Subject Matter Expert (Support&Ops)
India
Job Description
Subject Matter Expert (Support&Ops)
Pune, Maharashtra

Job Summary

Job Description: PKI Engineer Job Summary We are seeking a skilled and detail-oriented PKI Engineer to design, implement, and maintain Public Key Infrastructure (PKI) systems across internal and external environments. The ideal candidate will have hands-on experience with Microsoft ADCS, certificate lifecycle management, and integration with external PKI providers. This role is critical to ensuring secure authentication, encryption, and digital signing across enterprise systems. Key Responsibilities • Design, deploy, and manage Internal CA hierarchy (Root CA, Subordinate CA) using Microsoft ADCS. • Integrate and manage External PKI services (e.g., DigiCert) for public-facing applications and services. • Implement and maintain certificate lifecycle management using platforms like Venafi • Ensure compliance with security policies, certificate best practices, and industry standards (e.g., NIST). • Manage CRL and OCSP configurations, including load balancing and high availability. • Monitor and troubleshoot PKI-related issues including certificate enrollment, revocation, and authentication failures. • Collaborate with security, infrastructure, and application teams to support secure communications and identity assurance. • Maintain documentation for PKI architecture, processes, and operational procedures. • Support code signing, document signing, and device authentication use cases. • Evaluate and implement post-quantum cryptography readiness strategies. Required Skills & Qualifications • Bachelor\'s degree in Computer Science, Information Security, or related field. • 5+ years of experience in PKI engineering or related security infrastructure roles. • Strong knowledge of Microsoft ADCS, including offline Root CA and online Subordinate CA setup. • Experience with HSMs (Hardware Security Modules) for key protection. • Familiarity with external PKI providers and certificate issuance processes. • Understanding of X.509 certificate standards, TLS/SSL • Experience with certificate automation tools (e.g., Venafi, ACME clients). • Strong analytical and problem-solving skills. • Excellent communication and documentation abilities. • Knowledge of Post-Quantum Cryptography concepts, cryptographic agility, hybrid cryptography, and emerging NIST PQC standards.

Key Responsibilities

Job Description: PKI Engineer Job Summary We are seeking a skilled and detail-oriented PKI Engineer to design, implement, and maintain Public Key Infrastructure (PKI) systems across internal and external environments. The ideal candidate will have hands-on experience with Microsoft ADCS, certificate lifecycle management, and integration with external PKI providers. This role is critical to ensuring secure authentication, encryption, and digital signing across enterprise systems. Key Responsibilities • Design, deploy, and manage Internal CA hierarchy (Root CA, Subordinate CA) using Microsoft ADCS. • Integrate and manage External PKI services (e.g., DigiCert) for public-facing applications and services. • Implement and maintain certificate lifecycle management using platforms like Venafi • Ensure compliance with security policies, certificate best practices, and industry standards (e.g., NIST). • Manage CRL and OCSP configurations, including load balancing and high availability. • Monitor and troubleshoot PKI-related issues including certificate enrollment, revocation, and authentication failures. • Collaborate with security, infrastructure, and application teams to support secure communications and identity assurance. • Maintain documentation for PKI architecture, processes, and operational procedures. • Support code signing, document signing, and device authentication use cases. • Evaluate and implement post-quantum cryptography readiness strategies. Required Skills & Qualifications • Bachelor\'s degree in Computer Science, Information Security, or related field. • 5+ years of experience in PKI engineering or related security infrastructure roles. • Strong knowledge of Microsoft ADCS, including offline Root CA and online Subordinate CA setup. • Experience with HSMs (Hardware Security Modules) for key protection. • Familiarity with external PKI providers and certificate issuance processes. • Understanding of X.509 certificate standards, TLS/SSL • Experience with certificate automation tools (e.g., Venafi, ACME clients). • Strong analytical and problem-solving skills. • Excellent communication and documentation abilities. • Knowledge of Post-Quantum Cryptography concepts, cryptographic agility, hybrid cryptography, and emerging NIST PQC standards.

