| Chennai, Tamil NaduGautam Buddha Nagar, Uttar Pradesh
Job Summary
PKI (Domain certificate management) L2 Engineer with Venafi Tool expertise
The PKI L2 Engineer will be responsible for managing, maintaining, and supporting Public Key Infrastructure (PKI) systems, ensuring secure cryptographic operations, certificate lifecycle management, and seamless integration with enterprise platforms. This role requires strong technical expertise, communication skills, and the ability to collaborate with global customers and cross-functional teams.
Key Responsibilities
Strong understanding of cryptography and Public Key Infrastructure (PKI).\\\\r\\\\n• Hands-on experience with Microsoft PKI and AD CS technologies.\\\\r\\\\n• Knowledge of SSL/TLS protocols and alert codes.\\\\r\\\\n• Experience troubleshooting HTTPS and certificate-related issues.\\\\r\\\\n• Ability to write technical documentation (SOPs, KB articles).\\\\r\\\\n• Familiarity with ITIL and Change Management processes.\\\\r\\\\n• Strong analytical and problem-solving skills.\\\\r\\\\n• Excellent written and verbal communication skills.\\\\r\\\\n
Skill Requirements
Strong understanding of cryptography and Public Key Infrastructure (PKI). • Hands-on experience with Microsoft PKI and AD CS technologies. • Knowledge of SSL/TLS protocols and alert codes. • Experience troubleshooting HTTPS and certificate-related issues. • Ability to write technical documentation (SOPs, KB articles). • Familiarity with ITIL and Change Management processes. • Strong analytical and problem-solving skills. • Excellent written and verbal communication skills.
Other Requirements
Provide L2-level support for PKI operations and cryptographic services. • Collaborate with global customers and cross-functional teams with strong communication and soft skills. • Create SOPs, knowledge base articles, and deliver triage sessions. • Follow ITIL processes and manage changes effectively. • Design, implement, and manage 1, 2, or 3-tier PKI architectures. • Install, configure, and troubleshoot Active Directory Certificate Services (AD CS) including components like NDES and OCSP. • Manage certificate templates and various certificate types: SSL/TLS, Web Server, LDAPS, user/computer, EFS, Wildcard, etc. • Troubleshoot certificate enrollment issues and SSL/TLS handshake failures using Schannel errors and CAPI2 logs. • Support Web Server certificate issues on IIS and LDAPS in Active Directory environments. • Perform CA backup, restore, and support AD CS migration including cryptographic provider and hash algorithm upgrades. • Conduct CA auditing, maintenance, CRL/CA renewal, and health checks. • Work with CRL, AIA, CDP, and PKIView for validation. • Support certificate revocation and trust validation troubleshooting. • Work with Hardware Security Modules (HSMs) and relevant commands. • Manage integrations with public CAs such as DigiCert, GoDaddy, etc. • Perform certificate lifecycle management manually and via automation tools. • Work with CLM platforms such as Venafi.
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-