
Senior Security Engineer - Certificate Automation Engineer
Truist Financial Corporation1 month ago
Richmond, VA, USA +3 moreSenior
Base Salary
$120k - $160k/yr
Responsibilities
- Design and implement automation for certificate installation, deployment, binding, and validation across enterprise platforms.
- Extend certificate issuance and renewal automation into end-to-end lifecycle automation, emphasizing last-mile deployment.
- Develop and maintain automation frameworks using Ansible, APIs, and scripting.
- Integrate certificate automation with F5 load balancers, IIS, Apache, NGINX, application servers, database servers, and middleware.
- Onboard systems to automated certificate deployment and establish standardized deployment patterns.
- Implement pre- and post-installation validation to verify certificates are correctly deployed, trusted, and serving traffic.
- Identify and remediate certificate deployment gaps that cause outages, failed renewals, or misconfigurations.
- Troubleshoot certificate-related incidents and perform root cause analysis to eliminate recurring issues.
- Collaborate with technical and business teams to align automation with operational requirements and risk objectives.
- Contribute to certificate lifecycle, crypto-agility, and quantum-safe readiness initiatives.
- Provide technical leadership and lead or contribute to moderately to highly complex projects delivering scalable and resilient solutions.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- At least 7 years of experience in security engineering or related cybersecurity roles.
- Deep knowledge of cybersecurity principles, theories, concepts, threat modeling, security testing, and penetration testing.
- Experience with software development lifecycle security practices and complex information security technologies.
- Knowledge of enterprise security technologies including encryption, PKI, certificate authorities, identity management, and network security.
- Hands-on experience with certificate lifecycle management, especially certificate deployment and installation across infrastructure platforms.
- Experience developing automation with scripting or automation tools such as Ansible, Python, and APIs.
- Experience with enterprise systems including servers, load balancers, web servers, application servers, and middleware.
- Experience with Venafi or similar enterprise PKI platforms and ServiceNow or similar workflow/orchestration platforms.
- Familiarity with ACME protocols, API-driven certificate deployment, DevOps, and CI/CD pipelines as they relate to certificate deployment.
- Experience in large, complex enterprise environments, preferably financial services or other highly regulated industries.
- Understanding of crypto agility, shortened certificate lifecycles, and quantum-safe cryptography initiatives.
- Strong analytical, troubleshooting, communication, and cross-functional collaboration skills.
- Relevant certifications such as CISSP, GIAC, or cloud/security certifications are preferred.
Benefits
- Medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401(k) plan for eligible regular teammates working 20 or more hours per week.
- At least 10 days of vacation, 10 sick days, and paid holidays during the first year, prorated as applicable.
- Depending on position and division, eligibility may include a defined benefit pension plan, restricted stock units, and deferred compensation plan.
- Regular, non-temporary employment on the first shift in the United States; English fluency is required.