Role Overview
The PKI & Machine Identity Management (MIM) BAU Support Engineer is responsible for business-as-usual (BAU) operations, monitoring,
incident support, certificate lifecycle administration, and continuous optimization of Enterprise PKI and Venafi platforms.
The role ensures secure, reliable, and compliant issuance, renewal, revocation, and inventory management of certificates and other
machine identities across servers, network devices, applications, containers, and cloud services.
This position partners with Security, Infrastructure, Network, DevOps, and Application teams to maintain platform health, enable automation,
and support audit readiness through strong governance, documentation, and ITIL-aligned operational processes.
Key Responsibilities
1. BAU Operations & Platform Administration
- Perform daily health checks of PKI and Venafi components (services, databases, connectors, agents, HSM integrations, scheduled jobs).
- Monitor certificate expiry, discovery job status, policy changes, queue backlogs, and integration health; proactively address issues to avoid outages.
- Manage access controls and RBAC for PKI/Venafi consoles; support access reviews and segregation-of-duties requirements.
- Handle BAU requests: certificate issuance/renewal/revocation, template updates, discovery onboarding, exceptions, and reporting within defined SLAs.
- Maintain SOPs/runbooks, operational checklists, KB articles, and configuration documentation; keep artifacts current after changes.
2. Enterprise PKI Operations (Microsoft AD CS / Other PKI)
- Administer PKI hierarchy components (Root/Issuing CAs as applicable): service availability, backups, CA database health, and certificate chain validation.
- Manage certificate templates and enrollment policies: key usage, EKUs, subject/SAN formats, validity, renewal, and authorization controls.
- Support certificate enrollment mechanisms: auto-enrollment, SCEP/NDES, EST (if applicable), manual issuance, and API-based requests.
- Operate revocation services: CRL/Delta CRL publishing, OCSP responder (where applicable), and ensure reachability/latency SLAs.
- Support key protection and HSM operations (if in scope): key ceremonies support, key backup/restore procedures, and rotation/change controls.
3. Venafi – Certificate Lifecycle, Discovery & Policy Support
- Administer Venafi policy tree and certificate/device policies to enforce standardized certificate requirements and approvals.
- Configure and monitor discovery jobs to identify certificates, keys, and machine identities across on-prem and cloud environments.
- Support certificate lifecycle workflows: request intake, approvals, issuance, renewal automation, and revocation handling.
- Triage and resolve common Venafi issues: failed renewals, connector errors, CA connectivity failures, permissions, and policy conflicts.
- Maintain certificate inventory accuracy: tagging, ownership mapping, metadata hygiene, and decommissioning of stale entries.
4. Automation & Integrations (as applicable)
- Support integration and automation use cases for certificate deployment/renewal on platforms such as F5, IIS, Apache/Nginx, Kubernetes Ingress, and load balancers (as in scope).
- Maintain integrations with CAs, HSMs, CMDB, ITSM/ticketing tools (ServiceNow/Jira), and monitoring/SIEM for alerts and evidence.
- Troubleshoot API-based automation failures and renewal pipelines; support token/certificate rotation and secure credential handling.
- Assist DevOps/App teams with onboarding automation patterns (ACME/REST/agent-based deployment) aligned to governance.
5. Incident Response Support & Operational Readiness
- Respond to incidents involving certificate expiry, trust chain failures, revoked/compromised certificates, or PKI service outages.
- Provide evidence for SOC/IR: issuance logs, access history, certificate timelines, impacted system lists, and root cause indicators.
- Execute urgent mitigation actions under approval: emergency renewals, temporary extensions, CRL/OCSP remediation, and policy adjustments.
- Coordinate with application owners and infrastructure teams to validate post-fix service restoration and prevent recurrence.
6. Change, Problem & Capacity Management (ITIL-Aligned)
- Execute planned changes: CA/Venafi upgrades, connector updates, template modifications, policy changes, and scheduled maintenance with rollback plans.
- Drive problem management: RCA for recurring renewal failures, discovery gaps, CRL/OCSP outages, and automation regressions.
- Support capacity planning inputs: certificate volume growth, CA performance, database sizing, connector throughput, and HSM utilization.
- Ensure change records, approvals, and post-change validations are completed to maintain audit readiness.
