Job is active

PKI (Public Key Infrastructure) Specialist (Contract)

8 000 – 12 000 $
1 view

About this job

Role Summary

We are seeking an experienced PKI Engineer to design, implement, administer, and support the organization's Public Key Infrastructure (PKI) environment. The role will be responsible for certificate lifecycle management, certificate authority (CA) administration, cryptographic standard compliance, automation of certificate operations, and integration with enterprise applications and security platforms.

Responsible for the design, implementation, operation, and governance of the enterprise Public Key Infrastructure (PKI) environment, including certificate lifecycle management, key management, security compliance, automation, and integration with enterprise applications and infrastructure platforms. This role will support the PKI CLM program and ensure secure management of digital certificates across the organization.

Key Responsibilities

  • Manage and maintain enterprise PKI infrastructure, including Certificate Authorities (CA), Registration Authorities (RA), and certificate management platforms.
  • Administer end-to-end certificate lifecycle management, including issuance, renewal, revocation, replacement, and expiration tracking.
  • Deploy and support SSL/TLS certificates across servers, middleware, databases, web applications, APIs, and network devices
  • Implement certificate discovery, inventory management, and compliance reporting capabilities.
  • Manage cryptographic keys and Hardware Security Modules (HSMs) in accordance with security standards.
  • Develop and maintain automation scripts, APIs, and workflows for certificate provisioning and renewal.
  • Support PKI integrations with enterprise tools such as monitoring, ITSM, vulnerability management, and secrets management platforms
  • Troubleshoot certificate, authentication, encryption, and trust-chain related issues.
  • Maintain PKI operational procedures, standards, and audit documentation.
  • Collaborate with application, infrastructure, cybersecurity, and vendor teams on PKI projects and certificate deployments.
  • Support modernization initiatives including TLS 1.3 adoption, certificate governance, and Post-Quantum Cryptography (PQC) readiness.

Required Skills

  • Strong understanding of Public Key Infrastructure (PKI), X.509 Certificates, Certificate Authorities (CA), Certificate Revocation Lists (CRL), TLS/SSL, and Online Certificate Status Protocol (OCSP)
  • Experience with Microsoft ADCS, DigiCert, Entrust, Keyfactor, Venafi, AppViewX, or similar PKI platforms.
  • Knowledge of cryptographic technologies including RSA, ECC, AES-256, SHA-2/SHA-3, and TLS 1.2/1.3.
  • Hands-on experience with Windows and Linux platforms.
  • Scripting experience using PowerShell, Python, or Shell scripting.
  • Understanding HSMs, RBAC, audit controls, and security compliance requirements.
  • Experience in integrating PKI solutions with enterprise applications and middleware and database platforms.
  • 10+ years of PKI, Cybersecurity, or Infrastructure Security experience.
  • Certifications such as CISSP, CISM, Security+, or PKI-related certifications would be advantages
  • Experience with certificate lifecycle management (CLM) platforms and automation solutions.

Market insight

64% above median
6 085 $

Based on 26 065 offers with salary for Jobs on-site in Singapore

Full salary breakdown

Frequently asked questions

What salary can I expect?

The employer lists 8 000 – 12 000 $ for this role at ICON OUTSOURCING in Singapore. For comparison, the local market median is about 6 085 $ based on 26 065 similar offers.

How do I apply for this job?

Open the original source page and contact the employer there. Finder never charges job seekers.

Are these jobs up to date?

Yes. Finder regularly refreshes vacancies from public sources and removes closed offers.

Where can I see employment type and work format?

Key conditions are shown above the description. You can also open related listings for ICON OUTSOURCING and Singapore.

Apply