MisuJob - AI Job Search Platform MisuJob

PKI Engineer

Distro

São Paulo, São Paulo Remote permanent

Posted: March 16, 2026

Interested in this position?

Create a free account to apply with AI-powered matching

Quick Summary

Design, implement, and manage enterprise PKI and Certificate Lifecycle Management services, including certificate automation, policy enforcement, infrastructure and application integration, and ensuring compliance with security and audit standards.

Job Description

PKI JD

Summary:

We are looking for a PKI/CLM Engineer with hands-on experience in ADCS, AWS ACM, and Venafi to design, implement, and manage enterprise PKI and Certificate Lifecycle Management services. The role includes certificate automation, policy enforcement, infrastructure and application integration, and ensuring compliance with security and audit standards. Required skills include CRL and OCSP maintenance, AWS Key Vault, cloud and hybrid environments, and PowerShell scripting for automation.

Roles Responsibilities: -

Manage enterprise PKI infrastructure including Root and Issuing Certificate.

Responsibilities:

· Manage certificate lifecycle activities: issuance, renewal, revocation, rekey, rollover, and retirement.

· Configure and maintain Offline Root CA, Issuing CAs, certificate templates/profiles, and policy constraints.

· Manage CRL/OCSP publishing and ensure high availability.

· Maintain PKI documentation aligned with standards like CP/CPS, operational runbooks, and SOPs.

· Support audits and compliance requirements, including CAB Forum standards.

· Manage and monitor PKI/HSM operations end-to-end, including health checks, backups, configurations, and policies.

· Implement and maintain processes for managing internal and external certificate lifecycles.

· Monitor certificates for expiration, perform timely renewals, and revoke compromised or obsolete certificates.

· Possess strong technical expertise in Microsoft Active Directory Certificate Services (ADCS), including OCSP, CRLs, certificate templates, key archival, and NDES/SCEP.

· Proficient in scripting and automation, especially PowerShell, with the ability to integrate PKI solutions across platforms such as network devices, load balancers, and Windows/Linux environments.

· Have solid understanding of cryptography and encryption standards, including TLS, X.509, RSA/ECC, CSRs, and secure key management with HSMs and TPMs.

· Hands-on experience with cloud-based certificate and key management; strong troubleshooting skills; exposure to AWS ACM/PCA, Venafi tools, and relevant security or PKI certifications is advantageous.

· Assist with enterprise-wide certificate lifecycle tasks, including requests, issuance, renewal, and revocation.

· Maintain and update inventories of machine identities, including certificates, keys, and service credentials.

· Assist in identifying orphaned, expired, or misconfigured machine identities.

· Monitor adherence to governance controls and escalate exceptions or risks.

· Maintain accurate certificate inventory records, including ownership, purpose, and expiration dates.

· Identify and report at-risk certificates, including expired, soon-to-expire, weak cryptography, or unknown owners.

· Assist with certificate issuance requests and validate required information.

· Demonstrate experience managing enterprise-scale PKI environments across on-premises and cloud platforms, including lifecycle management and automation (e.g., Venafi Trust Protection Platform).

· Possess strong technical expertise in Microsoft Active Directory Certificate Services (ADCS), including OCSP, CRLs, certificate templates, key archival, and NDES/SCEP.

· Knowledge of AD, DNS, IAM operations, and CyberArk Privilege Cloud is beneficial.

Required Skills:

· Microsoft ADCS

· SCEP

· AWS PCA

· Venafi

· HSM & Encryption

· PKI & Certificate Management.

· AD (Good to have)

· CyberArk (Good to have)

#Matchpoint

#LI-PROMOTED

#LI-Remote

Why Apply Through MisuJob?

AI-Powered Job Matching: MisuJob uses advanced artificial intelligence to analyze your skills, experience, and career goals. Our matching algorithm compares your profile against thousands of job requirements to find positions where you have the highest chance of success. This saves you hours of manual job searching and ensures you only see relevant opportunities.

One-Click Applications: Once you create your profile, applying to jobs is effortless. Your resume and cover letter are automatically tailored to highlight the most relevant experience for each position. You can apply to multiple jobs in minutes, not hours.

Career Intelligence: Beyond job matching, MisuJob provides valuable career insights. See how your skills compare to market demands, identify skill gaps to address, and understand salary benchmarks for your experience level. Make data-driven decisions about your career path.

Frequently Asked Questions

How do I apply for this position?

Click the "Register to Apply" button above to create a free MisuJob account. Once registered, you can apply with one click and track your application status in your dashboard.

Is MisuJob free for job seekers?

Yes, MisuJob is completely free for job seekers. Create your profile, get matched with jobs, and apply without any cost. We help you find your dream job without any hidden fees.

How does AI matching work?

Our AI analyzes your resume, skills, and experience to understand your professional profile. It then compares this against job requirements using natural language processing to calculate a match percentage. Higher matches mean better fit for the role.

Can I apply to jobs in other countries?

Absolutely. MisuJob features jobs from companies worldwide, including remote positions. Filter by location or look for remote opportunities to find jobs that match your preferences.

Ready to Apply?

Join thousands of job seekers using MisuJob's AI to find and apply to their dream jobs automatically.

Register to Apply