Overview
About Business Unit:
At the core of all that Epsilon does is a team that sets the foundation of our IT infrastructure. The team drives innovation and efficiency through pioneering technology across Epsilon's platforms and business verticals. From being the first point of contact for infrastructure needs to final deployment, the team provides end-to-end solutions for our client-facing platforms. ETS supports all aspects of revenue-generating platforms for Epsilon and sets the architectural direction for our enterprise deployments. By adopting the newest technologies, such as Cloud, Automation, and Artificial Intelligence, the team is at the front of redefining our digital business and capturing new opportunities.
How You'll Make an Impact:
As a
Lead TLS & PKI Engineer on the
Solutions Enablement team, you will establish deep technical leadership for Epsilon's
public and private PKI, TLS, and certificate lifecycle capabilities-bringing protocol-level expertise the team needs to move from reactive certificate operations toward
automated, observable, and standards driven trust services.
You understand the shapes and forms TLS takes in enterprise environments-server authentication, client authentication (mTLS), private PKI, public CA-issued certificates, and cloud-managed trust-and when each pattern applies. You partner with Security on trust policy, with Network on edge and load-balancer consumption, and with Cloud, Platform, and Application teams on how certificates are issued, renewed, inventoried, and deployed across
AWS, Azure, and GCP.
You will drive incremental maturity in
certificate inventory, renewal automation, trust-chain management, TLS monitoring, and industry-aligned practices (including shorter public certificate lifetimes and reduced reliance on manual dispensing). You mentor engineers on TLS fundamentals, unblock complex handshake and chain-validation issues, and translate technical depth into momentum-documented patterns, automation, and operational field that reduce surprise outages and audit risk.
This role is ideal for a hands-on technical lead who combines PKI/TLS expertise with automation mentality and the ability to guide others while staying in the details when integrations fail in production.
Click here to view how Epsilon transforms marketing with 1 View, 1 Vision and 1 Voice.
Responsibilities
TLS, PKI & Certificate Architecture:
- Provide
technical leadership for enterprise TLS and PKI operations-certificate types, trust models, chain construction, and deployment patterns across on-premises, hybrid, and multi-cloud environments.
- Advise on
when and why to use public vs. private CA-issued certificates, internal PKI, cloud-managed certificates, and partner-issued credentials-including server TLS,
mutual TLS (mTLS), and integration-specific trust stores.
- Maintain working knowledge of
industry trends affecting certificate strategy-e.g., shortening public certificate lifetimes, CA/Browser Forum baseline requirements, and automation-first renewal models.
- Partner with
Security on PKI policy, trust scope, and governance; Security retains policy authority-you
operate and implement within agreed standards.
Certificate Lifecycle, Inventory & Automation:
- Own and improve
end-to-end certificate lifecycle workflows-issuance, renewal, revocation, inventory, and dispensing-reducing manual toil and surprise expirations.
- Drive
inventory accuracy and automation using platforms such as
Venafi (or equivalent CLM)-metadata, drift detection, scheduled reconciliation, and integration with operational systems of record.
- Design and implement
renewal automation-scheduled jobs, APIs, ACME or vendor-native automation where appropriate, and alerting ahead of expiry or trust-chain change.
- Establish process for certificate changes-
change records, partner notification for mTLS trust updates, and runbooks that prevent silent trust-store drift.
Cloud-Native Certificate & Key Services:
- Implement and govern certificate consumption across
AWS (e.g.,
ACM, IAM-bound certs, load balancer-managed TLS),
Azure (
Key Vault, managed certificates), and
GCP (
Certificate Manager,
Certificate Authority Service, Secret Manager).
- Guide teams on
correct use of cloud-native vs. enterprise PKI patterns-rotation, blast radius, and integration with load balancers, API gateways, and workloads.
- Partner with Cloud Engineering on
workload and platform certificate patterns across multi-account, multi-region deployments.
Deployment, IaC & Load Balancer Integration:
- Deliver certificates through
infrastructure-as-code and operational workflows to
software and hardware load balancers and edge platforms-e.g.,
F5 BIG-IP,
Citrix,
AWS ALB/NLB/CloudFront, API gateways, and ingress controllers. Deep expertise in one vendor is sufficient; breadth across platforms is valued.
