Senior Middleware Engineer
Posted 21hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Middleware Engineer automating PKI and SSL/TLS certificate lifecycle management. Supporting Ensono’s managed technology services through secure infrastructure, compliance, and incident resolution.
Responsibilities:
- Generate and provision SSL/TLS certificates using industry-standard tools and certificate authorities, managing the complete request-to-issuance workflow while maintaining secure key storage and documentation.
- Monitor certificate expiration dates proactively and execute timely renewals to prevent service disruptions, maintaining 100% uptime during renewal processes.
- Design and implement automated certificate management solutions to streamline generation, installation, and renewal processes through scripting and orchestration.
- Integrate certificate management with CI/CD pipelines, infrastructure-as-code platforms, and Kubernetes and Docker environments.
- Ensure compliance with organizational security policies and industry standards, securely handling certificate-related credentials and keys and conducting regular security audits.
- Troubleshoot and resolve certificate-related issues across development, operations, and security environments, providing technical support and production incident escalation handling.
- Use Keyfactor Command (CLM) for automated certificate discovery, lifecycle management, and renewal at scale.
- Apply PKI fundamentals including certificate chains, RSA/ECC key algorithms, CSR generation, CRL/AIA/OCSP, and key ceremonies.
- Create documentation, runbooks, and training materials on certificate management procedures and best practices.
Requirements:
- 6+ years of hands-on experience in certificate management, PKI (Public Key Infrastructure) administration, or related security infrastructure roles.
- Strong technical knowledge of SSL/TLS protocols, certificate formats (X.509, PEM, DER, PKCS#12), and their implementation across various platforms and environments.
- Proficiency with certificate authorities including commercial CAs (DigiCert, GlobalSign, Sectigo) and open-source solutions (Let's Encrypt, OpenSSL-based CAs).
- Advanced proficiency with certificate management tools such as OpenSSL, keytool, certbot, and platform-specific certificate management utilities.
- Hands-on experience administering and configuring web servers (Apache, Nginx) and application servers (Tomcat, JBoss, IIS) with certificate installations.
- Demonstrated expertise in Linux/Unix and Windows server environments, including command-line administration and system-level operations.
- Experience with infrastructure-as-code and automation frameworks such as Terraform, Ansible, Chef, or Puppet for managing certificate deployments at scale.
- Knowledge of monitoring and alerting platforms to implement certificate status tracking, expiration monitoring, and incident notification systems.
- Perform routine CA maintenance: database backups, CA certificate renewal, CRL/AIA rollover planning, and root/subordinate CA key ceremonies as needed.
- Troubleshoot ADCS-related issues — enrollment failures, template permission issues, autoenrollment failures, SPN/Kerberos-related errors (e.g., WSMAN SPN issues for remote enrollment/orchestration).
- Excellent organizational, communication, and problem-solving abilities with strong attention to detail, ability to document procedures clearly, and communicate technical concepts effectively.
Benefits:
- CLT hiring - 40 hours weekly workload
- Work remotely
- Health Insurance - SulAmérica Prestige (available for legal dependents)
- Dental Insurance - SulAmérica (available for legal dependents)
- Life Insurance - Prudential (24x salary)
- Private Pension - Metlife (up to 6% of company match)
- Meal Voucher and Internet allowance - Flash (R$1.000,00 per month)
- Employee Assistance Program
- Wellness program
- Individual performance compensation program, depending on eligibility
- Equity grant under our Associate Equity Appreciation Program, depending on eligibility














