate Services (ADCS).
  • Experience administering certificate lifecycle management platforms such as Venafi and/or AppViewX.
  • Prior L1/L2 operational support experience in PKI and certificate management environments.
  • Strong understanding of certificate lifecycle processes including issuance, renewal, revocation, expiration management, and deployment.
  • Experience troubleshooting certificate installation and configuration issues across enterprise applications and servers.
  • Hands-on experience with Windows and Linux server certificate configuration, deployment, and troubleshooting.
  • Experience supporting enterprise cryptographic products and solutions.
  • Familiarity with ServiceNow workflows and IT service management processes.
  • Understanding of PKI auditing, risk assessment, security controls, and compliance requirements.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent verbal and written communication skills with the ability to engage technical and non-technical stakeholders.
Nice to Have:
  • Experience with Entrust HSM administration and support.
  • Experience managing ADCS PKI clusters.
  • Knowledge of S/MIME implementation and support.
  • Experience with code-signing certificate management.
  • Familiarity with external Certificate Authorities such as Entrust and Sectigo.
  • Exposure to PKI automation and scripting using PowerShell.
  • Relevant security, PKI, or Microsoft certifications.

About Simeio and What We Do

Simeio has over 650 talented employees across the globe. We have offices in USA (Atlanta HQ and Texas), India, Canada, Costa Rica and UK.

Founded in 2007, and now backed by private equity company ZMC, Simeio is recognized as a top IAM provider by industry analysts.

Alongside Simeio’s identity orchestration tool “Simeio IO”, Simeio partners with industry-leading IAM software vendors to provide access management, identity governance and administration, privileged access management, and risk intelligence services across on-premises, cloud, and hybrid technology environments.

Simeio provides services to numerous Fortune 1000 companies across all industries including financial services, technology, healthcare, media, retail, public sector, utilities, and education.

Diversity & Inclusion

Simeio is an equal opportunity employer. If you require assistance with completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our recruitment team at [email protected].

About Your Application

We carefully review every application we receive. If your skills and experience match our needs, we'll be in touch. If you don't hear from us within 10 days, please don't be discouraged. We may retain your application for future opportunities, and we encourage you to check our careers page for other openings.

Simeio is an equal opportunity employer. If you require assistance with completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to any of the recruitment team at recruitment@simeio.com or +1 404-882-3700.

Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*