Job Summary
The Onsite Germany Architect for PKI & Crypto Inventory L2 is responsible for designing, implementing, and maintaining Public Key Infrastructure (PKI) and cryptographic inventory solutions at Level 2 (L2) support within the German region. This role ensures the security, integrity, and availability of cryptographic assets and works closely with internal stakeholders, technical teams, and external partners to deliver high-quality solutions tailored to enterprise needs.
Key Responsibilities
PKI Architecture & Design: Develop and maintain PKI solutions, including certificate authorities, registration authorities, and certificate lifecycle management. Define technical standards and best practices for PKI deployments. Crypto Inventory Management: Architect and oversee the inventory of cryptographic assets (keys, certificates, tokens, etc.), ensuring accurate tracking, compliance, and secure storage. L2 Support & Troubleshooting: Provide advanced (Level 2) technical support for PKI and crypto inventory issues, including incident response, root cause analysis, and remediation. Security & Compliance: Ensure PKI and crypto inventory solutions meet regulatory and organizational security requirements. Conduct risk assessments and implement controls to safeguard cryptographic materials. Stakeholder Collaboration: Work with IT, security, compliance, and business units to gather requirements, communicate updates, and deliver solutions aligned with organizational goals. Documentation & Reporting: Produce clear technical documentation, architecture diagrams, and inventory reports. Maintain accurate records of cryptographic assets and operations. Continuous Improvement: Evaluate emerging technologies, cryptographic algorithms, and industry trends to enhance PKI and crypto inventory systems.
Skill Requirements
Bachelor’s or Master’s degree in Computer Science, Information Security, or related field. 5+ years of experience in PKI design, implementation, and support, preferably in enterprise environments. Strong knowledge of cryptographic protocols, certificate lifecycle management, and crypto asset inventory solutions. Expertise in Windows, Linux, and network security architectures. Familiarity with compliance frameworks (e.g., GDPR, eIDAS, ISO 27001) relevant to Germany and the EU. Experience with automation tools, scripting languages (PowerShell, Python), and integration with IAM solutions. Excellent communication skills, fluent in English; German language proficiency is highly desirable. Ability to work onsite in Germany and collaborate in cross-functional, multicultural teams.
Other Requirements
Industry certifications such as CISSP, CISM, CEH, or equivalent. Experience with Hardware Security Modules (HSMs), smart cards, and secure key management solutions. Understanding of cloud PKI architectures (e.g., Azure Key Vault, AWS KMS). Project management experience in PKI and cryptography-related initiatives.