Role Overview
The PKI & Machine Identity Management (MIM) BAU Support Engineer is responsible for business-as-usual (BAU) operations, monitoring,
incident support, certificate lifecycle administration, and continuous optimization of Enterprise PKI and Venafi platforms.
The role ensures secure, reliable, and compliant issuance, renewal, revocation, and inventory management of certificates and other
machine identities across servers, network devices, applications, containers, and cloud services.
This position partners with Security, Infrastructure, Network, DevOps, and Application teams to maintain platform health, enable automation,
and support audit readiness through strong governance, documentation, and ITIL-aligned operational processes.
Key Responsibilities
1. BAU Operations & Platform Administration
- Perform daily health checks of PKI and Venafi components (services, databases, connectors, agents, HSM integrations, scheduled jobs).
- Monitor certificate expiry, discovery job status, policy changes, queue backlogs, and integration health; proactively address issues to avoid outages.
- Manage access controls and RBAC for PKI/Venafi consoles; support access reviews and segregation-of-duties requirements.
- Handle BAU requests: certificate issuance/renewal/revocation, template updates, discovery onboarding, exceptions, and reporting within defined SLAs.
- Maintain SOPs/runbooks, operational checklists, KB articles, and configuration documentation; keep artifacts current after changes.
2. Enterprise PKI Operations (Microsoft AD CS / Other PKI)
- Administer PKI hierarchy components (Root/Issuing CAs as applicable): service availability, backups, CA database health, and certificate chain validation.
- Manage certificate templates and enrollment policies: key usage, EKUs, subject/SAN formats, validity, renewal, and authorization controls.
- Support certificate enrollment mechanisms: auto-enrollment, SCEP/NDES, EST (if applicable), manual issuance, and API-based requests.
- Operate revocation services: CRL/Delta CRL publishing, OCSP responder (where applicable), and ensure reachability/latency SLAs.
- Support key protection and HSM operations (if in scope): key ceremonies support, key backup/restore procedures, and rotation/change controls.
3. Venafi – Certificate Lifecycle, Discovery & Policy Support
- Administer Venafi policy tree and certificate/device policies to enforce standardized certificate requirements and approvals.
- Configure and monitor discovery jobs to identify certificates, keys, and machine identities across on-prem and cloud environments.
- Support certificate lifecycle workflows: request intake, approvals, issuance, renewal automation, and revocation handling.
- Triage and resolve common Venafi issues: failed renewals, connector errors, CA connectivity failures, permissions, and policy conflicts.
- Maintain certificate inventory accuracy: tagging, ownership mapping, metadata hygiene, and decommissioning of stale entries.
4. Automation & Integrations (as applicable)
- Support integration and automation use cases for certificate deployment/renewal on platforms such as F5, IIS, Apache/Nginx, Kubernetes Ingress, and load balancers (as in scope).
- Maintain integrations with CAs, HSMs, CMDB, ITSM/ticketing tools (ServiceNow/Jira), and monitoring/SIEM for alerts and evidence.
- Troubleshoot API-based automation failures and renewal pipelines; support token/certificate rotation and secure credential handling.
- Assist DevOps/App teams with onboarding automation patterns (ACME/REST/agent-based deployment) aligned to governance.
5. Incident Response Support & Operational Readiness
- Respond to incidents involving certificate expiry, trust chain failures, revoked/compromised certificates, or PKI service outages.
- Provide evidence for SOC/IR: issuance logs, access history, certificate timelines, impacted system lists, and root cause indicators.
- Execute urgent mitigation actions under approval: emergency renewals, temporary extensions, CRL/OCSP remediation, and policy adjustments.
- Coordinate with application owners and infrastructure teams to validate post-fix service restoration and prevent recurrence.
6. Change, Problem & Capacity Management (ITIL-Aligned)
- Execute planned changes: CA/Venafi upgrades, connector updates, template modifications, policy changes, and scheduled maintenance with rollback plans.
