We are looking for an experienced Senior PKI Engineer to design, implement, administer, and support an enterprise Public Key Infrastructure (PKI) environment within a regulated banking environment.
The role will focus on certificate lifecycle management, Certificate Authority administration, cryptographic key management, PKI automation, security compliance, and integration with enterprise applications and infrastructure platforms.
This position will also support the organisation's PKI Certificate Lifecycle Management (CLM) programme and ensure secure, reliable, and compliant management of digital certificates across the enterprise.
Key Responsibilities
- Manage and maintain enterprise PKI infrastructure, including Certificate Authorities (CA), Registration Authorities (RA), and certificate management platforms.
- Administer end-to-end certificate lifecycle management, including issuance, renewal, revocation, replacement, and expiry tracking.
- Deploy and support SSL/TLS certificates across servers, middleware, databases, web applications, APIs, and network devices.
- Implement certificate discovery, inventory management, monitoring, and compliance reporting.
- Manage cryptographic keys and Hardware Security Modules (HSMs) in line with security standards and governance requirements.
- Develop and maintain automation scripts, APIs, and workflows for certificate provisioning and renewal.
- Integrate PKI solutions with enterprise applications, middleware, databases, monitoring tools, ITSM platforms, vulnerability management tools, and secrets-management solutions.
- Troubleshoot certificate, authentication, encryption, trust-chain, and TLS-related issues.
- Maintain PKI operational procedures, standards, audit documentation, and governance controls.
- Collaborate with application, infrastructure, cybersecurity, and vendor teams on PKI initiatives and certificate deployments.
- Support modernisation initiatives including TLS 1.3 adoption, certificate governance, and Post-Quantum Cryptography (PQC) readiness.
Requirements
- Minimum 10 years of experience in PKI, Cybersecurity, Infrastructure Security, or a closely related field.
- Banking / Financial Services experience is mandatory.
- Strong hands-on experience in Public Key Infrastructure (PKI) and Certificate Lifecycle Management.
- Strong knowledge of X.509 Certificates, CA, RA, CRL, OCSP, SSL/TLS.
- Experience with PKI / CLM platforms such as Microsoft ADCS, DigiCert, Entrust, Keyfactor, Venafi, AppViewX, or similar solutions.
- Hands-on experience with HSMs and cryptographic key management.
- Good understanding of cryptographic technologies including RSA, ECC, AES-256, SHA-2/SHA-3, TLS 1.2/1.3.
- Strong experience with Windows and Linux environments.
- Scripting experience using PowerShell, Python, or Shell scripting.
- Experience integrating PKI with applications, APIs, middleware, databases, and enterprise security platforms.
- Familiarity with RBAC, audit controls, security compliance, and governance requirements.
- Strong troubleshooting, analytical, and stakeholder-management skills.
Registration No.: R25156061
EA No.: 11C3373