01Overview
Job description
Company and benefits
Job ID
INFOR019310
Employment Type
Regular
Work Style
hybrid
Location
Noida,UP,India
Role
Information Security Engineer III- Eng (DigiCert, Digital Certificate, PKI)
Why UKG:
At UKG, the work you do matters. The code you ship, the decisions you make, and the care you show a customer all add up to real impact. Today, tens of millions of workers start and end their days with our workforce operating platform. Helping people get paid, grow in their careers, and shape the future of their industries. Thats what we do.
We never stop learning. We never stop challenging the norm. We push for better, and we celebrate the wins along the way. Here, youll get flexibility thats real, benefits you can count on, and a team that succeeds together. Because at UKG, your work mattersand so do you.
About the Role
UKG is seeking an experienced Information Security Engineer III to join the Identity & Access Management (IAM) team. This role is responsible for designing, implementing, and supporting enterprise Public Key Infrastructure (PKI) and secrets management solutions that secure applications, infrastructure, and cloud workloads.
The ideal candidate will have hands-on experience with DigiCert PKI, Certificate Lifecycle Management (CLM), Google Secret Manager, and HashiCorp Vault, along with a strong understanding of cryptography, certificate management, and cloud security. You will work closely with Infrastructure, Cloud Engineering, DevOps, Security, and Application teams to automate certificate and secrets management while ensuring secure, scalable, and compliant operations.
Key Responsibilities
Design, implement, administer, and optimize enterprise PKI solutions using DigiCert.
Manage the complete certificate lifecycle, including certificate issuance, renewal, revocation, discovery, and automated deployment through Certificate Lifecycle Management (CLM).
Administer and support Google Secret Manager and HashiCorp Vault for secure storage, rotation, and access to secrets, certificates, and encryption keys.
Collaborate with application, infrastructure, and DevOps teams to integrate PKI, certificate automation, and secrets management into enterprise platforms and CI/CD pipelines.
Implement automation for certificate provisioning, renewal, and secret rotation using APIs, scripting, and infrastructure-as-code practices.
Monitor PKI infrastructure and certificate health to ensure service availability and compliance.
Troubleshoot certificate, TLS/SSL, secrets management, and authentication issues across cloud and on-premises environments.
Develop operational documentation, runbooks, and standard operating procedures.
Support security audits, regulatory compliance, and vulnerability remediation related to certificates, cryptographic assets, and secrets management.
Stay current with emerging technologies and security best practices related to PKI, cryptography, and cloud-native security.
Required Qualifications
Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.
59 years of experience in Information Security, IAM, Infrastructure Security, or Cloud Security Engineering.
Hands-on experience administering DigiCert PKI and Certificate Lifecycle Management (CLM) solutions.
Experience managing enterprise TLS/SSL certificates, code-signing certificates, client certificates, and certificate automation.
Experience with Google Secret Manager and HashiCorp Vault for enterprise secrets management.
Strong understanding of PKI concepts, X.509 certificates, Certificate Authorities (CA), cryptographic key management, TLS/SSL, CSR generation, OCSP, and CRL.
Experience integrating PKI and secrets management solutions with enterprise applications and cloud platforms.
Experience with automation using REST APIs, PowerShell, Python, or Shell scripting.
Experience with Google Cloud Platform (GCP); exposure to AWS or Azure is a plus.
Strong analytical, troubleshooting, and problem-solving skills.
Preferred Qualifications
Experience integrating PKI and secrets management into Kubernetes, containers, and CI/CD platforms.
Familiarity with .