Skill Requirements

Job Description: PKI Engineer Job Summary We are seeking a skilled and detail-oriented PKI Engineer to design, implement, and maintain Public Key Infrastructure (PKI) systems across internal and external environments. The ideal candidate will have hands-on experience with Microsoft ADCS, certificate lifecycle management, and integration with external PKI providers. This role is critical to ensuring secure authentication, encryption, and digital signing across enterprise systems. Key Responsibilities • Design, deploy, and manage Internal CA hierarchy (Root CA, Subordinate CA) using Microsoft ADCS. • Integrate and manage External PKI services (e.g., DigiCert) for public-facing applications and services. • Implement and maintain certificate lifecycle management using platforms like Venafi • Ensure compliance with security policies, certificate best practices, and industry standards (e.g., NIST). • Manage CRL and OCSP configurations, including load balancing and high availability. • Monitor and troubleshoot PKI-related issues including certificate enrollment, revocation, and authentication failures. • Collaborate with security, infrastructure, and application teams to support secure communications and identity assurance. • Maintain documentation for PKI architecture, processes, and operational procedures. • Support code signing, document signing, and device authentication use cases. • Evaluate and implement post-quantum cryptography readiness strategies. Required Skills & Qualifications • Bachelor\'s degree in Computer Science, Information Security, or related field. • 5+ years of experience in PKI engineering or related security infrastructure roles. • Strong knowledge of Microsoft ADCS, including offline Root CA and online Subordinate CA setup. • Experience with HSMs (Hardware Security Modules) for key protection. • Familiarity with external PKI providers and certificate issuance processes. • Understanding of X.509 certificate standards, TLS/SSL • Experience with certificate automation tools (e.g., Venafi, ACME clients). • Strong analytical and problem-solving skills. • Excellent communication and documentation abilities. • Knowledge of Post-Quantum Cryptography concepts, cryptographic agility, hybrid cryptography, and emerging NIST PQC standards.

Other Requirements

Job Description: PKI Engineer Job Summary We are seeking a skilled and detail-oriented PKI Engineer to design, implement, and maintain Public Key Infrastructure (PKI) systems across internal and external environments. The ideal candidate will have hands-on experience with Microsoft ADCS, certificate lifecycle management, and integration with external PKI providers. This role is critical to ensuring secure authentication, encryption, and digital signing across enterprise systems. Key Responsibilities • Design, deploy, and manage Internal CA hierarchy (Root CA, Subordinate CA) using Microsoft ADCS. • Integrate and manage External PKI services (e.g., DigiCert) for public-facing applications and services. • Implement and maintain certificate lifecycle management using platforms like Venafi • Ensure compliance with security policies, certificate best practices, and industry standards (e.g., NIST). • Manage CRL and OCSP configurations, including load balancing and high availability. • Monitor and troubleshoot PKI-related issues including certificate enrollment, revocation, and authentication failures. • Collaborate with security, infrastructure, and application teams to support secure communications and identity assurance. • Maintain documentation for PKI architecture, processes, and operational procedures. • Support code signing, document signing, and device authentication use cases. • Evaluate and implement post-quantum cryptography readiness strategies. Required Skills & Qualifications • Bachelor\'s degree in Computer Science, Information Security, or related field. • 5+ years of experience in PKI engineering or related security infrastructure roles. • Strong knowledge of Microsoft ADCS, including offline Root CA and online Subordinate CA setup. • Experience with HSMs (Hardware Security Modules) for key protection. • Familiarity with external PKI providers and certificate issuance processes. • Understanding of X.509 certificate standards, TLS/SSL • Experience with certificate automation tools (e.g., Venafi, ACME clients). • Strong analytical and problem-solving skills. • Excellent communication and documentation abilities. • Knowledge of Post-Quantum Cryptography concepts, cryptographic agility, hybrid cryptography, and emerging NIST PQC standards.

Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.