A contractor on the Platforms team, you will be responsible for core enterprise Windows infrastructure, with a defined specialization in certificate lifecycle automation and machine identity management. This role will lead the buildout and expansion of certificate automation capability across additional environments, working closely with the existing PKI/AD CS infrastructure rather than replacing it. You will help define the standards, integration patterns, and operational processes the team uses for certificate lifecycle management going forward, including discovery, automated renewal, and policy-based governance across servers, applications, and network devices. Outside of the certificate automation work, your core responsibilities mirror those of a senior Windows administrator: Active Directory, Group Policy, DNS/DHCP, Windows Server administration, and STIG compliance. You will also maintain baseline familiarity with CyberArk Privileged Access Management to assist the team’s PAM lead when needed, though CyberArk is not your primary ownership area. As a senior team member, you are expected to document your work thoroughly, particularly the certificate automation buildout, since this documentation will help establish a repeatable reference for how certificate automation is run across the enterprise. This also includes:
• Certificate Automation Platform Administration: Lead the buildout and expansion of the enterprise certificate lifecycle automation platform, including certificate discovery, monitoring, automated renewal, and revocation across servers, applications, and network devices.
• Certificate Lifecycle Management: Manage the full certificate lifecycle including issuance, renewal, revocation, and expiration tracking, applying policy-based governance to reduce certificate-related outages and unmanaged machine identities.
• CA Integration: Integrate the certificate automation platform with internal and external Certificate Authorities, primarily Microsoft AD CS, ensuring proper alignment with the existing Root CA/Intermediate CA hierarchy, CRL distribution, and OCSP responder configuration.
• Automation and Scripting: Develop PowerShell and, where applicable, Python or REST API-based automation to streamline certificate provisioning, renewal workflows, and reporting.
• Active Directory Management: Administer and support Active Directory services including user accounts, security groups, Group Policy, and security configurations across a multi-site enterprise environment.
• DNS/DHCP Administration: Administer and troubleshoot AD-integrated DNS and DHCP services as part of broader enterprise infrastructure support.
• Windows Server Administration: Install, configure, and maintain Windows Server environments, ensuring optimal performance, reliability, and STIG compliance.
• System Security and Compliance: Ensure security of Windows and certificate infrastructure through STIG remediation, patch management, ACAS vulnerability remediation, and alignment with DISA security baselines.
• Documentation and Standards Development: Produce comprehensive documentation for the certificate automation buildout, including architecture decisions, integration points, and operational runbooks, submitted through GitLab for peer review. This documentation will help establish a standard reference for the platform going forward.
• CyberArk Awareness: Maintain baseline familiarity with CyberArk PAM operations, including vault structure and credential management concepts, sufficient to provide backup assistance when the team’s CyberArk lead requires coverage.
• Monitoring and Troubleshooting: Proactively monitor certificate infrastructure and Windows platform health, identify issues, and perform troubleshooting to ensure system stability and prevent certificate-related outages.
•Collaboration: Work closely with the PKI lead, CyberArk lead, cybersecurity, and architecture teams to ensure the certificate automation work aligns with broader identity and security architecture.