NC
Senior Security Engineer
NR Consulting - India
๐ฎ๐ณ India
On-site
Senior
4 days ago
- PKI
- ServiceNow
- Python
- PowerShell
- REST API
- SSH
- CyberArk
- SFTP
- Vault
- Azure
- Key Vault
4 days ago
Location : Bangalore
EXP : 6 +Years
Description
Experience & profile
6+ years in platform, infrastructure or security engineering, with hands-on PKI/certificate-lifecycle or machine-identity tooling experience: this is live technical build work across certificates and keys, configuring tooling and populating system-of-record data for a live PKI environment, not administrative or entry-level support.
Comfortable working against a defined, time-boxed scope of work with deliverables tracked to MAP dates, rather than an open-ended mandate.
Purpose
Extend the enterprise's existing certificate and key tooling โ Venafi, ServiceNow โ to cover the machine-identity assets this program is bringing into scope, and populate the system of record those assets need before the governance function can Client, track or report on them. This is hands-on technical build capacity against a defined scope, not original architecture and not an open-ended function.
Roles & Responsibilities
Discovery build support
Machine-identity discovery build support โextend the Phase 1โ3 discovery effort to machine-identity assets (certificates and keys) against the defined, time-boxed scope of work, capturing the internal-vs-external classification ESS01 requires at the point of discovery (this determines the rotation cadence โ 1 year external, 5 years internal).
CMDB population โpopulate ServiceNow (candidate CMDB system of record, Program Doc open item 7) with the resulting machine-identity asset inventory, in a structure the governance function can query, track and report from.
Tooling configuration โWork with SNOW team for configure tooling changes needed to support machine-identity assets across the build phases, including surfacing the existing Venafi Inventory โ Certificates view as the discovery surface the program builds on rather than replaces.
Control-design support
Rekey-vs-renew enforcement โsupport configuration and process changes that make the rekey/renew distinction operational: Venafi renews against the same key material by default (ESS01 ยง2.1 requires the private and public key cryptoperiods to match), so tooling and workflow need an explicit control, not just a policy statement.
Key Owner / Custodian registry โsupport building the registry schema once Information Security rules on the open Key Holder definition (open item 2), so ownership data captured during discovery lands in a structure the standing function can register and monitor.
Skills & product knowledge
Core technical skills
PKI and cryptography fundamentals: X.509 certificates, PGP/GPG key pairs, certificate signing requests, cryptoperiods, approved key lengths and algorithms (ESS01 ยง1.0 sets a 2048-bit minimum).
Certificate lifecycle engineering: issuance, renewal, revocation and โ distinctly โ rotation/rekey, and why a renewal-only practice can leave decade-old key material behind a compliant-looking expiry dashboard.
CMDB and ITSM data modelling: configuration-item structuring, asset attribution and integration patterns for a system of record (ServiceNow), including API/REST-based data population.
Scripting and automation for discovery and tooling integration (e.g., Python, PowerShell, REST/API scripting against Venafi and ServiceNow).
Working knowledge of PGP/SSH key material and third-party file-transfer contexts (IBM Sterling File Gateway with Secure Proxy) is a plus, given the audit-scope exposure sits there.
Product / platform knowledge
Venafi/ Cyberark Certificate Mgmt โcertificate inventory (Inventory โ Certificates)
IBM Sterling File Gateway with Secure Proxy โawareness of the SFTP/PGP onboarding process for third-party file transfer, since PGP key material (the audit-scope exposure) is tracked through the Sterling onboarding form rather than Venafi or Oasis.
ServiceNow (Nice to have) โCMDB structuring and the renewal-ticket queue workflow; candidate system of record for key/certificate governance evidence.
DigiCert โthe public certificate authority behind Venafi issuance; awareness of the yearly public-certificate subscription model.
Oasis Security (Nice to have)โ discovery, ownership attribution, lifecycle management and automated secret rotation via a vault (HashiCorp Vault, Azure Key Vault or CyberArk);
CyberArk vaultโ awareness of vault setup, configuration and rotation/renewal actions via vault API integration to discovery tool.
2. Security engineer
| Field | Detail |
|---|---|
| Track | Security analyst โ support for technical build, tooling and implementation to steady state governance |
Experience & profile
3โ6 years in a governance, risk, compliance, IT audit-support or Security platform-operations analyst capacity โ approved tier basis:, closer to a mid-level analyst assignment with PKI engineering skills.
Purpose
Run the governance layer day to day: know what certificates and keys exist, who owns them, when they expire, and whether the required controls (ownership, validation, evidence) are actually operating โ without ever taking on the ownership or rotation work itself. In the build phase, this means baselining today's process against ESS01 so the standing function is designed against reality rather than assumption.
Roles & Responsibilities
Project phase (current, approved scope)
Certificate discovery โexecute the five-question discovery model (owner, storage location, expiry, renewal process, monitoring) against the in-scope keys / certificate population, tracked Confirmed / In Progress / Pending โ the deliverable.
Process baseline โbaseline today's two-approval issuance process and ServiceNow-queue renewal workflow against standard, and document which certificates the existing AD-team approval step already covers versus where the gaps sit.
Cadence review โassess today's certificate governance and oversight cadence and recommend the cadence the governance function should hold once steady state begins
Support to Senior Secops Enginer during Build / implementation
Skills & product knowledge
Core skills
Structured discovery and inventory methodology: comfortable executing a defined discovery model (the five-question model: owner, storage location, expiry, renewal process, monitoring) consistently across a large asset population and tracking status to closure.
Process baselining and gap documentation: able to compare an as-is operational process (approvals, renewal queues) against a written standard (ESS01) and state precisely where the two diverge.
Control and audit-evidence discipline: understands why system-of-record artefacts are required over email or meeting notes as evidence, and how to retain and organise that evidence for review.
Compliance/governance reporting: able to turn inventory and exception data into reporting that leadership and Internal Audit can act on, without editorialising the underlying facts.
Stakeholder communication for notification and escalation: clear, low-friction outreach to Key Owners at 30 days out, and calm, well-evidenced escalation when a response doesn't come.
Product / platform knowledge
Venafi/ Cyberark Certificate Mgmt โcertificate inventory (Inventory โ Certificates)
Cyberark Vault and API integrationโ awareness of vailt setup, configuration and rotation/renewal actions via vault API integration to discovery tool.
ServiceNow (Nice to have) โCMDB structuring and the renewal-ticket queue workflow; candidate system of record for key/certificate governance evidence.
DigiCert โthe public certificate authority behind Venafi issuance; awareness of the yearly public-certificate subscription model.
Oasis Security (Nice to have)โ discovery, ownership attribution, lifecycle management and automated secret rotation via a vault (HashiCorp Vault, Azure Key Vault or CyberArk);
IBM Sterling File Gateway with Secure Proxy โawareness of the SFTP/PGP onboarding process for third-party file transfer, since PGP key material (the audit-scope exposure) is tracked through the Sterling onboarding form rather than Venafi or Oasis.
Senior Security Engineer ยท NR Consulting - India