IAM Engineer (PKI & Identity Infrastructure)
About the role
We are looking for an experienced IAM Engineer specializing in Public Key Infrastructure (PKI) and Identity Infrastructure to join a global IT organization. In this role, you will be responsible for designing, implementing, and maintaining enterprise PKI services while integrating certificate-based authentication with modern identity platforms and security solutions.
Working closely with Infrastructure, Security, Endpoint, and Networking teams, you will help deliver secure identity services that support a modern Zero Trust environment.
Key Responsibilities
- Design, implement, and maintain enterprise PKI infrastructure, including Certificate Authorities (CA), subordinate CAs, and trust chains.
- Manage the complete certificate lifecycle, including issuance, renewal, revocation, and monitoring.
- Integrate PKI services with Microsoft Active Directory, Microsoft Entra ID, Intune, endpoint devices, and enterprise applications.
- Maintain and enhance certificate auto-enrollment and certificate-based authentication services.
- Support Zero Trust initiatives, including passwordless authentication and device trust.
- Configure and maintain CRL, OCSP, and other PKI security mechanisms.
- Troubleshoot and resolve incidents related to identity, authentication, and digital certificates.
- Develop and maintain technical documentation, operational procedures, and knowledge base articles.
- Collaborate with cross-functional teams including Information Security, Endpoint Management, Networking, and Infrastructure.
- Contribute to automation and continuous improvement of IAM and PKI processes.
Required Skills & Experience
- 3–5+ years of experience in Identity & Access Management or Identity Infrastructure.
- Hands-on experience administering Enterprise Public Key Infrastructure (PKI).
- Strong knowledge of Microsoft Active Directory (AD DS, GPO, LDAP, Kerberos).
- Experience with Microsoft Entra ID (Azure AD), including SSO, Conditional Access, and Identity Governance.
- Practical experience with Active Directory Certificate Services (AD CS).
- Strong understanding of X.509 certificates, SSL/TLS, client certificates, and code signing.
- Experience managing CRL, OCSP, certificate auto-enrollment, and certificate lifecycle management.
- Experience integrating PKI with Intune, MDM platforms, VPN, Wi-Fi (802.1X), enterprise applications, and authentication protocols such as SAML, OIDC, and mTLS.
- PowerShell scripting experience, particularly for AD and PKI administration.
- Basic knowledge of APIs and process automation.
- Understanding of security frameworks such as ISO 27001, NIST, and Zero Trust architecture.
- Good understanding of security risks related to Identity and PKI technologies.
Soft Skills
- Strong analytical and problem-solving abilities.
- Excellent communication skills with both technical and non-technical stakeholders.
- Ability to work effectively in an international, cross-functional environment.
- Self-driven, proactive approach with strong ownership.
- High attention to quality and security.
- Experience working within Agile and/or DevOps environments.
Nice to Have
- Experience with ITSM platforms such as ServiceNow.
- Knowledge of Azure DevOps or similar documentation platforms.
- Experience with identity automation and scripting.
- Familiarity with modern authentication technologies and passwordless solutions.
What You'll Do
You will play a key role in strengthening enterprise identity security by delivering scalable PKI solutions, supporting secure authentication, and contributing to the organization's Zero Trust strategy while working within a global technology environment.