- Define reusable patterns for
installing, binding, and rotating certificates on listeners, VIPs, and client-auth profiles-including
partner CA bundles for inbound mTLS-without one-off manual installs at scale.
- Partner with Network and platform teams on edge configuration; you are not required to be a full-stack F5 administrator, but you must understand how certificates are consumed and rotated on load-balancing platforms.
- Fix
TLS handshake failures, chain validation errors, cipher/TLS version mismatches, and certificate binding issues across the full path (client edge backend).
Mutual TLS & Trust Chain Management:
- Lead
mTLS and trust-chain coordination with Network and integration teams-distinguishing server TLS from
partner-issued client authentication and the trust bundles required on edge platforms.
- Maintain clarity on
trust anchor ownership-what lives on load balancers vs. application vs. OS trust stores-and drive inventory and monitoring so chain changes do not cause silent outages.
- Support
partner notification when external certificate chains change-reducing surprise failures when trust stores are not updated in sync with partner renewals.
TLS Monitoring & Observability:
- Define
what to monitor across the certificate and TLS lifecycle-and
why each signal matters (e.g., expiry windows, issuance failures, renewal job health, inventory drift, handshake errors, client-cert validation failures, chain mismatch, and trust-store divergence from inventory).
- Design monitoring and alerting that goes
beyond expiry dates-catching provisioning failures, failed renewals, chain changes, and mTLS validation errors before or as they impact production traffic.
- Integrate TLS observability with inventory platforms (e.g., Venafi), edge/load-balancer telemetry, cloud certificate services, and operational monitoring tools where appropriate.
- Contribute to runbooks and dashboards that help teams distinguish
lifecycle risk from
runtime TLS failure and respond with the right remediation.
Standards, Documentation & Team Development:
- Create and maintain
documented standards, diagrams, and playbooks for certificate types, renewal paths, mTLS onboarding, and common integration patterns.
- Mentor engineers on TLS/PKI fundamentals-X.509, SANs, intermediates, OCSP/CRL concepts, and secure key handling.
- Drive workstreams that incrementally mature PKI operations-automation, inventory pipelines, monitoring, and cross-team runbooks-without waiting for a single big-bang transformation.
- Evaluate emerging capabilities (e.g.,
ACME, short-lived workload certificates, SPIFFE/SPIRE-adjacent patterns) and recommend practical adoption aligned to Security policy and business outcomes.
- Participate in
on-call rotation for critical certificate or TLS-related production incidents as required.
- Additional responsibilities as assigned.
Qualifications
Who You Are:
A hands-on TLS and PKI technical lead who can explain
why a handshake failed and
what to change in the trust store-not just renew a cert in a portal. You understand certificate lifecycle as an operational field: inventory, automation, renewal, monitoring, and the human/process gaps that cause outages. You partner well across Security, Network, Cloud, and application teams, and you bias toward repeatable patterns over tribal knowledge. You are comfortable mentoring others while owning the hardest problems in the PKI domain.
What you'll bring with you:
- 7+ years of experience in infrastructure, security engineering, network engineering, or platform operations roles, with
3+ years focused on
PKI, TLS, or certificate lifecycle management in production enterprise environments.
- Deep technical depth in TLS 1.2/1.3, X.509 certificates, public and private PKI, certificate chains, SANs, key types, and common deployment patterns (server TLS, mTLS, internal CA, public CA).
- Hands-on experience with
certificate lifecycle management platforms (e.g.,
Venafi, DigiCert, Sectigo CLM, or equivalent)-inventory, policy, renewal workflows, and API driven automation.
- Experience with
cloud-native certificate and key services-
AWS Certificate Manager (ACM),
Azure Key Vault, and
GCP Certificate Manager / Certificate Authority Service (or comparable patterns).
- Experience
installing, binding, and rotating certificates on
software and hardware load balancers and edge platforms-e.g., F5, Citrix, AWS load balancers/CDN, API gateways, or equivalent; not required to be a dedicated F5 expert.
