





Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Niche PKI/TLS role reduces applicant pool despite metro location and recognizable company brand.
Highly specialized PKI/TLS expertise makes candidate experience less transferable across generalist roles.
Explicit 7+ years and 3+ years PKI experience plus mandatory Venafi/cloud/tool expertise.
Lead technical strategy and operations for enterprise TLS, PKI, and certificate lifecycle across on-premises, hybrid, and multi-cloud environments (AWS, Azure, GCP).
Own end-to-end certificate lifecycle management including inventory, renewal automation, trust-chain management, and TLS monitoring to reduce outages and audit risk.
Mentor engineers on TLS/PKI fundamentals, drive incremental maturity programs, and collaborate cross-functionally on trust policies and certificate integrations including load balancers and mTLS.
7+ years experience in infrastructure, security, network engineering or platform operations, including 3+ years specifically in PKI, TLS, or certificate lifecycle management in production enterprise environments.
Hands-on experience with certificate lifecycle management platforms like Venafi or equivalents.
Experience with cloud-native certificate services (AWS ACM, Azure Key Vault, GCP Certificate Manager/Authority Service) and installing/configuring certificates on load balancers/edge platforms (e.g., F5, Citrix, AWS ALB).
Work Experience Required: 7+ years in relevant domains with 3+ years PKI/TLS focus; Notice period: Not explicitly mentioned in the JD.
Deep expertise in TLS 1.2/1.3, X.509, public/private PKI, certificate chains, and automation-first renewal practices aligned with industry trends.
Proven ability to lead technical workstreams, mentor engineers, and partner effectively with Security, Network, Cloud, and Platform teams in complex enterprise environments.
Experience designing and implementing TLS observability, automated certificate inventories, mTLS programs at scale, and infrastructure-as-code workflows for certificate provisioning and rotation.