PKI (Public Key Infrastructure) Specialist (Contract)

TANGSPAC CONSULTING PTE LTDSingaporemycareersfuturepublished 09/25/2026
Must-have:PythonAWSCloudSecurityRemote

Key Responsibilities Administer end-to-end certificate lifecycle management, including issuance, renewal, revocation, replacement, and expiration tracking.

Provide on-site hands-and-eyes support for remote technical teams accessing IT infrastructure devices Execute hosting provisioning (VMs, database, storage, backup) for IT and OT applications, following internal change management process Deploy and support SSL/TLS certificates across servers, middleware, databases, web applications, APIs, and network devices Implement certificate discovery, inventory management, and compliance reporting capabilities. Manage cryptographic keys and Hardware Security Modules (HSMs) in accordance with security standards. Develop and maintain automation scripts, APIs, and workflows for certificate provisioning and renewal. Support PKI integrations with enterprise tools such as monitoring, ITSM, vulnerability management, and secrets management platforms Troubleshoot certificate, authentication, encryption, and trust-chain related issues. Maintain PKI operational procedures, standards, and audit documentation. Collaborate with application, infrastructure, cybersecurity, and vendor teams on PKI projects and certificate deployments. Support modernization initiatives including TLS 1.3 adoption, certificate governance, and Post-Quantum Cryptography (PQC) readiness. Required Skills 5+ years in IT infrastructure project coordination or delivery, ideally including at least one new-site or facility build-out Hands-on troubleshooting & configuring experience with network, server hosting, storage/backup, and cloud (AWS) Manage and maintain enterprise PKI infrastructure, including Certificate Authorities (CA), Registration Authorities (RA), and certificate management platforms. Strong understanding of Public Key Infrastructure (PKI), X.509 Certificates, Certificate Authorities (CA), Certificate Revocation Lists (CRL), TLS/SSL, and Online Certificate Status Protocol (OCSP) Experience with Microsoft ADCS, DigiCert, Entrust, Keyfactor, Venafi, AppViewX, or similar PKI platforms. Knowledge of cryptographic technologies including RSA, ECC, AES-256, SHA-2/SHA-3, and TLS 1.2/1.3. Hands-on experience with Windows and Linux platforms. Scripting experience using PowerShell, Python, or Shell scripting. Understanding HSMs, RBAC, audit controls, and security compliance requirements. Experience in integrating PKI solutions with enterprise applications and middleware and database platforms. 10+ years of PKI, Cybersecurity, or Infrastructure Security experience. Certifications such as CISSP, CISM, Security+, or PKI-related certifications would be advantages Experience with certificate lifecycle management (CLM) platforms and automation solutions.