





Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Niche PKI/TLS specialization and seniority lower applicant competition despite metro location.
High—specialized PKI/TLS and certificate lifecycle skills are not easily transferable across industries.
Explicit 7+ years and 3+ years PKI requirement plus mandatory tools, cloud, IaC, and regulated/audit experience.
Lead technical architecture and operational maturity of TLS, PKI, and certificate lifecycle management across on-premises and multi-cloud (AWS, Azure, GCP) environments.
Drive automation, inventory accuracy, renewal workflows, and TLS monitoring to prevent outages and reduce manual work using platforms like Venafi and cloud-native services.
Mentor engineers, collaborate cross-functionally on trust policy and deployment patterns, and resolve complex TLS issues including mutual TLS and load balancer certificate integrations.
7+ years in infrastructure, security, network engineering, or platform operations with 3+ years focused on PKI, TLS, or certificate lifecycle management in enterprise environments.
Deep expertise in TLS 1.2/1.3, X.509, public/private PKI, certificate chains, and deployment patterns including mTLS.
Hands-on experience with certificate lifecycle management platforms (Venafi or equivalent), cloud-native certificate/key services (AWS ACM, Azure Key Vault, GCP Certificate Manager), and load balancer certificate operations.
Work Experience Required: 7+ years total with 3+ years in PKI/TLS/certificate management; Location or notice period: Not explicitly mentioned in the JD.
Technical leader with strong cross-team collaboration skills to drive incremental improvements in certificate automation and TLS deployment at scale in complex enterprise and multi-cloud setups.
Experienced in operationalizing certificate lifecycle fully including inventory, renewal automation, monitoring, and managing trust anchors, with a focus on preventing production outages.
Hands-on troubleshooter comfortable explaining TLS handshake failures, trust store issues, and leading mTLS or hybrid cloud certificate programs; able to mentor junior engineers on deep TLS/PKI concepts.