CLM Engineer

Location: Phoenix, AZ

Converge Resources

Certificate Lifecycle Management (CLM) Engineer

Enterprise Infrastructure & Performance

Assignment

Work Arrangement

Location

12-month contract; potential conversion

On-site Monday–Friday

Phoenix, Arizona

 

Position Overview

We are seeking a Certificate Lifecycle Management Engineer to support the digital certificates and machine identities used across enterprise network, security, application, and cloud environments. This engineer will administer the certificate lifecycle platform, improve automation, and reduce the risk of service interruptions caused by expired, misconfigured, or untrusted certificates.

The ideal candidate has hands-on experience with an enterprise CLM or PKI platform, understands how certificates function within network infrastructure, and can partner with security, application, and infrastructure teams in a controlled, audit-focused environment.

Key Responsibilities

Administer the enterprise certificate lifecycle platform and support issuance, installation, renewal, rotation, revocation, and retirement workflows.

Monitor PKI health, including root and intermediate certificate authorities, templates, trust relationships, and certificate chains.

Expand automated certificate discovery, inventory, expiration alerting, and renewal to prevent avoidable service interruptions.

Integrate certificate automation with load balancers, firewalls, web servers, Cisco network devices, and other infrastructure components.

Onboard applications and systems into the CLM platform in partnership with network, security, infrastructure, and application owners.

Troubleshoot certificate-related trust, encryption, connectivity, and application-access failures.

Support hardware security module activities associated with secure key storage and certificate signing when applicable.

Maintain runbooks, operating procedures, control evidence, and audit-ready documentation.

Participate in incident response and root-cause analysis for PKI-related outages or security events.

Recommend improvements to certificate governance, key-management practices, platform health, and automation coverage.

Required Qualifications

Hands-on administration experience with Venafi, Keyfactor/EJBCA, AppViewX, DigiCert CertCentral, Sectigo, or a comparable CLM/PKI platform.

Working knowledge of certificate authorities, trust chains, public/private key pairs, certificate-signing requests, and revocation methods such as CRL and OCSP.

Understanding of TLS/SSL and the ways certificate problems can affect applications, devices, and network connectivity.

Core networking knowledge, including TCP/IP, DNS, load balancers, firewalls, and enterprise network architecture; Cisco experience is preferred.

Experience using PowerShell, Python, or another scripting language for automation, reporting, or systems integration.

Ability to create accurate technical documentation and communicate effectively with cross-functional teams.

Experience working within formal change, incident, security, or audit-control processes.

Preferred Qualifications

Banking, financial services, or other regulated-industry experience.

Knowledge of security and compliance frameworks relevant to regulated enterprises, such as PCI DSS, SOX, or FFIEC guidance.

Experience with Thales Luna or another hardware security module.

Exposure to Azure Key Vault, AWS Certificate Manager, or other cloud certificate and secrets-management services.

Familiarity with ServiceNow or a comparable IT service-management platform.

Security+, CISSP, or relevant CLM/PKI platform certification.

Assignment Details

This is a 12-month contract assignment with the possibility of conversion to a permanent position. The role requires on-site work in Phoenix, Arizona, Monday through Friday. Conversion is not guaranteed and will depend on business needs, performance, and position availability.

Back to Jobs

  • Max. file size: 100 MB.
Share this job Posting: