Why UKG:
At UKG, the work you do matters. The code you ship, the decisions you make, and the care you show a customer all add up to real impact. Today, tens of millions of workers start and end their days with our workforce operating platform. Helping people get paid, grow in their careers, and shape the future of their industries. That’s what we do.
We never stop learning. We never stop challenging the norm. We push for better, and we celebrate the wins along the way. Here, you’ll get flexibility that’s real, benefits you can count on, and a team that succeeds together. Because at UKG, your work matters—and so do you.
About the Role
UKG is seeking an experienced Information Security Engineer III to join the Identity & Access Management (IAM) team. This role is responsible for designing, implementing, and supporting enterprise Public Key Infrastructure (PKI) and secrets management solutions that secure applications, infrastructure, and cloud workloads.
The ideal candidate will have hands-on experience with DigiCert PKI, Certificate Lifecycle Management (CLM), Google Secret Manager, and HashiCorp Vault, along with a strong understanding of cryptography, certificate management, and cloud security. You will work closely with Infrastructure, Cloud Engineering, DevOps, Security, and Application teams to automate certificate and secrets management while ensuring secure, scalable, and compliant operations.
Key Responsibilities
- Design, implement, administer, and optimize enterprise PKI solutions using DigiCert.
- Manage the complete certificate lifecycle, including certificate issuance, renewal, revocation, discovery, and automated deployment through Certificate Lifecycle Management (CLM).
- Administer and support Google Secret Manager and HashiCorp Vault for secure storage, rotation, and access to secrets, certificates, and encryption keys.
- Collaborate with application, infrastructure, and DevOps teams to integrate PKI, certificate automation, and secrets management into enterprise platforms and CI/CD pipelines.
- Implement automation for certificate provisioning, renewal, and secret rotation using APIs, scripting, and infrastructure-as-code practices.
- Monitor PKI infrastructure and certificate health to ensure service availability and compliance.
- Troubleshoot certificate, TLS/SSL, secrets management, and authentication issues across cloud and on-premises environments.
- Develop operational documentation, runbooks, and standard operating procedures.
- Support security audits, regulatory compliance, and vulnerability remediation related to certificates, cryptographic assets, and secrets management.
- Stay current with emerging technologies and security best practices related to PKI, cryptography, and cloud-native security.
Required Qualifications
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.
- 5–9 years of experience in Information Security, IAM, Infrastructure Security, or Cloud Security Engineering.
- Hands-on experience administering DigiCert PKI and Certificate Lifecycle Management (CLM) solutions.
- Experience managing enterprise TLS/SSL certificates, code-signing certificates, client certificates, and certificate automation.
- Experience with Google Secret Manager and HashiCorp Vault for enterprise secrets management.
- Strong understanding of PKI concepts, X.509 certificates, Certificate Authorities (CA), cryptographic key management, TLS/SSL, CSR generation, OCSP, and CRL.
- Experience integrating PKI and secrets management solutions with enterprise applications and cloud platforms.
- Experience with automation using REST APIs, PowerShell, Python, or Shell scripting.
- Experience with Google Cloud Platform (GCP); exposure to AWS or Azure is a plus.
- Strong analytical, troubleshooting, and problem-solving skills.
Preferred Qualifications
- Experience integrating PKI and secrets management into Kubernetes, containers, and CI/CD platforms.
- Familiarity with Infrastructure as Code tools such as Terraform.
- Knowledge of identity and access management concepts, including authentication, authorization, and Zero Trust architecture.
- Experience supporting compliance frameworks such as SOC 2, ISO 27001, PCI DSS, or SOX.
- Relevant certifications such as DigiCert, HashiCorp Vault Associate, Google Cloud Security, Security+, or CISSP are desirable.
Technical Skills
- DigiCert PKI Platform
- Certificate Lifecycle Management (CLM)
- Google Secret Manager
- HashiCorp Vault
- Public Key Infrastructure (PKI)
- TLS/SSL & X.509 Certificates
- Certificate Authorities (CA)
- Key & Certificate Management
- REST APIs
- PowerShell, Python, or Shell Scripting
- Google Cloud Platform (GCP)
- Terraform (preferred)
- Kubernetes (preferred)
- DevSecOps & CI/CD Integration
Company Overview:
UKG is the Workforce Operating Platform that puts workforce understanding to work. With the world's largest collection of workforce insights, and people-first AI, our ability to reveal unseen ways to build trust, amplify productivity, and empower talent, is unmatched. It's this expertise that equips our customers with the intelligence to solve any challenge in any industry — because great organizations know their workforce is their competitive edge. Learn more at ukg.com.
UKG is proud to be an equal opportunity employer and is committed to promoting diversity and inclusion in the workplace, including the recruitment process.
Disability Accommodation in the Application and Interview Process
For individuals with disabilities that need additional assistance at any point in the application and interview process, please email [email protected]