GRM Technologies logo

Assistant Manager - PKI Architect & Administrator – Keyfactor Command + HSM (PKI / CLM)

GRM Technologies

Saudi ArabiaFull-timePosted Oct 6, 2026

Job description

Greetings from GRM Technologies!!! Location : GCC (Onsite) Employment Typ e : Full-time Role Summary We are seeking a PKI Architect & Administrator to design, implement, operate, and continuously improve our enterprise PKI and Certificate Lifecycle Management (CLM) capability using Keyfactor Command , with strong hands-on ownership of HSM-backed key management .

The role is responsible for end-to-end PKI architecture , CA operations , certificate automation , HSM administration , integrations , policy enforcement , and security/compliance alignment across on-prem and hybrid environments.

Key Responsibilities

PKI Architecture & Engineering Define and maintain enterprise PKI architecture (Root CA / Issuing CA hierarchy, trust models, certificate profiles, templates, issuance policies, and trust distribution). Design PKI to support TLS/SSL , mutual TLS , device identity, application identity, and service-to-service authentication.

Establish certificate governance standards (naming, algorithms, key sizes, validity, renewal/rotation, revocation strategy via CRL/OCSP). Provide technical leadership for PKI modernization, automation, scalability, and high availability. Keyfactor Command Administration & CLM Install, configure, and administer Keyfactor Command , including: Certificate discovery, inventory, issuance workflows, approvals, and policy enforcement RBAC, identity integrations, and segmentation Alerts, reporting, dashboards, renewal/expiry management and remediation tracking Implement certificate automation using Keyfactor capabilities (agents/connectors/APIs) to reduce manual issuance and renewals.

Integrate Keyfactor with Microsoft AD CS , web servers, load balancers/ADCs, Kubernetes/Ingress, cloud services, and enterprise applications as applicable. HSM Administration & Key Management Administer and operate Hardware Security Modules (HSMs) used for CA private key protection and enterprise key management (e.g., Utimaco, Thales, Entrust, Safenet/Gemalto ).

Perform and document key lifecycle operations : key generation, key import/export (where permitted), backup/restore, rotation, and secure destruction aligned to policy. Execute/support key ceremonies for Root/Issuing CAs using M-of-N / quorum controls , including witness procedures, audit trails, and evidence packs. Configure and maintain HSM partitions/slots , security domains, users/roles, quorum policies, and privileged access controls.

Integrate HSMs with CA platforms (e.g., AD CS) and Keyfactor components; troubleshoot PKCS#11 , CNG/KSP , provider, and crypto-stack integration issues. Ensure HA/DR readiness for HSM-backed CA services, including periodic recovery testing and documentation. Monitor HSM health/capacity (sessions, utilization, firmware status), manage firmware updates/patching via change control, and coordinate vendor support.

PKI Operations & Lifecycle Management Execute daily PKI operations: issuance, renewal, revocation, incident response for certificate issues, and service restoration. Troubleshoot certificate-related outages (chain/trust failures, mTLS failures, SNI/ciphers, OCSP/CRL distribution, intermediate trust issues). Maintain and test backup/restore and DR runbooks for Keyfactor + CA + HSM components.

Drive certificate hygiene: eliminate unknown certificates, remediate weak crypto, enforce rotation, reduce “shadow PKI”. Security, Compliance, and Governance Maintain and improve PKI documentation: CP/CPS , SOPs, HLD/LLD, runbooks, standards, and operational evidence. Ensure alignment with applicable requirements (as relevant): ISO 27001 , PCI DSS , internal security baselines, and crypto governance standards.

Support internal/external audits with evidence, reports, system logs, key ceremony records, and policy mappings. Monitoring, Reporting, and Continuous Improvement Implement monitoring and alerting for Keyfactor, CA services, OCSP/CRL endpoints, HSM health, and certificate expirations. Produce operational and compliance reports: certificate inventory, expiring certificates, issuance trends, exceptions, SLA/KPI metrics.

Identify and deliver automation enhancements and process improvements across PKI/CLM operations.

Required Skills

& Experience 8+ years in enterprise PKI engineering/administration, including CA operations and certificate lifecycle management. Hands-on administration of Keyfactor Command (preferred) or comparable CLM platforms with equivalent responsibilities. Strong technical knowledge of: X.509, certificate chains, trust stores, CSR workflows TLS/SSL, mTLS , cipher suites, SNI, OCSP/CRL concepts Cryptography fundamentals: RSA/ECC, key sizes, hashing algorithms, secure key handling Strong experience with HSM administration in PKI environments, including PKCS#11 , CNG/KSP , and vendor client/tooling.

Experience integrating PKI/CLM with: Microsoft AD CS and Windows PKI components Linux and Windows platforms; IIS/Apache/Nginx Load balancers/ADCs (e.g., F5, Citrix, NGINX, HAProxy) (any of these) Kubernetes/containers and/or cloud certificate services (beneficial) Automation and scripting: Power. Shell , Python , REST APIs (Keyfactor API experience preferred).

Strong troubleshooting skills across network, systems, and application stacks for certificate and crypto issues. Solid understanding of operational controls: dual control , separation of duties , privileged access, change management.

Preferred Qualifications

(Nice to Have) Keyfactor training/certification. HSM vendor training/certification (e.g., Utimaco/Thales ). Experience in FIPS 140-2/140-3 aligned environments and audit evidence preparation for cryptographic controls. Security certifications (any): CISSP, CISM, GSEC, Azure/AWS security, etc. DevOps/GitOps exposure for certificate management in CI/CD pipelines.

Education

Bachelor’s degree in Computer Science / IT / Cybersecurity or equivalent practical experience.

More jobs at GRM Technologies

See all openings at GRM Technologies