Hiring.Camp

PKI Certificate Management - Security Identity Engineer

LSEG

·

Today

Location
IND-BLR-Divyasree Technopolis, India
Type
Full-time
Department
Engineering
Experience
7+ years
Education
Bachelor
Source
Workday

Description

Role Summary

The Security PKI Engineer will be responsible for engineering, operating, and continuously improving LSEG’s Public Key Infrastructure (PKI) and Certificate Lifecycle Management (CLM) capabilities. This role ensures trusted identity, authentication, and encryption services are reliable, scalable, and secure across enterprise and cloud environments. You will contribute to designs and production improvements that increase availability, performance, and operational efficiency, partnering closely with architects, security teams, infrastructure, and application owners to deliver measurable outcomes on agreed priorities and timelines.

Key Responsibilities

· Engineer, administer, and maintain PKI components including Root, Intermediate, and Issuing Certificate Authorities.

· Operating and supporting certificate validation and distribution services including CRLs, OCSP, AIA, and CDP.

· Executing end-to-end certificate lifecycle processes: request validation, issuance, renewal, revocation, and retirement.

· Ensuring essential PKI and CLM processes meet high-quality standards through strong operational controls, documentation, and repeatable runbooks.

· Maintaining certificate inventory hygiene and reduce operational risk by proactively addressing expirations and crypto compliance gaps.

· Driving project priorities, deadlines, and outcomes for PKI and CLM engineering deliverables.

· Applying deep knowledge of site reliability, software engineering, tooling, frameworks, infrastructure, and systems to deliver each task effectively.

· Contributing to designs of software components, systems, and features that improve availability, scalability, latency, and efficiency of LSEG services.

· Participating in sustainable incident response and production improvements, including root cause analysis and preventive remediation.

· Building automation to prevent problem recurrence and implementing automated responses for non-exceptional service conditions.

· Writing and reviewing optimized and accurate automation code and scripts to improve certificate operations and reliability.

· Providing feedback and suggested improvements through peer code reviews, focusing on quality, performance, and maintainability.

· Improving monitoring and alerting for certificate expiry, CA health, OCSP and CRL availability, and CLM workflow performance.

· Supporting integration of CLM workflows with enterprise tooling and APIs to reduce manual effort and improve governance.

· Partnering with architects to decompose solutions for technology systems and products, aligning PKI and CLM designs to platform standards.

· Acting as a point of contact within the PKI domain by demonstrating strong depth of knowledge and building awareness of adjacent domains to manage dependencies.

· Proactively building and applying relevant domain knowledge related to workflows, data pipelines, business policies, configurations, and constraints.

· Providing mentorship and advice to team members on improving availability and performance of critical services.

Qualifications

·

  • Bachelor's degree in Computer Science, Cyber Security, Engineering, or a related technical discipline.

  • 7+ years of experience in PKI, Cyber Security, Identity & Access Management, or security engineering.

  • Expert understanding of PKI, X.509 certificates, certificate chains, trust models, and certificate validation.

  • Strong experience with Certificate Authorities and supporting services, including Root, Intermediate, and Issuing CAs, CRLs, OCSP, AIA, and CDP.

  • Hands-on experience with enterprise PKI and CLM platforms such as Microsoft AD CS, CyberArk Certificate Manager (Venafi), DigiCert, Keyfactor, Entrust, Sectigo, or EJBCA.

  • Strong understanding of key management, HSMs, KSPs, CSPs, certificate lifecycle management, and cryptographic controls.

  • Experience designing and implementing PKI automation using APIs, PowerShell, Python, or Bash.

  • Strong knowledge of Active Directory, Entra ID, Kerberos, NTLM, SAML, OAuth, OIDC, and identity federation.

  • Experience operating PKI services across Azure, AWS, and/or GCP, including cloud-native certificate management patterns.

  • Strong understanding of networking and security protocols, including TCP/IP, DNS, TLS, mTLS, firewalls, and load balancing.

  • Experience operating security-critical services with an SRE mindset, including monitoring, alerting, incident response, and service resilience.

  • Experience supporting crypto agility and Post-Quantum Cryptography (PQC) readiness initiatives, including certificate discovery, cryptographic inventory, automation, migration planning, and adoption of emerging NIST PQC standards.

  • Experience with code signing, software supply chain security, Kubernetes certificate automation, and PKI architecture design.

Certifications (Nice to have)

· Security Certifications (SSCP, CompTIA Security+)

· Azure/AWS/GCP cloud security certifications

· PKI/CLM platform training and/or public CA program familiarity

Career Stage:

Manager

London Stock Exchange Group (LSEG) Information:

Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.

LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.

Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership, Excellence and Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.

Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.

We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyone’s race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.

You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.

LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.

Please take a moment to read this privacy notice carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what it’s used for, and how it’s obtained, your rights and how to contact us as a data subject.

If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice.

Skills

PythonAWSAzureGCPKubernetesOAuthTCP/IPSREComplianceCompTIA

Similar Jobs

3

PKI / Certificate Management Engineer (R-00198)

True Zero Technologies · 100% Remote · Remote

2 weeks ago

PKI & Certificate Management Engineer (m/f/d)

Freseniusglobal · Bad Homburg (EK1), Germany

1 month ago

PKI & Certificate Management Engineer (m/f/d)

Freseniusglobal · Bad Homburg (EK1), Germany

1 month ago