KPMG US
Senior Specialist, Identity and Access Management, PKI Engineer
KPMG US, Cincinnati, Ohio, United States, 45208
Overview
KPMG Advisory practice is currently our fastest growing practice. We are seeing tremendous client demand, and we do not anticipate that slowing down. We emphasize adaptability, collaboration, and ongoing learning. KPMG offers opportunities for professional growth, training facilities, and access to market tools to help you advance your career in Advisory. KPMG is seeking a Senior Specialist, Identity and Access Management, PKI Engineer to join our Managed Services practice. Responsibilities
Design, deploy, and manage highly available PKI solutions, ensuring secure and resilient operations across the organization and integration of PKI with enterprise applications and systems for secure communications and data protection. Utilize and manage PKI tools such as Microsoft Active Directory Certificate Services, OpenSSL, HashiCorp Vault, and AWS Certificate Manager for key management and distribution; configure, deploy, and manage Hardware Security Modules (HSMs) to enhance key storage and operations. Develop and implement strategies for key lifecycle management (creation, distribution, rotation, renewal, revocation) and integrate PKI with Registration Authorities (RA) and Certificate Authorities (CA) to streamline issuance and management. Define target state architecture and operating models for PKI infrastructure; collaborate with cross-functional teams to support cryptographic protocols and security initiatives. Monitor PKI infrastructure for security threats and vulnerabilities; conduct regular assessments and audits to ensure compliance with industry standards; troubleshoot PKI-related issues with escalation and SLA adherence. Document PKI architecture, processes, procedures, and strategic approaches; create and maintain client knowledge articles, SOPs, architecture and scripts to ensure smooth operations and enable continuous improvement and maintenance of IAM solutions. Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment. Qualifications
Minimum three years of recent experience deploying and managing highly available PKI solutions, including tools such as Microsoft AD Certificate Services, OpenSSL, HashiCorp Vault, and AWS Certificate Manager. Bachelor's degree in Computer Science, Engineering, Information Security, or a related field from an accredited institution. Proven ability to define target state architecture and operating models for PKI infrastructure and integrate PKI solutions with enterprise applications and systems. Strong understanding of key lifecycle management processes (creation, distribution, rotation, renewal, revocation) and familiarity with Hardware Security Modules (HSMs) and RA/CA integration. Experience with programming languages such as Java, Python, or C++; familiarity with cloud-based PKI solutions and their integration. Experience in secure environments with compliance standards (e.g., NIST, ISO 27001); knowledge of network security concepts and secure communication protocols. Ability to travel as needed. Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. No visa sponsorship (H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT) is available for this opportunity. EEO Statement:
KPMG LLP and its affiliates and subsidiaries comply with all applicable federal, state, and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, citizenship status, disability, or veteran status. Additional information
Seniority level: Mid-Senior level Employment type: Full-time Job function: General Business #J-18808-Ljbffr
KPMG Advisory practice is currently our fastest growing practice. We are seeing tremendous client demand, and we do not anticipate that slowing down. We emphasize adaptability, collaboration, and ongoing learning. KPMG offers opportunities for professional growth, training facilities, and access to market tools to help you advance your career in Advisory. KPMG is seeking a Senior Specialist, Identity and Access Management, PKI Engineer to join our Managed Services practice. Responsibilities
Design, deploy, and manage highly available PKI solutions, ensuring secure and resilient operations across the organization and integration of PKI with enterprise applications and systems for secure communications and data protection. Utilize and manage PKI tools such as Microsoft Active Directory Certificate Services, OpenSSL, HashiCorp Vault, and AWS Certificate Manager for key management and distribution; configure, deploy, and manage Hardware Security Modules (HSMs) to enhance key storage and operations. Develop and implement strategies for key lifecycle management (creation, distribution, rotation, renewal, revocation) and integrate PKI with Registration Authorities (RA) and Certificate Authorities (CA) to streamline issuance and management. Define target state architecture and operating models for PKI infrastructure; collaborate with cross-functional teams to support cryptographic protocols and security initiatives. Monitor PKI infrastructure for security threats and vulnerabilities; conduct regular assessments and audits to ensure compliance with industry standards; troubleshoot PKI-related issues with escalation and SLA adherence. Document PKI architecture, processes, procedures, and strategic approaches; create and maintain client knowledge articles, SOPs, architecture and scripts to ensure smooth operations and enable continuous improvement and maintenance of IAM solutions. Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment. Qualifications
Minimum three years of recent experience deploying and managing highly available PKI solutions, including tools such as Microsoft AD Certificate Services, OpenSSL, HashiCorp Vault, and AWS Certificate Manager. Bachelor's degree in Computer Science, Engineering, Information Security, or a related field from an accredited institution. Proven ability to define target state architecture and operating models for PKI infrastructure and integrate PKI solutions with enterprise applications and systems. Strong understanding of key lifecycle management processes (creation, distribution, rotation, renewal, revocation) and familiarity with Hardware Security Modules (HSMs) and RA/CA integration. Experience with programming languages such as Java, Python, or C++; familiarity with cloud-based PKI solutions and their integration. Experience in secure environments with compliance standards (e.g., NIST, ISO 27001); knowledge of network security concepts and secure communication protocols. Ability to travel as needed. Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. No visa sponsorship (H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT) is available for this opportunity. EEO Statement:
KPMG LLP and its affiliates and subsidiaries comply with all applicable federal, state, and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, citizenship status, disability, or veteran status. Additional information
Seniority level: Mid-Senior level Employment type: Full-time Job function: General Business #J-18808-Ljbffr