- Drive problem management: RCA for recurring renewal failures, discovery gaps, CRL/OCSP outages, and automation regressions.
- Support capacity planning inputs: certificate volume growth, CA performance, database sizing, connector throughput, and HSM utilization.
- Ensure change records, approvals, and post-change validations are completed to maintain audit readiness.
7. Reporting, Compliance & Governance
- Produce BAU reports: expiring certificates, failed renewals, issuance volumes, policy compliance, and SLA metrics.
- Support audit/compliance evidence (e.g., ISO, SOC2, PCI) including: certificate inventory,
Responsibilities
Role Overview
The PKI & Machine Identity Management (MIM) BAU Support Engineer is responsible for business-as-usual (BAU) operations, monitoring,
incident support, certificate lifecycle administration, and continuous optimization of Enterprise PKI and Venafi platforms.
The role ensures secure, reliable, and compliant issuance, renewal, revocation, and inventory management of certificates and other
machine identities across servers, network devices, applications, containers, and cloud services.
This position partners with Security, Infrastructure, Network, DevOps, and Application teams to maintain platform health, enable automation,
and support audit readiness through strong governance, documentation, and ITIL-aligned operational processes.
Key Responsibilities
1. BAU Operations & Platform Administration
- Perform daily health checks of PKI and Venafi components (services, databases, connectors, agents, HSM integrations, scheduled jobs).
- Monitor certificate expiry, discovery job status, policy changes, queue backlogs, and integration health; proactively address issues to avoid outages.
- Manage access controls and RBAC for PKI/Venafi consoles; support access reviews and segregation-of-duties requirements.
- Handle BAU requests: certificate issuance/renewal/revocation, template updates, discovery onboarding, exceptions, and reporting within defined SLAs.
- Maintain SOPs/runbooks, operational checklists, KB articles, and configuration documentation; keep artifacts current after changes.
2. Enterprise PKI Operations (Microsoft AD CS / Other PKI)
- Administer PKI hierarchy components (Root/Issuing CAs as applicable): service availability, backups, CA database health, and certificate chain validation.
- Manage certificate templates and enrollment policies: key usage, EKUs, subject/SAN formats, validity, renewal, and authorization controls.
- Support certificate enrollment mechanisms: auto-enrollment, SCEP/NDES, EST (if applicable), manual issuance, and API-based requests.
- Operate revocation services: CRL/Delta CRL publishing, OCSP responder (where applicable), and ensure reachability/latency SLAs.
- Support key protection and HSM operations (if in scope): key ceremonies support, key backup/restore procedures, and rotation/change controls.
3. Venafi – Certificate Lifecycle, Discovery & Policy Support
- Administer Venafi policy tree and certificate/device policies to enforce standardized certificate requirements and approvals.
- Configure and monitor discovery jobs to identify certificates, keys, and machine identities across on-prem and cloud environments.
- Support certificate lifecycle workflows: request intake, approvals, issuance, renewal automation, and revocation handling.
- Triage and resolve common Venafi issues: failed renewals, connector errors, CA connectivity failures, permissions, and policy conflicts.
- Maintain certificate inventory accuracy: tagging, ownership mapping, metadata hygiene, and decommissioning of stale entries.
4. Automation & Integrations (as applicable)
- Support integration and automation use cases for certificate deployment/renewal on platforms such as F5, IIS, Apache/Nginx, Kubernetes Ingress, and load balancers (as in scope).
- Maintain integrations with CAs, HSMs, CMDB, ITSM/ticketing tools (ServiceNow/Jira), and monitoring/SIEM for alerts and evidence.
- Troubleshoot API-based automation failures and renewal pipelines; support token/certificate rotation and secure credential handling.
- Assist DevOps/App teams with onboarding automation patterns (ACME/REST/agent-based deployment) aligned to governance.
5. Incident Response Support & Operational Readiness
- Respond to incidents involving certificate expiry, trust chain failures, revoked/compromised certificates, or PKI service outages.
