PKI Security Engineer

4 months ago


Denver, United States ITmPowered, LLC Full time
PKI Security Engineer

The PKI Security Engineer will work with the PKI Architect in the design, engineering, implementation, and administration of an enterprise PKI including Venafi TPP CLM platform, Certificate Automation, HSM Hardware Security Modules with MofN design, CA Template Design, and PKI operation aligned to CP/CPS documentation.

Primary responsibilities:

  • Engineering and Administration of Key Vaults, Cryptographic and PKI Services
  • Venafi Engineering and Administration of Certificate Lifecycle Management Services and infrastructure
  • Venafi TPP Engineering - Policy folder design
  • Engineering of Venafi Certificate discovery scanning / agent, OS / F5 base-lining and agent tuning.
  • Certificate ingestion, preliminary association, and migration into end state certificate policy folders and management levels (provisioning, enrollment, monitoring).
  • Enable adoption of Venafi automation - Provisioning, Enrollment, Monitoring. Support users of company Venafi Trust Protection Platform (Venafi TPP). PKI certificate management training for TPP users.
  • Provide consulting to business users on certificate renewals (binding), CSR's, Venafi Certificate management levels, encryption type/strength, etc.
  • Organize Venafi TPP user and administrative documentation for company implementation.
  • HSM Engineering and Administration of Encryption and Key Management Services and infrastructure.
  • HSM's - configure, deploy, and maintain Hardware Security Modules (HSM's) for highest level of private key protection and security. Utilizing MofN design, operation, logging and audit compliance. Generate, maintain, and destroy cryptographic keys of various lengths and types using HSM.
  • CA - Certificate Authorities - Maintain Windows Server 2016, 2012 ADCS, CA Templates, Issuing CA's, etc.
  • CRL Management and automation with OCSP responders.
  • Process management/implementation for PKI, Cryptography, and Hardware Security Modules (HSM).
  • Liaising with technology teams ServiceNow admins, Network, Sys Admins, Cyber, IAM, GRC, Audit.
Qualifications
  • Education: Bachelor's Degree (required). Master's preferred.
  • 5-10 years of experience in IT monitoring, implementing, and integrating IT security systems.
  • 5+ years of PKI operation; Certificate Management, Venfi CLM, HSM's, CRL, OCSP responders, etc.
  • 3+ years Venafi Engineering, Implementation, administration (19.x, 18.x) - policy Folder Design, Deployments, Upgrades, Scanning, Agent tuning,
  • SSL certificate automation Provisioning, Enrollment, Monitoring using Venafi.
  • Venafi Certified Administrator (VSA) or Venafi Security Professional (VSP)
  • HSM experience with (Gemalto, Thales, nCipher, Luna or similar HSM). Understands MofN operation.
  • Strong working experience with PKI infrastructure (Certificate Authorities (Root / Issuing), Registration Authority, Certificate trust chains and Certificate Revocation Lists).
  • Fluent with the following protocols: TCP/IP, SSL, TLS, SCP and HTTPS.
  • SSL Certificates and deployment, maintenance, renewal of certificates from web/app/proxy.
  • Background in Systems Administration of Windows ADCS, Linux, VM, Application and database servers.
  • Experience with Microsoft Active Directory, and LDAP directory integrations a plus.
  • Scripting and Automation in PowerShell, Perl, bash, ksh or other scripting language strongly preferred.
  • Strong work ethic. Time management with ability to work with diverse teams and lead meetings.
  • Demonstrate excellent attitude and communication skills with internal and external customers.
  • Strong infrastructure design and documentation skills
  • CISSP or similar certification is a Plus
Location / Logistics:
  • Local Denver resources only. On site only. No remote.
  • W2 only No sub-contracting. No sponsorship available.


  • Denver, United States Amtex Enterprises Full time

    Job Title: CyberArk IAM Engineer Rate: Upto $80-90/hr Vendor W2 Location: Local Minneapolis, MN or Denver, CO candidates preferred but open to remote Duration: 12 Months Overview: This is support based around CyberArk but seeks a candidate with a broad IAM background (Sailpoint, RSA, MS Authenticator, Azure, etc.). Looking for a certified Sentry level...


  • denver, United States Apex Systems Full time

    Cloud SIEM EngineerLocations: Chicago, IL / Denver, CO / Washington, DC - 3X A WEEK ON-SITE$80/hour on W2W2 ONLYUnable to work C2CJoin our team as a Cloud SIEM Engineer and play a crucial role in enhancing our security posture. We seek a dedicated professional passionate about security and innovation to help protect our assets from evolving cyber threats.Key...


  • Denver, United States Apex Systems Full time

    Cloud SIEM EngineerLocations: Chicago, IL / Denver, CO / Washington, DC - 3X A WEEK ON-SITE$80/hour on W2W2 ONLYUnable to work C2CJoin our team as a Cloud SIEM Engineer and play a crucial role in enhancing our security posture. We seek a dedicated professional passionate about security and innovation to help protect our assets from evolving cyber threats.Key...


  • Denver, United States Professional Employment Group of Colorado Full time

    *US Citizen Required* *No C2C**No 3rd parties*Looking for a experienced Security Analyst to help assist on a contract engagement for a client in Denver. This can be 100% remote.Performing both routine security monitoring tasks, as well as moving along with the CIS Security Framework implementation plan.Scope of Responsibilities: The contractor will take on...


  • denver, United States Professional Employment Group of Colorado Full time

    *US Citizen Required* *No C2C**No 3rd parties*Looking for a experienced Security Analyst to help assist on a contract engagement for a client in Denver. This can be 100% remote.Performing both routine security monitoring tasks, as well as moving along with the CIS Security Framework implementation plan.Scope of Responsibilities: The contractor will take on...


  • Denver, United States ManTech Full time

    ManTech is seeking a motivated, career and customer-oriented **Cyber Security Engineer, Detections** to join our team in **Denver, CO area** , to provide unparalleled support to our customer and to begin an exciting and rewarding career within ManTech. **Responsibilities include, but are not limited to:** + Support Cyber Operations Squadron (COS)...


  • Denver, United States Raymond James Financial Services Full time

    Description This position follows our hybrid-friendly schedule, so you get the best of both worlds – flexibility and collaboration. In office days will be 2-3 per week averaging 10-12 days per month in one of the following Corporate Office locations: St. Petersburg, FL; Southfield, MI; Memphis, TN; Denver, CO. Job Summary: As the Cloud Security Engineer,...


  • Denver, United States Sumo Logic Full time

    Senior Software Engineer - I - Security Detections At Sumo Logic , we are building a data platform designed to power the analytics and investigations that are common in the Security Operation Centers of large enterprises. It is designed to accept hundreds of billions of events from security-relevant data sources (detection products, network sensors,...


  • Denver, United States ITmPowered, LLC Full time

    CyberArk Administrator– ITmPowered Consulting The CyberArk Security Administrator position will support the Medical Device Cybersecurity program mission of risk reduction. Provide CyberArk Engineering expertise for the program buildout and enterprise expansion of CyberArk plugins across the medical device landscape. Drive CyberArk plugin Engineering...


  • Denver, United States ITmPowered, LLC Full time

    CyberArk Administrator– ITmPowered Consulting The CyberArk Security Administrator position will support the Medical Device Cybersecurity program mission of risk reduction. Provide CyberArk Engineering expertise for the program buildout and enterprise expansion of CyberArk plugins across the medical device landscape. Drive CyberArk plugin Engineering...


  • Denver, United States PMAT Full time

     About Us:  PMAT is a non-traditional small business founded with the passion and ideas to deliver dynamic data solutions from exceptional people that increase the capability of the mission. We focus on designing and building impactful digital solutions that utilize modern cloud, data, and software concepts. We love working on complex and dynamic...


  • denver, United States Compri Consulting Full time

    Client located in Denver (DTC), Colorado is seeking a Network & Security Analyst for a direct hire position. This person will audit for network vulnerabilities, develop solutions for cybersecurity issues, investigate incidents, and provide overall support of IT systems.Required:-3+ years network security experience.-Experience with routers, switches,...

  • Security Architect

    6 days ago


    Denver, United States Vorto Operations LLC Full time

    Job DescriptionJob DescriptionSecurity ArchitectLocation: Denver, COAbout VortoVorto is on a mission to increase sustainability and create more jobs by making supply chains more efficient across the entire value chain. Through powerful AI technology, Vorto's autonomous supply chain platform seeks to reduce carbon emissions caused by supply chain...


  • Denver, United States Compri Consulting Full time

    Client located in Denver (DTC), Colorado is seeking a Network & Security Analyst for a direct hire position. This person will audit for network vulnerabilities, develop solutions for cybersecurity issues, investigate incidents, and provide overall support of IT systems.Required:-3+ years network security experience.-Experience with routers, switches,...


  • Denver, Colorado, United States HealthEdge Full time

    Job DescriptionThe Chief Security Strategist will lead and manage a team responsible for safeguarding HealthEdge's healthcare data, infrastructure, and applications. This role is critical in protecting sensitive healthcare data and ensuring the security of our platforms.Key ResponsibilitiesDevelop and execute a comprehensive security strategy in alignment...


  • Denver, United States PMAT Full time

     The overall goal of a Software Quality Assurance (SQA) Engineer is to deliver quality software to the customer by minimizing defects.  The primary duties of a SQA Engineer is to design test plans, scenarios, scripts, or procedures. Document software defects using a bug-tracking system and report defects to software developers. Identify, analyze, and...


  • Denver, United States Bridgeview Inc Full time

    SUMMARYBridgeview is currently seeking an Cyber Security Architect for one of our clients. If you love building and supporting technology solutions that make businesses successful, then read on for more details.TITLE: Cyber Security ArchitectLOCATION: RemoteCyber Security Architect with experience defining and assessing the organization's security strategy,...


  • denver, United States BridgeView Full time

    SUMMARYBridgeview is currently seeking an Cyber Security Architect for one of our clients. If you love building and supporting technology solutions that make businesses successful, then read on for more details.TITLE: Cyber Security ArchitectLOCATION: RemoteCyber Security Architect with experience defining and assessing the organization's security strategy,...


  • denver, United States BridgeView Full time

    SUMMARYBridgeview is currently seeking an Cyber Security Architect for one of our clients. If you love building and supporting technology solutions that make businesses successful, then read on for more details.TITLE: Cyber Security ArchitectLOCATION: RemoteCyber Security Architect with experience defining and assessing the organization's security strategy,...


  • Denver, United States BridgeView Full time

    SUMMARYBridgeview is currently seeking an Cyber Security Architect for one of our clients. If you love building and supporting technology solutions that make businesses successful, then read on for more details.TITLE: Cyber Security ArchitectLOCATION: RemoteCyber Security Architect with experience defining and assessing the organization's security strategy,...