Iam Secops Engineer - Pki & Encryption

Eli Lilly Eli Lilly · Pharma · Cork, Ireland

This role is for an IAM SecOps Engineer focused on Public Key Infrastructure (PKI) and encryption services within a large enterprise. The engineer will be responsible for designing, implementing, and securing these technologies, managing certificate lifecycles, key management, and cryptographic standards. The role involves partnering with various stakeholders to ensure secure and compliant operations.

What you'd actually do

  1. This IAM SecOps Engineer - PKI & Encryption will serve as a member of the Lilly Cybersecurity Identity and Access Management team, responsible for delivering and securing PKI and encryption technologies that support Lilly's mission.
  2. You will develop technical specifications, design patterns, standards-as-code, and security guidance for PKI and encryption capabilities and services.
  3. As a key contributor, you will identify and optimize critical processes around certificate lifecycle management, key management, cryptographic standards, and continuous improvement of PKI and encryption technologies.
  4. As an IAM SecOps Engineer - PKI & Encryption, you will leverage your technical expertise to evaluate, architect, and implement PKI solutions that meet business and security requirements.
  5. Design and maintain technical integrations of PKI and encryption services, including certificate authority (CA) hierarchy design, certificate issuance and renewal workflows, key management, and hardware security module (HSM) operations to meet business requirements.

Skills

Required

  • Designing, implementing, and supporting enterprise PKI solutions (Microsoft AD CS, Sectigo, DigiCert, Entrust, or comparable CA platforms)
  • Managing certificate lifecycle processes (issuance, renewal, revocation, HSM operations)
  • PKI and encryption services integration
  • Certificate authority (CA) hierarchy design
  • Key management
  • Hardware security module (HSM) operations
  • Monitoring, troubleshooting, and continuous optimization of certificate lifecycle management
  • Cryptographic policy enforcement
  • Understanding of evolving threat landscape and PKI/encryption risks
  • Collaboration with cross-functional and remote team members
  • Communication and presentation skills
  • Understanding of cryptographic standards and protocols (TLS/SSL, RSA, ECC, AES)
  • Experience with certificate lifecycle management platforms (Venafi, DigiCert CertCentral, AppView, or comparable)
  • Designing and implementing enterprise-scale PKI architecture for cloud, hybrid, and on-premises environments
  • Integration with Azure and AWS certificate services
  • Translating business and compliance requirements into effective cryptographic policies, certificate profiles, and key management standards
  • Collaboration with technical counterparts, audit and compliance teams, and business stakeholders
  • Automation solutions using Python

Nice to have

  • Emerging post-quantum cryptography (PQC) standards from NIST
  • Deep expertise with two-tier and three-tier CA models, root CA operations, and offline CA management best practices

What the JD emphasized

  • 5+ years of demonstrated technical experience designing, implementing, and supporting enterprise PKI solutions
  • 5+ years of hands-on experience managing certificate lifecycle processes