Cyber Security Architect
الوصف الوظيفي
Cyber Security Architect - PKI & Digital Signing Engineer
We are seeking an experienced PKI & Digital Signing Engineer to design, implement, administer, and support our organization's Public Key Infrastructure (PKI) and digital signing platforms. This role is critical in ensuring the security, compliance, and high availability of our enterprise's certificate services, digital signature solutions, and cryptographic infrastructure across both Windows and Linux environments.
As a Cyber Security Architect, you will be responsible for managing enterprise certificate services, digital signature solutions, and cryptographic infrastructure. You will demonstrate hands-on expertise with SigningHub, ADSS Server, and Entrust Certificate Authority, along with a strong understanding of enterprise PKI architecture, certificate lifecycle management, and secure authentication technologies.
- PKI Architecture & Administration: Design, implement, and maintain enterprise Public Key Infrastructure (PKI) solutions. Administer Certificate Authority (CA) infrastructure and certificate lifecycle processes. Configure, maintain, and troubleshoot PKI services across Windows Server and Linux platforms. Ensure high availability, disaster recovery, and resilience of PKI environments. Manage OCSP responders, CRLs, certificate templates, and enrollment services.
- Digital Signing Platforms: Deploy, configure, administer, and maintain SigningHub. Implement and manage ADSS Server for digital signatures, timestamping, signature validation, and verification services. Administer and support Entrust Certificate Authority infrastructure and related PKI services. Integrate digital signing platforms with enterprise applications, identity management systems, and document management workflows. Support digital signature standards including PAdES, XAdES, CAdES, and eIDAS where applicable.
- Security & Compliance: Monitor, secure, and harden PKI and digital signing infrastructure against vulnerabilities and cyber threats. Conduct security assessments, audits, and compliance reviews of certificate services. Maintain documentation for PKI architecture, operational procedures, and security controls. Ensure compliance with organizational security policies and regulatory requirements.
- System Administration: Install, configure, patch, and maintain Windows Server and Linux systems supporting PKI and digital signing services. Implement monitoring, backup, disaster recovery, and capacity planning for PKI infrastructure. Automate operational and administrative tasks using PowerShell, Bash, or other scripting languages.
- Integration & Support: Provide technical expertise to development, infrastructure, and security teams for PKI-related projects. Troubleshoot complex certificate, authentication, encryption, and digital signing issues. Support integrations involving TLS/SSL, APIs, identity platforms, and enterprise applications. Produce technical documentation, operational runbooks, and knowledge base articles.
Required qualifications include a Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent practical experience), along with proven experience designing, implementing, and administering enterprise PKI environments. Strong administration experience with Windows Server and Linux, hands-on experience with SigningHub, ADSS Server, and Entrust Certificate Authority, and strong knowledge of Public Key Infrastructure (PKI), digital certificates, and cryptographic concepts are essential.
Preferred qualifications include experience with Microsoft Active Directory Certificate Services (AD CS), knowledge of Microsoft Entra ID (Azure AD), Active Directory, LDAP, and SSO technologies, experience with cloud-based PKI services, familiarity with REST APIs, and experience working in regulated industries.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.