7. Reporting, Compliance & Governance
- Produce BAU reports: expiring certificates, failed renewals, issuance volumes, policy compliance, and SLA metrics.
- Support audit/compliance evidence (e.g., ISO, SOC2, PCI) including: certificate inventory,
Responsibilities
Role Overview
The PKI & Machine Identity Management (MIM) BAU Support Engineer is responsible for business-as-usual (BAU) operations, monitoring,
incident support, certificate lifecycle administration, and continuous optimization of Enterprise PKI and Venafi platforms.
The role ensures secure, reliable, and compliant issuance, renewal, revocation, and inventory management of certificates and other
machine identities across servers, network devices, applications, containers, and cloud services.
This position partners with Security, Infrastructure, Network, DevOps, and Application teams to maintain platform health, enable automation,
and support audit readiness through strong governance, documentation, and ITIL-aligned operational processes.
Key Responsibilities
1. BAU Operations & Platform Administration
- Perform daily health checks of PKI and Venafi components (services, databases, connectors, agents, HSM integrations, scheduled jobs).
- Monitor certificate expiry, discovery job status, policy changes, queue backlogs, and integration health; proactively address issues to avoid outages.
- Manage access controls and RBAC for PKI/Venafi consoles; support access reviews and segregation-of-duties requirements.
- Handle BAU requests: certificate issuance/renewal/revocation, template updates, discovery onboarding, exceptions, and reporting within defined SLAs.
- Maintain SOPs/runbooks, operational checklists, KB articles, and configuration documentation; keep artifacts current after changes.
2. Enterprise PKI Operations (Microsoft AD CS / Other PKI)
- Administer PKI hierarchy components (Root/Issuing CAs as applicable): service availability, backups, CA database health, and certificate chain validation.
- Manage certificate templates and enrollment policies: key usage, EKUs, subject/SAN formats, validity, renewal, and authorization controls.
- Support certificate enrollment mechanisms: auto-enrollment, SCEP/NDES, EST (if applicable), manual issuance, and API-based requests.
- Operate revocation services: CRL/Delta CRL publishing, OCSP responder (where applicable), and ensure reachability/latency SLAs.
- Support key protection and HSM operations (if in scope): key ceremonies support, key backup/restore procedures, and rotation/change controls.
3. Venafi – Certificate Lifecycle, Discovery & Policy Support
- Administer Venafi policy tree and certificate/device policies to enforce standardized certificate requirements and approvals.
- Configure and monitor discovery jobs to identify certificates, keys, and machine identities across on-prem and cloud environments.
- Support certificate lifecycle workflows: request intake, approvals, issuance, renewal automation, and revocation handling.
- Triage and resolve common Venafi issues: failed renewals, connector errors, CA connectivity failures, permissions, and policy conflicts.
- Maintain certificate inventory accuracy: tagging, ownership mapping, metadata hygiene, and decommissioning of stale entries.
4. Automation & Integrations (as applicable)
- Support integration and automation use cases for certificate deployment/renewal on platforms such as F5, IIS, Apache/Nginx, Kubernetes Ingress, and load balancers (as in scope).
- Maintain integrations with CAs, HSMs, CMDB, ITSM/ticketing tools (ServiceNow/Jira), and monitoring/SIEM for alerts and evidence.
- Troubleshoot API-based automation failures and renewal pipelines; support token/certificate rotation and secure credential handling.
- Assist DevOps/App teams with onboarding automation patterns (ACME/REST/agent-based deployment) aligned to governance.
5. Incident Response Support & Operational Readiness
- Respond to incidents involving certificate expiry, trust chain failures, revoked/compromised certificates, or PKI service outages.
- Provide evidence for SOC/IR: issuance logs, access history, certificate timelines, impacted system lists, and root cause indicators.
- Execute urgent mitigation actions under approval: emergency renewals, temporary extensions, CRL/OCSP remediation, and policy adjustments.
- Coordinate with application owners and infrastructure teams to validate post-fix service restoration and prevent recurrence.
6. Change, Problem & Capacity Management (ITIL-Aligned)
- Execute planned changes: CA/Venafi upgrades, connector updates, template modifications, policy changes, and scheduled maintenance with rollback plans.
- Drive problem management: RCA for recurring renewal failures, discovery gaps, CRL/OCSP outages, and automation regressions.
