freehire launches on Product Hunt on 26 August.

Follow →

Information Security Engineer III- Eng (DigiCert, PKI & Secrets Management)

Summary

Design and maintain enterprise PKI and secrets management using DigiCert, Google Secret Manager, and HashiCorp Vault to secure cloud and on-prem workloads.

UKG is seeking an experienced Information Security Engineer III to join the Identity & Access Management (IAM) team. This role is responsible for designing, implementing, and supporting enterprise Public Key Infrastructure (PKI) and secrets management solutions that secure applications, infrastructure, and cloud workloads.

The ideal candidate will have hands-on experience with DigiCert PKI, Certificate Lifecycle Management (CLM), Google Secret Manager, and HashiCorp Vault, along with a strong understanding of cryptography, certificate management, and cloud security. You will work closely with Infrastructure, Cloud Engineering, DevOps, Security, and Application teams to automate certificate and secrets management while ensuring secure, scalable, and compliant operations.

Key Responsibilities

  • Design, implement, administer, and optimize enterprise PKI solutions using DigiCert.
  • Manage the complete certificate lifecycle, including certificate issuance, renewal, revocation, discovery, and automated deployment through Certificate Lifecycle Management (CLM).
  • Administer and support Google Secret Manager and HashiCorp Vault for secure storage, rotation, and access to secrets, certificates, and encryption keys.
  • Collaborate with application, infrastructure, and DevOps teams to integrate PKI, certificate automation, and secrets management into enterprise platforms and CI/CD pipelines.
  • Implement automation for certificate provisioning, renewal, and secret rotation using APIs, scripting, and infrastructure-as-code practices.
  • Monitor PKI infrastructure and certificate health to ensure service availability and compliance.
  • Troubleshoot certificate, TLS/SSL, secrets management, and authentication issues across cloud and on-premises environments.
  • Develop operational documentation, runbooks, and standard operating procedures.
  • Support security audits, regulatory compliance, and vulnerability remediation related to certificates, cryptographic assets, and secrets management.
  • Stay current with emerging technologies and security best practices related to PKI, cryptography, and cloud-native security.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 5–9 years of experience in Information Security, IAM, Infrastructure Security, or Cloud Security Engineering.
  • Hands-on experience administering DigiCert PKI and Certificate Lifecycle Management (CLM) solutions.
  • Experience managing enterprise TLS/SSL certificates, code-signing certificates, client certificates, and certificate automation.
  • Experience with Google Secret Manager and HashiCorp Vault for enterprise secrets management.
  • Strong understanding of PKI concepts, X.509 certificates, Certificate Authorities (CA), cryptographic key management, TLS/SSL, CSR generation, OCSP, and CRL.
  • Experience integrating PKI and secrets management solutions with enterprise applications and cloud platforms.
  • Experience with automation using REST APIs, PowerShell, Python, or Shell scripting.
  • Experience with Google Cloud Platform (GCP); exposure to AWS or Azure is a plus.
  • Strong analytical, troubleshooting, and problem-solving skills.

Preferred Qualifications

  • Experience integrating PKI and secrets management into Kubernetes, containers, and CI/CD platforms.
  • Familiarity with Infrastructure as Code tools such as Terraform.
  • Knowledge of identity and access management concepts, including authentication, authorization, and Zero Trust architecture.
  • Experience supporting compliance frameworks such as SOC 2, ISO 27001, PCI DSS, or SOX.
  • Relevant certifications such as DigiCert, HashiCorp Vault Associate, Google Cloud Security, Security+, or CISSP are desirable.

Technical Skills

  • DigiCert PKI Platform
  • Certificate Lifecycle Management (CLM)
  • Google Secret Manager
  • HashiCorp Vault
  • Public Key Infrastructure (PKI)
  • TLS/SSL & X.509 Certificates
  • Certificate Authorities (CA)
  • Key & Certificate Management
  • REST APIs
  • PowerShell, Python, or Shell Scripting
  • Google Cloud Platform (GCP)
  • Terraform (preferred)
  • Kubernetes (preferred)
  • DevSecOps & CI/CD Integration

Why UKG

At UKG, our purpose is people. As part of the Identity & Access Management team, you'll help secure the technologies that protect our global workforce and customers. You'll work alongside talented engineers on enterprise-scale security initiatives, leverage modern cloud and automation technologies, and contribute to building resilient, secure, and scalable identity and infrastructure services.

See also