As a Public Key Infrastructure Specialist, you will design, implement, administer, and support the organisation's PKI environment. You will be responsible for certificate lifecycle management, CA administration, cryptographic compliance, automation of certificate operations, and integration with enterprise applications and security platforms.
What You'll Do and How You'll Succeed
PKI Administration & Lifecycle Management
- You manage and maintain enterprise PKI infrastructure, including Certificate Authorities (CA), Registration Authorities (RA), and certificate management platforms.
- You administer end‑to‑end certificate lifecycle management - issuance, renewal, revocation, replacement, and expiry tracking.
- You deploy and support SSL/TLS certificates across servers, middleware, databases, web applications, APIs, and network devices.
- You implement certificate discovery, inventory management, and compliance reporting.
Cryptography & Security Compliance
- You manage cryptographic keys and Hardware Security Modules (HSMs) in line with security standards.
- You develop automation scripts, APIs, and workflows for certificate provisioning and renewal.
- You support PKI integrations with enterprise tools such as monitoring, ITSM, vulnerability management, and secrets management.
- You troubleshoot certificate, authentication, encryption, and trust‑chain issues.
- You maintain PKI operational procedures, standards, and audit documentation.
Modernisation & Governance
- You collaborate with application, infrastructure, cybersecurity, and vendor teams on PKI projects.
- You support modernisation initiatives including TLS 1.3 adoption, certificate governance, and Post‑Quantum Cryptography (PQC) readiness.
We'd Love to Hear From You If...
Experience
- You have 10+ years of PKI, cybersecurity, or infrastructure security experience.
- You have experience in banking or financial services environments.
- You have supported certificate lifecycle management (CLM) platforms and automation solutions.
Technical Expertise
- You have strong understanding of PKI, X.509 Certificates, CAs, CRLs, TLS/SSL, and OCSP.
- You have experience with Microsoft ADCS, DigiCert, Entrust, Keyfactor, Venafi, AppViewX, or similar PKI platforms.
- You know cryptographic technologies including RSA, ECC, AES‑256, SHA‑2/SHA‑3, TLS 1.2/1.3.
- You have hands‑on experience with Windows and Linux platforms.
- You are proficient in scripting (PowerShell, Python, Shell).
- You understand HSMs, RBAC, audit controls, and compliance requirements.
- You have experience integrating PKI with enterprise applications, middleware, and databases.
Ways of Working
- You demonstrate strong problem‑solving and troubleshooting skills.
- You collaborate effectively with application, infrastructure, and cybersecurity teams.
- You maintain rigorous documentation and governance practices.
- You proactively support modernisation and security readiness initiatives.
Preferred Qualifications
- You hold certifications such as CISSP, CISM, Security+, or PKI‑related credentials.
- You have Infosec or PKI specialisation certifications (advantage).