This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Middleware Engineer based in Brazil.
This role focuses on securing and automating enterprise certificate and PKI operations across complex technology environments.
You will manage the full SSL/TLS certificate lifecycle, from generation and issuance through installation, renewal, and retirement.
The position combines hands-on infrastructure expertise with automation, security, and operational reliability.
You will help integrate certificate management into CI/CD pipelines, infrastructure-as-code workflows, and containerized platforms.
The role also involves troubleshooting production issues and supporting secure, highly available environments.
You will contribute to documentation, runbooks, audits, and knowledge sharing to strengthen operational maturity.
This is a remote opportunity for an experienced engineer who enjoys solving complex security and infrastructure challenges.
Accountabilities:
- Generate, provision, install, renew, and manage SSL/TLS certificates throughout their complete lifecycle.
- Manage certificate requests through issuance while ensuring secure key storage, credential handling, and accurate documentation.
- Proactively monitor certificate expiration dates and coordinate timely renewals to prevent service interruptions.
- Maintain certificate availability and support renewal activities with a strong focus on service continuity and uptime.
- Design and implement automated certificate management solutions that reduce manual intervention and operational errors.
- Automate certificate generation, deployment, installation, renewal, and related operational workflows using scripting and orchestration.
- Integrate certificate management processes with CI/CD pipelines and infrastructure-as-code environments.
- Support automated certificate operations across Kubernetes and Docker-based container environments.
- Administer and use Keyfactor Command for certificate discovery, lifecycle management, and renewal at scale.
- Maintain and operate PKI environments, including certificate authorities, certificate chains, and associated services.
- Perform routine CA maintenance, including database backups, CA certificate renewals, and CRL/AIA rollover planning.
- Support root and subordinate CA key ceremonies and related security procedures when required.
- Troubleshoot SSL/TLS and certificate-related incidents across development, operations, and security environments.
- Investigate and resolve Active Directory Certificate Services (ADCS) issues, including enrollment, permissions, autoenrollment, and SPN/Kerberos-related problems.
- Provide technical support and escalation handling for production certificate and PKI incidents.
- Ensure certificate management activities comply with organizational security policies and applicable industry standards.
- Conduct regular security reviews and maintain secure handling of certificate-related credentials and cryptographic keys.
- Create comprehensive technical documentation, operational runbooks, and training materials for certificate management procedures.
- Share knowledge and enable other team members to independently support certificate operations and best practices.
Requirements:
- 6+ years of hands-on experience in certificate management, PKI administration, or related security infrastructure roles.
- Strong understanding of SSL/TLS protocols and certificate formats including X.509, PEM, DER, and PKCS#12.
- Solid knowledge of PKI fundamentals, including certificate chains, RSA/ECC algorithms, CSR generation, CRL, AIA, OCSP, and key ceremonies.
- Experience working with commercial certificate authorities such as DigiCert, GlobalSign, or Sectigo.
- Experience with open-source certificate solutions such as Let's Encrypt and OpenSSL-based CAs.
- Advanced proficiency with certificate management and cryptographic tools including OpenSSL, keytool, certbot, and platform-specific utilities.
- Hands-on experience with Keyfactor Command or comparable certificate lifecycle management platforms.
- Experience administering and configuring Apache and Nginx web servers.
- Experience installing and managing certificates on application servers such as Tomcat, JBoss, and IIS.
- Strong Linux/Unix and Windows server administration skills, including command-line and system-level operations.
- Experience with infrastructure-as-code and automation frameworks such as Terraform, Ansible, Chef, or Puppet.
- Knowledge of monitoring and alerting platforms for certificate status tracking, expiration monitoring, and incident notifications.
- Practical experience with Active Directory Certificate Services, including enrollment, templates, autoenrollment, and related troubleshooting.
- Understanding of SPN/Kerberos concepts and troubleshooting of related issues, including WSMAN SPN problems affecting remote enrollment or orchestration.
- Strong troubleshooting and problem-solving abilities across infrastructure, security, and production environments.
- Excellent organizational and communication skills, with strong attention to detail.
- Ability to create clear technical documentation and explain complex infrastructure and security concepts effectively.
- Ability to work collaboratively across development, operations, and security teams.
Benefits:
- Remote work from Brazil.
- CLT employment with a 40-hour weekly workload.
- Health insurance through SulAmérica Prestige, including coverage options for legal dependents.
- Dental insurance through SulAmérica, including coverage options for legal dependents.
- Life insurance through Prudential equivalent to 24 times salary.
- Private pension plan through MetLife with up to 6% company matching.
- Monthly meal voucher and internet allowance through Flash totaling R$1,000.
- Employee Assistance Program.
- Wellness program.
- Base salary plus additional compensation programs depending on eligibility and individual performance.
- Potential equity grant through an Associate Equity Appreciation Program.
- Remote-first flexibility when client-site presence is not required.
- Commitment to diversity, inclusion, and equal employment opportunities.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1