Skip to main content Skip to footer

Security Architect

Bengaluru Job No. atci-5525313-s2014979 Full-time

工作描述

Project Role : Security Architect
Project Role Description : Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations.
Must have skills : Data Encryption, Public Key Infrastructure
Good to have skills : NA
Minimum 2 year(s) of experience is required
Educational Qualification : 15 years full time education

Summary:
As a Security PKI Analyst, you are responsible for the operational support, administration, and continuous improvement of Public Key Infrastructure (PKI) services, including certificate lifecycle management, code signing infrastructure, and HSM operations. The role supports enterprise scale PKI environments within a managed services delivery model, ensuring service stability, security, and operational efficiency.

Roles & Responsibilities:
- Expected to be an SME, collaborate and manage the team to perform.
- Provide L2/L3 operational support for enterprise PKI services, including certificate issuance, renewal, revocation, validation, and troubleshooting across standard and secure environments.
- Operate and support Certificate Authorities (Root/Issuing), CRL/OCSP services, and code signing infrastructure, ensuring service availability, integrity, and compliance.
- Support HSM backed PKI and code signing environments, performing operational activities under dual control and segregation of duties, while excluding key ownership and custodianship.
- Manage PKI incidents, service requests, and minor changes in line with defined SLAs, including participation in on call support for P1/P2 incidents and major incident handling.
- Perform root cause analysis (RCA) for recurring PKI issues and implement corrective and preventive actions to reduce incidents and service disruption.
- Monitor PKI health and performance, including CA services, certificate chains, CRL/OCSP availability, and certificate related alerts using enterprise monitoring tools.
- Identify and implement automation and scripting opportunities (PowerShell / Python) to reduce manual PKI operations, improve turnaround time, and enhance operational efficiency.
- Contribute to Continuous Service Improvement (CSI) by analyzing ticket trends, operational metrics, and process gaps, and maintaining updated runbooks, SOPs, and knowledge articles.
- Support audit, compliance, and security activities by providing operational evidence, participating in reviews, and ensuring adherence to security and regulatory standards.
- Collaborate with application, infrastructure, and security teams to resolve PKI related issues, support application onboarding, and ensure smooth service delivery.
- Support BCDR and resilience activities, including certificate readiness validation and operational support during planned drills.


Professional & Technical Skills:
- Must To Have Skills: Proficiency in Data Encryption.
- Strong experience with Enterprise PKI, preferably Microsoft AD CS
- Hands on knowledge of:
- Certificate Authorities (Root, Issuing)
- TLS/SSL, X.509 certificates
- CRL, OCSP, certificate chains
- Experience supporting code signing infrastructure
- Working knowledge of HSMs (e.g., Thales, Entrust, or equivalent)
- Scripting experience using PowerShell and/or Python
- Familiarity with monitoring tools (e.g., Splunk or equivalent)

Additional Information:
- The candidate should have minimum 8 years of experience in Data Encryption.
- PKI / AD CS
- Cryptography or HSM related certifications
- A 15 years full time education is required.

职位要求

15 years full time education

更多了解埃森哲

我们的专长

我们秉承“科技融灵智,匠心承未来”的企业使命,致力于通过引领变革创造价值,为我们的客户、员工、股东、合作伙伴与整个社会创造美好未来。

认识我们的团队

从业务服务部门到各个行业领域, 从职场新人到卓越领袖,我们一直在运用科技创造非凡!

联系我们

加入我们的团队

搜索与你的技能和兴趣匹配的空缺职位。我们希望招聘充满激情、求知若渴、富有创意、专注于解决方案且喜欢团队合作的员工。

埃森哲职位博客

关注埃森哲职业博客,在职场中先人一步,从真正的业内人士处,获取职业建议、内部观点以及可以即学即用的行业真知。