





Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Niche PKI/TLS specialization reduces applicants, but metro location and recognizable employer raise competition.
Highly specialized PKI/TLS and cloud-certificate expertise limits transferability across industries.
Explicit 7+ years, mandatory PKI/TLS, Venafi/cloud and regulated security experience create stringent shortlisting filters.
Lead technical ownership for enterprise TLS, PKI, and certificate lifecycle management across on-premise, hybrid, and multi-cloud (AWS, Azure, GCP) environments.
Drive automation and observability of certificate inventory, renewal, trust-chain management, and TLS monitoring to reduce outages and audit risks.
Provide hands-on technical leadership including troubleshooting TLS handshake failures and mentoring engineers on TLS/PKI concepts and operational best practices.
7+ years experience in infrastructure, security engineering, network engineering, or platform operations, including 3+ years in PKI, TLS, or certificate lifecycle management in production.
Deep expertise in TLS 1.2/1.3, X.509, public/private PKI, mTLS, certificate chains, and lifecycle management platforms (e.g., Venafi).
Experience with cloud-native certificate services on AWS ACM, Azure Key Vault, and GCP Certificate Manager / Certificate Authority Service.
Experience installing, binding, and rotating certificates on software/hardware load balancers (e.g., F5, Citrix, AWS ALB/NLB).
Experienced hands-on technical lead able to handle complex TLS/PKI operational issues and lead cross-team workstreams for automation and monitoring maturity.
Skilled at collaborating with security, network, cloud, and platform teams to implement standard, scalable certificate and trust solutions across multi-cloud environments.
Proven mentor and educator in TLS fundamentals with a focus on repeatable patterns and operational excellence in a security-aware environment.