- Support capacity planning inputs: certificate volume growth, CA performance, database sizing, connector throughput, and HSM utilization.
- Ensure change records, approvals, and post-change validations are completed to maintain audit readiness.
7. Reporting, Compliance & Governance
- Produce BAU reports: expiring certificates, failed renewals, issuance volumes, policy compliance, and SLA metrics.
- Support audit/compliance evidence (e.g., ISO, SOC2, PCI) including: certificate inventory,
Salary : As per industry standard.
Industry :IT-Software / Software Services
Functional Area : IT Software - Application Programming , Maintenance
As a Technology Architect, you will engage in the design and delivery of technology architecture for various platforms, products, or engagements. Your typical day will involve collaborating with cross-functional teams to define innovative solutions that address performance, capability, and scalability requirements. You will analyze existing systems, identify areas for improvement, and implement architectural best practices to ensure the successful execution of projects. Additionally, you will be responsible for guiding the team in making informed decisions that align with the overall technology strategy, fostering an environment of collaboration and continuous improvement. Roles & Responsibilities: - Expected to be an SME.- Collaborate and manage the team to perform.- Responsible for team decisions.- Engage with multiple teams and contribute on key decisions.- Provide solutions to problems for their immediate team and across multiple teams.- Facilitate knowledge sharing sessions to enhance team capabilities.- Evaluate emerging technologies and recommend their adoption where beneficial. Professional & Technical Skills: - Must To Have Skills: Proficiency in Databricks Unified Data Analytics Platform.- Strong understanding of cloud computing principles and architecture.- Experience with data integration and ETL processes.- Familiarity with big data technologies and frameworks.- Ability to design scalable and high-performance data solutions. Additional Information: - The candidate should have minimum 7.5 years of experience in Databricks Unified Data Analytics Platform.- This position is based at our Bengaluru office.- A 15 years full time education is required.
Responsibilities
As a Technology Architect, you will engage in the design and delivery of technology architecture for various platforms, products, or engagements. Your typical day will involve collaborating with cross-functional teams to define innovative solutions that address performance, capability, and scalability requirements. You will analyze existing systems, identify areas for improvement, and implement architectural best practices to ensure the successful execution of projects. Additionally, you will be responsible for guiding the team in making informed decisions that align with the overall technology strategy, fostering an environment of collaboration and continuous improvement. Roles & Responsibilities: - Expected to be an SME.- Collaborate and manage the team to perform.- Responsible for team decisions.- Engage with multiple teams and contribute on key decisions.- Provide solutions to problems for their immediate team and across multiple teams.- Facilitate knowledge sharing sessions to enhance team capabilities.- Evaluate emerging technologies and recommend their adoption where beneficial. Professional & Technical Skills: - Must To Have Skills: Proficiency in Databricks Unified Data Analytics Platform.- Strong understanding of cloud computing principles and architecture.- Experience with data integration and ETL processes.- Familiarity with big data technologies and frameworks.- Ability to design scalable and high-performance data solutions. Additional Information: - The candidate should have minimum 7.5 years of experience in Databricks Unified Data Analytics Platform.- This position is based at our Bengaluru office.- A 15 years full time education is required.
Salary : Rs. 27,00,000.0 - Rs. 29,00,000.0
Industry :IT-Software / Software Services
Functional Area : IT Software - Application Programming , Maintenance
Req ID: 10512717
Must Have: Big Query-3 Years , Data Flow- 2 years, Data Proc- 2 years, Cloud Sql-1 Years Terraform e-1 Years,Python or Java
Work Location: Hyderabad/Pune/Bangalore/Chennai/Kolkata- Bangalore
Experience Range in Required Skills: 4 to 8 Years
Responsibilities
Req ID: 10512717
Must Have: Big Query-3 Years , Data Flow- 2 years, Data Proc- 2 years, Cloud Sql-1 Years Terraform e-1 Years,Python or Java
Work Location: Hyderabad/Pune/Bangalore/Chennai/Kolkata- Bangalore
Experience Range in Required Skills: 4 to 8 Years
Salary : As per industry standard.
Industry :IT-Software / Software Services
Functional Area : IT Software - Application Programming , Maintenance
Role Category :Programming & Design
Role :Big Query-3 Years , Data Flow- 2 years, Data Proc- 2 years, Cloud Sql-1 Years Terraform e-1 Years,Python or Java