Cyber Security Engineer 3

Comcast Comcast · Media · Chennai, India

Seeking a PKI Engineer with 5+ years of experience in designing, implementing, and maintaining enterprise-scale public key infrastructure (PKI) solutions. Responsibilities include managing PKI services, administering HSMs, designing certificate chains, building integrations with platforms like Venafi, and automating certificate lifecycle management.

What you'd actually do

  1. Manage, maintain, and optimize enterprise PKI services, including issuing, renewing, and revoking digital certificates.
  2. Administer and integrate Hardware Security Modules (HSMs) to secure private key storage and cryptographic operations.
  3. Design, implement, and troubleshoot certificate chains, public/private key pairs, and intermediate/root CAs to ensure trust and compliance.
  4. Build and maintain integrations with platforms such as Venafi, Microsoft Intune, and other enterprise systems to enable automated certificate lifecycle management.
  5. Support automation of certificate provisioning, renewal, and deployment processes across hybrid environments (on-prem and cloud).

Skills

Required

  • PKI
  • Venafi
  • HSM
  • OSCP
  • Powershell
  • PKI Certificate
  • enterprise PKI environments
  • HSMs, certificate authorities, certificate chains, CRLs, and OCSP
  • Venafi Trust Protection Platform, Microsoft Intune, or equivalent certificate automation and management platforms
  • certificate lifecycle automation, APIs, and integrations
  • Windows and Linux certificate stores, Active Directory Certificate Services (ADCS), and modern cloud PKI approaches
  • troubleshooting and problem-solving skills in PKI-related areas
  • communication skills
  • work cross-functionally with technical and non-technical teams

Nice to have

  • scripting or automation (e.g., PowerShell, Python, or Bash) for PKI workflows
  • Zero Trust architectures and enterprise identity solutions
  • security compliance standards (e.g., NIST, PCI DSS, ISO 27001)

What the JD emphasized

  • PKI
  • Venafi
  • HSM
  • OSCP
  • HSM
  • Powershell
  • PKI Certificate
  • Hardware Security Modules (HSMs)
  • certificate chains, public/private key pairs, and intermediate/root CAs
  • Venafi Trust Protection Platform
  • Zero Trust