Corporate Vice President - Enterprise PKI & Cryptographic Engineering

New York Life - New York, United States

Hiring: Corporate Vice President - Enterprise PKI & Cryptographic Engineering Company: New York Life Location: New York, United States Job Posted Time: 2026-09-03 11:15:48 Employment Type: Hybrid Target Skills & Keywords : AWS, Azure, CI/CD, GCP, Kubernetes, PKI, PowerShell, Python, REST, ServiceNow, TLS, Vault About the job Experience: •8+ years of progressive, hands-on experience in PKI, cryptographic engineering, identity engineering, or security engineering, with significant responsibility for enterprise PKI environments. Required Skills: •Design, engineer, and modernize enterprise PKI services and trust hierarchies — offline root CAs, issuing/subordinate CAs, and cloud-native issuance — spanning users, applications, devices, workloads, APIs, and non-human identities. •Engineer and administer Microsoft AD CS, including CA configuration, certificate templates, auto-enrollment, trust chains, CRLs, OCSP, and recovery capabilities. •Own Certificate Lifecycle Management (CLM): drive discovery, inventory, issuance, renewal, revocation, and reporting from fragmented manual processes toward centralized, policy-driven automation. •Build automation and reusable, self-service certificate APIs using ACME, SCEP, EST, REST, PowerShell, and Python; integrate with ServiceNow, CI/CD, Kubernetes, and DevOps tooling. •Engineer HSM/KMS backed CA and signing services, including key ceremonies, backup, rotation, access control, and disaster recovery, across on-prem and cloud (AWS, Azure, GCP). •Serve as the PKI and cryptographic engineering subject-matter expert for the Security Review Board and Architecture Review Board, and provide authoritative technical risk recommendations on IS Exception requests. •Maintain strong knowledge of Active Directory and Microsoft Entra ID where they intersect with certificate services, certificate-based authentication, device identity, Conditional Access, and Privileged Identity Management. •Maintain the enterprise cryptographic inventory and drive cryptographic agility, short-lived certificates, and post-quantum migration readiness. Qualifications: •Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or equivalent practical experience. •Deep hands-on experience engineering or operating enterprise certificate authority environments, including Microsoft AD CS, certificate templates, trust chains, CRLs, and OCSP. •In-depth knowledge of X.509, TLS/mTLS, certificate enrollment, revocation, trust models, and cryptographic key management. •Strong knowledge of Active Directory and Microsoft Entra ID, particularly where they intersect with PKI, certificate-based authentication, device identity, or non-human identity. •Demonstrated capacity to conduct deep technical security reviews, identify material PKI and cryptographic risks, and define practical remediation or compensating controls. •Strong communication skills, with the ability to explain complex PKI and cryptographic risk to engineers, architects, governance bodies, auditors, vendors, and senior leaders. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!