- Provide evidence for SOC/IR: issuance logs, access history, certificate timelines, impacted system lists, and root cause indicators.
- Execute urgent mitigation actions under approval: emergency renewals, temporary extensions, CRL/OCSP remediation, and policy adjustments.
- Coordinate with application owners and infrastructure teams to validate post-fix service restoration and prevent recurrence.
6. Change, Problem & Capacity Management (ITIL-Aligned)
- Execute planned changes: CA/Venafi upgrades, connector updates, template modifications, policy changes, and scheduled maintenance with rollback plans.
- Drive problem management: RCA for recurring renewal failures, discovery gaps, CRL/OCSP outages, and automation regressions.
- Support capacity planning inputs: certificate volume growth, CA performance, database sizing, connector throughput, and HSM utilization.
- Ensure change records, approvals, and post-change validations are completed to maintain audit readiness.
7. Reporting, Compliance & Governance
- Produce BAU reports: expiring certificates, failed renewals, issuance volumes, policy compliance, and SLA metrics.
- Support audit/compliance evidence (e.g., ISO, SOC2, PCI) including: certificate inventory,
Salary : As per industry standard.
Industry :IT-Software / Software Services
Functional Area : IT Software - Application Programming , Maintenance
Requesting your support to identify/share suitable CWR resources at SA level
JD is attached. Pls share the JD with the candidates so that they are aware of it. Profiles should be in the above attached format.
Please note: They are primarily looking for Bangalore based people for the role.
Responsibilities
Requesting your support to identify/share suitable CWR resources at SA level
JD is attached. Pls share the JD with the candidates so that they are aware of it. Profiles should be in the above attached format.
Please note: They are primarily looking for Bangalore based people for the role.
Salary : As per industry standard.
Industry :IT-Software / Software Services
Functional Area : IT Software - Application Programming , Maintenance
: Digital : Microsoft Azure~Identity and Access Management Implementation| Design & Architecture~Multifactor Authentication (MFA)Role Descriptions: Azure AD AdministrationManaging users andIdentity and Access Management (IAM)Configure SSO for SaaS apps in AAD| setup App Registrations and API permissions| ensure secure token exchange.Design| implement| and troubleshoot hybrid identity with Azure AD Connect| including password hash sync| pass-through authentication groups| enforcing RBAC and implementing Conditional Access with Multi Factor Authentication (MFA)
Essential Skills: Azure AD AdministrationManaging users andIdentity and Access Management (IAM)Configure SSO for SaaS apps in AAD| setup App Registrations and API permissions| ensure secure token exchange.Design| implement| and troubleshoot hybrid identity with Azure AD Connect| including password hash sync| pass-through authentication groups| enforcing RBAC and implementing Conditional Access with Multi Factor Authentication (MFA)
Responsibilities
: Digital : Microsoft Azure~Identity and Access Management Implementation| Design & Architecture~Multifactor Authentication (MFA)Role Descriptions: Azure AD AdministrationManaging users andIdentity and Access Management (IAM)Configure SSO for SaaS apps in AAD| setup App Registrations and API permissions| ensure secure token exchange.Design| implement| and troubleshoot hybrid identity with Azure AD Connect| including password hash sync| pass-through authentication groups| enforcing RBAC and implementing Conditional Access with Multi Factor Authentication (MFA)
Essential Skills: Azure AD AdministrationManaging users andIdentity and Access Management (IAM)Configure SSO for SaaS apps in AAD| setup App Registrations and API permissions| ensure secure token exchange.Design| implement| and troubleshoot hybrid identity with Azure AD Connect| including password hash sync| pass-through authentication groups| enforcing RBAC and implementing Conditional Access with Multi Factor Authentication (MFA)
Salary : As per industry standard.
Industry :IT-Software / Software Services
Functional Area : IT Software - Application Programming , Maintenance
Role Category :Programming & Design
Role :: Digital : Microsoft Azure~Identity and Access Management Implementation| Design & Architecture~Multifactor Authentication (MFA)
As a Cloud Migration Engineer, you will assess existing solutions and infrastructure to facilitate their migration to the cloud. Your typical day will involve planning, delivering, and implementing application and data migration strategies that leverage both private and public cloud technologies. You will work collaboratively with various teams to ensure that the migration processes are efficient, scalable, and aligned with the organization's business objectives, ultimately driving next-generation business outcomes. Roles & Responsibilities: - Expected to perform independently and become an SME.- Required active participation/contribution in team discussions.- Contribute in providing solutions to work related problems.- Assist in the development of migration strategies that align with business goals.- Collaborate with cross-functional teams to ensure seamless integration of cloud solutions. Professional & Technical Skills: - Must To Have Skills: Proficiency in AWS Glue.- Experience with cloud service providers such as Amazon Web Services, Microsoft Azure, or Google Cloud Platform.- Strong understanding of data migration techniques and best practices.- Familiarity with containerization technologies like Docker and Kubernetes.- Knowledge of scripting languages such as Python or Bash for automation tasks. Additional Information: - The candidate should have minimum 3 years of experience in AWS Glue.- This position is based at our Chennai office.- A 15 years full time education is required.
Responsibilities
As a Cloud Migration Engineer, you will assess existing solutions and infrastructure to facilitate their migration to the cloud. Your typical day will involve planning, delivering, and implementing application and data migration strategies that leverage both private and public cloud technologies. You will work collaboratively with various teams to ensure that the migration processes are efficient, scalable, and aligned with the organization's business objectives, ultimately driving next-generation business outcomes. Roles & Responsibilities: - Expected to perform independently and become an SME.- Required active participation/contribution in team discussions.- Contribute in providing solutions to work related problems.- Assist in the development of migration strategies that align with business goals.- Collaborate with cross-functional teams to ensure seamless integration of cloud solutions. Professional & Technical Skills: - Must To Have Skills: Proficiency in AWS Glue.- Experience with cloud service providers such as Amazon Web Services, Microsoft Azure, or Google Cloud Platform.- Strong understanding of data migration techniques and best practices.- Familiarity with containerization technologies like Docker and Kubernetes.- Knowledge of scripting languages such as Python or Bash for automation tasks. Additional Information: - The candidate should have minimum 3 years of experience in AWS Glue.- This position is based at our Chennai office.- A 15 years full time education is required.
Salary : As per industry standard.
Industry :IT-Software / Software Services
Functional Area : IT Software - Application Programming , Maintenance
Key Responsibilities:
Prepare and maintain financial records, reports, and reconciliations.
Handle accounts payable and receivable, ensuring timely processing of invoices and payments.
Assist in the preparation of monthly and annual financial statements.
Monitor and manage cash flow, ensuring sufficient funds are available for operational needs.
Process payroll and ensure compliance with tax regulations.
Assist in budgeting and forecasting.
Liaise with external auditors for financial audits and compliance requirements.
Ensure timely submission of tax returns and other regulatory filings.
Review and reconcile general ledger entries, identifying discrepancies and resolving them promptly.
Assist in the preparation of financial reports for management.
Support the finance team in various ad-hoc tasks as required.
Responsibilities
Key Responsibilities:
Prepare and maintain financial records, reports, and reconciliations.
Handle accounts payable and receivable, ensuring timely processing of invoices and payments.
Assist in the preparation of monthly and annual financial statements.
Monitor and manage cash flow, ensuring sufficient funds are available for operational needs.
Process payroll and ensure compliance with tax regulations.
Assist in budgeting and forecasting.
Liaise with external auditors for financial audits and compliance requirements.
Ensure timely submission of tax returns and other regulatory filings.
Review and reconcile general ledger entries, identifying discrepancies and resolving them promptly.
Assist in the preparation of financial reports for management.
Support the finance team in various ad-hoc tasks as required.
Salary : Rs. 2,50,000.0 - Rs. 3,60,000.0
Industry :IT-Software / Software Services
Functional Area : IT Software - Application Programming , Maintenance