Project Role :Security ArchitectProject Role Description :Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations. Must have skills :Data EncryptionGood to have skills :Public Key Infrastructure Minimum 5 year(s) of experience is requiredEducational Qualification :15 years full time educationSummary: As a Security Architect, you will define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Your typical day will involve collaborating with various teams to document the implementation of cloud security controls and facilitating the transition to cloud security-managed operations. You will engage in discussions to align security strategies with organizational objectives, ensuring that all security measures are effectively integrated into the cloud environment. Additionally, you will assess and refine security protocols to adapt to evolving threats and compliance requirements, contributing to a secure and resilient cloud infrastructure. Roles & Responsibilities:
Expected to be an SME.
Collaborate and manage the team to perform.
Design and maintain enterprise PKI architecture, including Root and Subordinate Certificate Authorities (CAs)
Define and enforce cryptographic standards (key algorithms, sizes, hashing mechanisms)
Ensure PKI infrastructure aligns with security best practices and scalability requirements
Install, configure, harden, and maintain Certificate Authority systems
Perform CA certificate renewals, CRL and OCSP configuration, and lifecycle maintenance
Manage secure backup and recovery of CA systems and cryptographic material
Ensure high availability and disaster recovery for PKI services.
Define and maintain certificate templates and issuance policies
Manage cryptographic key generation, storage, and protection
Integrate and administer Hardware Security Modules (HSMs), where applicable
Conduct regular reviews of certificate usage, expiration risks, and cryptographic health
Identify and remediate vulnerabilities related to certificates and trust chains
Manage and monitor certificate revocation mechanisms (CRL and OCSP)
Implement automation for certificate enrollment and renewal (e.g., auto-enrollment, APIs, scripts)
Integrate PKI services with certificate lifecycle management toolsProfessional & Technical Skills:Hands-on experience with Microsoft AD Certificate Services (AD CS), including Root & Issuing CAs, certificate templates, auto-enrollment, CRL and OCSP.
Skilled in NDES/SCEP for secure certificate enrollment of network devices and MDM-managed endpoints (including Intune integration)
Experienced in managing DigiCert public trust certificates, covering SSL/TLS lifecycle, renewals, and revocations
Strong expertise in certificate lifecycle management, troubleshooting trust issues, and ensuring secure authentication using X.509 and TLSAdditional Information:
The candidate should have minimum 5 years of experience in Data Encryption.
This position is based at our Bengaluru or Hyderabad office.
A 15 years full time education is required.Qualification 15 years full time education
Job Classification
Industry: IT Services & ConsultingFunctional Area / Department: IT & Information SecurityRole Category: IT SecurityRole: Security Architect / ConsultantEmployement Type: Full time