Full-Time

PKI & Certificate Management Architect

Updated on 8/21/2026

Experient Group

Experient Group

No salary listed

Atlanta, GA, USA

Hybrid

Hybrid work arrangement indicated; required in-office frequency is not specified.

Category
IT & Security (1)
Required Skills
Kubernetes
Microsoft Azure
Python
ServiceNow
Microsoft Windows
Microservices
AWS
Go
Linux/Unix
Google Cloud Platform
Requirements
  • Strong working knowledge of public key infrastructure and the X.509 certificate standard, including certificate lifecycle, certificate authorities, chains of trust, key management, and revocation.
  • Experience automating certificate inventorying and provisioning across heterogeneous systems, including Linux, Windows, Amazon Web Services, Google Cloud Platform, Entra, Internet of Things devices, Kubernetes, and Cloudflare.
  • Proficiency with at least one scripting or programming language for automation and integration work, such as Python or Go.
  • Experience leading technical delivery by setting architecture, reviewing work, and bringing a team along.
Responsibilities
  • Design the target-state architecture for centralized certificate lifecycle management, including issuance, renewal, revocation, discovery, and inventory.
  • Lead the technical migration from multiple Certificate Authorities onto Zero Touch PKI, including certificate migration or creation and transitioning critical infrastructure services to the new software-as-a-service-backed certificate authority.
  • Build enterprise-grade automations for certificate provisioning and renewal to remove manual touchpoints.
  • Establish certificate discovery and inventory with CyberArk Certificate Manager across multiple cloud providers, servers, load balancers, application services, and network devices.
  • Work with stakeholders to define standards for certificate policy, key types, validity periods, and rotation.
  • Work with platform, security, and application teams to onboard their systems onto the central platform.
  • Set up monitoring and alerting for expirations, policy violations, and integration failures.
Desired Qualifications
  • Experience with ACME, SCEP, and EST enrollment protocols and CRL and OCSP revocation processes.
  • Knowledge of mutual TLS and service-to-service certificate use in microservice environments.
  • Experience with cloud-native certificate services such as AWS Certificate Manager, Azure Key Vault, Azure Cloud HSM, or Google Cloud KMS.
  • Hands-on integration experience with certificate management or public key infrastructure tooling; direct experience with Zero Touch PKI and CyberArk Certificate Manager, formerly Venafi, is a strong plus.
  • Experience designing API or ServiceNow integrations for developer self-service.
  • Prior hands-on experience migrating off Microsoft Active Directory Certificate Services at enterprise scale.
  • Experience integrating certificate and expiration events with security information and event management tooling for security visibility.
  • Prior experience in large-scale, multi-team enterprise environments involving thousands of certificates and dozens of stakeholder teams.
  • Background in a regulated or audited environment.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A