Role : SEC Certificate Management
Exp : 6+ years
Location : Pune, Mumbai, Bangalore, Chennai, Hyderabad, Noida
Mode : Hybrid
Mandatory Skills : MS PKI for Certificate Management
Good to Have Skills : Application Security (application security framework/ threat modelling/ Secure SDLC/ DevSecOps/Application Security Architecture Review)
Job Summary :
A critical high priority project is underway to completely overhaul how certificates are managed across the organization globally. This includes all types of certificates such as SSL/TLS certificates, code signing certificates, client authentication certificates, email encryption certificates, and device certificates. The objective is to establish a centralized Certificate Management Office (CMO) that provides enterprise-wide governance standards and lifecycle oversight for certificate management through dedicated role owners supported by a structured committee framework.
We are seeking three highly skilled Business Analysts with deep expertise in certificate management, strong technical writing skills, and a solid understanding of operating within a complex global organization. These BAs will work closely with internal stakeholders and external experts to define the CMO structure, roles, and the optimal approach to certificate management for an organization of significant size and complexity.
Key Responsibilities :
- Collaborate with project leadership, senior IT leadership, and external experts to define the Certificate Management Office (CMO) framework including structure, roles, responsibilities, and governance models.
- Analyze and document current certificate types, ownership, and management practices across all certificate types and Marsh global business units.
- Understand and document the complexities of managing certificates in a large global matrixed organization with diverse technology environments.
- Identify gaps, risks, and opportunities for improvement in certificate management infrastructure design and processes.
- Develop detailed business requirements, process flows, and technical documentation related to certificate management aligned with enterprise governance.
- Facilitate workshops, interviews, and governance council meetings with cross-functional stakeholders to gather and validate requirements.
- Support the design and implementation of the new CMO and new certificate management solutions, policies, and governance models that align with standards such as NIST and CA/Browser Forum.
- Produce clear, comprehensive, and high-quality technical and business documentation including policy translation into technical standards and operational procedures.
- Ensure alignment of certificate management practices with security policies, compliance requirements, and operational standards.
- Provide expert advice on certificate lifecycle management, security considerations, operational best practices, and automation strategies.
- Assist in defining and documenting roles for the new CMO and support executive reporting on risk, outages, and compliance posture related to certificate management.
Qualifications :
- Proven experience as a Business Analyst with a focus on certificate management or related IT security infrastructure.
- Deep knowledge of all types of certificates (e.g., SSL/TLS, code signing, client authentication, email encryption, device certificates) and their security and operational considerations.
- Solid understanding of certificate lifecycle management including issuance, renewal, revocation, and monitoring.
- Experience with certificate management tools, platforms, and automation technologies (e.g., Venafi, HashiCorp Vault, ACME protocols).
- Excellent technical writing skills with the ability to produce clear, detailed, and structured documentation.
- Demonstrated ability to work effectively in a complex global matrixed organization with multiple stakeholders and governance layers.
- Experience in large-scale IT security or infrastructure projects, preferably in global enterprises.
- Familiarity with industry standards and frameworks such as NIST, CA/Browser Forum, and enterprise GRC (Governance, Risk, and Compliance).
- Solid analytical, problem-solving, and communication skills.
- Ability to innovate, think big, and challenge the status quo of things.
- Relevant certifications in business analysis, cybersecurity, or IT management are a plus.
(ref:hirist.tech)