23 Aug
|
Ju0026M Group
|
Brampton
23 Aug
Ju0026M Group
Brampton
Certificate Lifecycle Operations
- Manage certificate discovery, enrollment, issuance, renewal, revocation, replacement, and retirement activities.
- Maintain accurate certificate inventory, ownership, and lifecycle records.
- Support large-scale certificate renewal events and emergency certificate replacement procedures.
- Ensure compliance with enterprise PKI standards, security policies, and audit requirements.
CLM Platform Administration
- Administer and support SaaS-based Certificate Lifecycle Management platforms and Satellite / Connector components.
- Configure certificate templates, enrollment policies, and integration connectors.
- Monitor connector health, synchronization status, and platform availability.
- Troubleshoot enrollment failures, renewal failures, connector communication issues, and API-related errors.
PKI & Security Support
- Support enterprise Public Key Infrastructure (PKI) operations.
- Integrate with Microsoft Active Directory Certificate Services (ADCS) and external Certificate Authorities.
- Validate certificate chains, SAN entries, EKU usage, CRL/OCSP responses, and trust relationships.
- Support private key protection, certificate governance, and audit logging requirements.
Automation & Integration
- Utilize REST APIs for certificate enrollment, renewal, revocation, import/export, and reporting operations.
- Develop or maintain automation scripts using PowerShell, Python, Bash, or equivalent scripting languages.
- Support ACMEv2-based certificate automation for enterprise workloads.
- Assist with CI/CD and infrastructure automation integrations where applicable.
Cloud & Kubernetes Support
- Support certificate operations for Kubernetes cert-manager environments.
- Manage TLS certificates for Ingress Controllers, APIs, microservices, and containerized applications.
- Support cloud-based certificate and key management services, including:
- Azure Key Vault
- AWS Certificate Manager (ACM)
- AWS KMS / Secrets Manager
- Other enterprise cloud key management solutions
Monitoring & Reporting
- Implement proactive monitoring for:
- Certificate expiry
- Connector health
- API failures
- Enrollment and renewal exceptions
- Generate operational dashboards, SLA reports, KPI metrics, and monthly service reports.
- Participate in governance reviews and continuous service improvement initiatives.
Essential Skills
- Experience with Enterprise Certificate Lifecycle Management (CLM) platforms.
- Strong understanding of PKI concepts and certificate lifecycle processes.
- Hands-on experience with SSL/TLS certificate management.
- Experience with Microsoft ADCS.
- Knowledge of ACMEv2 enrollment and renewal workflows.
- Experience managing Windows Certificate Store / CAPI.
- Experience with REST API integrations.
- Proficiency in PowerShell scripting.
Preferred
- Experience with CyberArk Certificate Manager SaaS, Venafi, Keyfactor, DigiCert Trust Lifecycle Manager, AppViewX, or similar enterprise CLM platforms.
- Kubernetes cert-manager.
- Azure Key Vault.
- AWS ACM / KMS.
- OpenSSL, keytool, and certificate troubleshooting utilities.
- Python or Bash scripting.
- Enterprise monitoring tools such as Splunk, Dynatrace, Prometheus, Grafana, or equivalent.
Operational Support Expectations
- Provide 8x5 operational support with participation in 24x7 on-call / follow-the-sun support rotation when required.
- Support P1P4 incident management and major incident bridge activities.
- Perform Root Cause Analysis (RCA) and contribute to problem management remediation plans.
- Maintain operational runbooks, SOPs, and knowledge base documentation.
Preferred Certifications
- CyberArk Sentry Certificate Manager (preferred).
- Venafi Certified Skilled.
- Microsoft Certified: Windows Server / Identity.
- Certified Kubernetes Administrator (CKA) (nice to have).
- ITIL v4 Foundation.
📌 Enterprise (CLM) Operations Support Engineer (Brampton)
🏢 Ju0026M Group
📍 Brampton