← Back to jobs
Bangalore, Karnataka, India
No related jobs found
Machine-identity discovery build support — extend the Phase 1–3 discovery effort to machine-identity assets (certificates and keys) against the defined, time-boxed scope of work, capturing the internal-vs-external classification ESS01 requires at the point of discovery (this determines the rotation cadence — 1 year external, 5 years internal).
CMDB population — populate ServiceNow (candidate CMDB system of record, Program Doc open item 7) with the resulting machine-identity asset inventory, in a structure the governance function can query, track and report from.
Tooling configuration — Work with SNOW team for configure tooling changes needed to support machine-identity assets across the build phases, including surfacing the existing Venafi Inventory → Certificates view as the discovery surface the program builds on rather than replaces.
Control-design support
Rekey-vs-renew enforcement — support configuration and process changes that make the rekey/renew distinction operational: Venafi renews against the same key material by default (ESS01 §2.1 requires the private and public key cryptoperiods to match), so tooling and workflow need an explicit control, not just a policy statement.
Key Owner / Custodian registry — support building the registry schema once Information Security rules on the open Key Holder definition (open item 2), so ownership data captured during discovery lands in a structure the standing function can register and monitor.
Skills & product knowledge
Core technical skills
PKI and cryptography fundamentals: X.509 certificates, PGP/GPG key pairs, certificate signing requests, cryptoperiods, approved key lengths and algorithms (ESS01 §1.0 sets a 2048-bit minimum).
Certificate lifecycle engineering: issuance, renewal, revocation and — distinctly — rotation/rekey, and why a renewal-only practice can leave decade-old key material behind a compliant-looking expiry dashboard.
CMDB and ITSM data modelling: configuration-item structuring, asset attribution and integration patterns for a system of record (ServiceNow), including API/REST-based data population.
Scripting and automation for discovery and tooling integration (e.g., Python, PowerShell, REST/API scripting against Venafi and ServiceNow).
Working knowledge of PGP/SSH key material and third-party file-transfer contexts (IBM Sterling File Gateway with Secure Proxy) is a plus, given the audit-scope exposure sits there.
Product / platform knowledge
Venafi/ Cyberark Certificate Mgmt — certificate inventory (Inventory → Certificates)
IBM Sterling File Gateway with Secure Proxy — awareness of the SFTP/PGP onboarding process for third-party file transfer, since PGP key material (the audit-scope exposure) is tracked through the Sterling onboarding form rather than Venafi or Oasis.
ServiceNow (Nice to have) — CMDB structuring and the renewal-ticket queue workflow; candidate system of record for key/certificate governance evidence.
DigiCert — the public certificate authority behind Venafi issuance; awareness of the yearly public-certificate subscription model.
Oasis Security (Nice to have) — discovery, ownership attribution, lifecycle management and automated secret rotation via a vault (HashiCorp Vault, Azure Key Vault or CyberArk);
CyberArk vault– awareness of vault setup, configuration and rotation/renewal actions via vault API integration to discovery tool
Any Gradute
No related jobs found
← Back to jobs