Job Description
This is a hands-on Technical service management role. This role is part of the ETSOM - Identity Security Governance (ISG) which drives and improves Public Key Infrastructure and certificate management across the entire Shell estate. Works with Individual partners with other technology teams to design and implement PKI automation and best practices. Role will be accountable to drive 3 Core security services which are Public Key Infrastructure (PKI), Certificate Management Services (CMS) and Enterprise Key Management Services (EKMS)
The successful candidate is someone who is a Domain Technical Subject Matter Expert, has good supplier technical delivery skills, has strong attention to detail as well as motivation to collaborate.
Primary focus areas are:. Ensures accurate inventory of the certificates in use in our environment
. Improves and reduces manual PKI and certificate activities through automation, guidance and documentation
. Creates and manages automation and workflows relevant for certificate management
. Supports supplier's technology teams on all aspects of certificate life-cycle management like Discovery, Generation, Distribution, Rotation and Revocation.
. Validates security and operational requirements for PKI and certificate management
Role and Responsibilities :. Design processes and workflows for issuing, renewing and revoking certificates
. Document PKI and certificate management guidance for the company
. Determine automation opportunities for certificate lifecycle, and as the subject matter expert help guide and shape how automation is enabled
. Design new certificate management services, integrations and technologies
. Advocate for security and compliance when interacting with other teams
. Create and maintain useful, well-structured and error free documentation
. Communicate complicated issues clearly and succinctly to various levels of the business
. Consistently abide by change control requirements for our services
. Align risk and control processes into day to day responsibilities to monitor and mitigate risk and escalates appropriately
. Supplier delivery management for all 3 services
. Technology road map review along with the Industry best practices
. Tracking SLA's and PKI's with vendors
. Weekly , Monthly, Quaterly Service reviews
Technical Requirements :. Minimum of 8-10 years of related experience
. Solid working knowledge on Windows 2012,2016,2019 Operating Systems
. MCSE / MCTS / MCITP qualification desirable
. Good understanding of the network and authentication protocols (SMB/CIFS, DNS, RPC, LDAP, Kerberos, NTLM, etc).
. In-depth experience designing, deploying, managing and maintaining Public Key Infrastructure
. Strong, demonstrable experience in Cybersecurity engineering, design, implementation and documentation
. Provide hands on engineering support required to build and maintain internal and external PKI systems.
. Good understanding of security principles (User profiles, authentication, authorization, PKI: EFS/Smartcard/Certificates)
. Group Policy implementation, design and troubleshooting
. Security and Administration of the PKI
. Working knowledge of cryptography
. Experience with LDAP directories
. Knowledge of virtualization technologies
. Working knowledge of Windows performance monitoring & troubleshooting
. Working knowledge of SCOM would be beneficial.
. Understanding of X.509, RSA and general certificate management processes
. Solid experience with public key infrastructure (PKI)
. Expert knowledge with certificate lifecycle management
. Expert knowledge of Secure Sockets Layer (SSL) certificate
. Solid experience with Microsoft Certificate Services
. Experience with commercial Certificate Authority providers ( like Microsoft, DigiCert, Symantec, Entrust, Sectigo, GlobalSign, GeoTrust & Rapid SSL etc )
. Expert knowledge in implementation of Hardware Security Modules (HSM)
. Expert knowledge of AppViewX or similar cert management tools.
. Expert knowledge of industry-standard Information Security frameworks, policies and procedures
. Working knowledge of HSM ( nChiper ) , ACS Cards,
. Expert knowledge of Low Crypto , High Crypto CA Servers
. Root Certificate Authority maintenance and life cycle
. Awareness of Block-chain based PKI ( IOT )
. Web of Trust and working knowledge
. Expert knowledge of digital certificates in Enterprise and Stand alone set up
. In-depth knowledge of typical IT operating systems (Windows/Linux) and technology platforms (Networking, Server, Application, Cloud)
. Development and scripting background or experience
Employement Category:
Employement Type: Full time
Industry: Oil
Functional Area: IT
Role Category: Software Engineer
Role/Responsibilies: Service Integration Analyst -PKI
Contact Details:
Company: Shell
Location(s): Bengaluru