- Understanding of
private PKI operations-internal CA hierarchy, issuance workflows, trust distribution, and coordination with Security on policy boundaries.
- Familiarity with
infrastructure-as-code (Terraform or equivalent) for certificate provisioning, binding, and operational validation.
- Experience defining
TLS and certificate monitoring-knowing which lifecycle and runtime signals matter, why they matter, and how to alert on them beyond simple expiry checks.
- Awareness of
industry certificate lifetime trends and operational implications-planning for shorter-lived public certificates and automation-first renewal.
- Demonstrated ability to
lead technical workstreams,
mentor engineers, and
partner across teams (Security, Network, Cloud, Platform) without owning every implementation yourself.
- Experience with
incident troubleshooting for TLS-related production issues in 24x7 environments.
- Demonstrated success in security-conscious or regulated environments-audit-ready documentation, least-privilege key handling, and structured process updates.
- Self-directed with strong prioritization skills; comfortable operating in complex, multi-stakeholder enterprise contexts.
- Willingness to participate in on-call rotation.
Why you might stand out from other talent:
- Experience building
automated inventory pipelines-scheduled exports from load balancers or cloud APIs reconciled against Venafi or a system of record.
- Hands-on
mTLS program experience at scale-partner onboarding, trust bundle lifecycle, and outage prevention when partner chains change.
- ACME or fully automated renewal implementations across hybrid and multi-cloud estates.
- Strong
TLS observability design-handshake failure detection, client-cert validation monitoring, and lifecycle dashboards tied to actionable runbooks.
- Experience with
SPIFFE/SPIRE, workload identity certificates, or short-lived credential patterns adjacent to traditional PKI.
- Multi-cloud
PKI harmonization-consistent patterns across AWS, Azure, and GCP without duplicating manual processes per platform.
- Relevant certifications (e.g., CISSP, CCSP, cloud security specialty, vendor PKI/TLS training) or equivalent demonstrated expertise.
- Scripting and automation skills (
Python preferred) for certificate operations, validation, inventory sync, and integration tooling.
Additional Information
Epsilon is a global data, technology and services company that powers the marketing and advertising ecosystem. For decades, we've provided marketers from the world's leading brands the data, technology and services they need to engage consumers with 1 View, 1 Vision and 1 Voice. 1 View of their universe of potential buyers. 1 Vision for engaging each individual. And 1 Voice to harmonize engagement across paid, owned and earned channels.
Epsilon's comprehensive portfolio of capabilities across our suite of digital media, messaging and loyalty solutions bridge the divide between marketing and advertising technology. We process 400+ billion consumer actions each day using advanced AI and hold many patents of proprietary technology, including real-time modeling languages and consumer privacy advancements. Thanks to the work of every employee, Epsilon has been consistently recognized as industry-leading by Forrester, Adweek and the MRC. Epsilon is a global company with more than 9,000 employees around the world.
Our pillars aren't just words. They're how we show up every day.
-
People centricity: We focus on employee well-being in an environment where colleagues truly care about each other.
-
Collaboration: We work together, support one another, and collectively achieve goals.
-
Growth: There are endless opportunities for growth through learning, development and career advancement.
-
Innovation: We drive progress through cutting-edge solutions and forward-thinking approaches.
-
Flexibility: We've created a balance between work and personal life, and we encourage adaptability to solve problems creatively.
Our values guide us to create value for our clients, our people and consumers.
-
Act with integrity
-
Work together to win together
-
Innovate with purpose
-
Respect all voices
-
Empower with accountability
These pillars and values are our foundation-shaping our culture, guiding our decisions, and uniting us in common purpose.
Epsilon is an Equal Opportunity Employer.
Epsilon is committed to promoting diversity, inclusion, and equal employment opportunities by using reasonable efforts to attract, recruit, engage and retain qualified individuals of all ethnicities and backgrounds, including, but not limited to, women, people of color, LGBTQ individuals, people with disabilities and any other underrepresented groups, traits or characteristics.