Remote job
Senior Middleware Engineer
Job details
About this role
Role overview A senior engineering position focused on Public Key Infrastructure (PKI) and certificate lifecycle management within a managed services environment. The role centers on automating SSL/TLS certificate operations at scale and integrating those workflows with modern delivery pipelines and infrastructure platforms. It is based remotely in Brazil.
Responsibilities - Generate, request, and provision SSL/TLS certificates through commercial and open-source certificate authorities, managing the full request-to-issuance workflow with secure key handling. - Monitor certificate expiration and execute timely renewals to prevent service disruptions across production environments. - Design and implement automation for certificate generation, installation, and renewal, using scripting and orchestration tooling to reduce manual effort. - Integrate certificate management with CI/CD pipelines, infrastructure-as-code platforms, and container orchestration systems including Kubernetes and Docker. - Maintain compliance with security policies and industry standards, including secure handling of keys, credentials, and audit documentation. - Troubleshoot certificate-related incidents across development, operations, and security environments, including ADCS enrollment issues and web/application server certificate problems. - Maintain CA infrastructure, including database backups, CA certificate renewal, CRL/AIA rollover planning, and key ceremonies. - Produce documentation, runbooks, and training material that enable broader teams to operate certificate processes independently.
Requirements - 6+ years of hands-on experience in certificate management, PKI administration, or related security infrastructure roles. - Strong knowledge of SSL/TLS protocols, certificate formats (X.509, PEM, DER, PKCS#12), and PKI fundamentals including certificate chains, RSA/ECC algorithms, CSR generation, CRL/AIA/OCSP, and key ceremonies. - Proficiency with commercial CAs (such as DigiCert, GlobalSign, Sectigo) and open-source options such as Let's Encrypt and OpenSSL-based CAs. - Advanced use of certificate management tooling including OpenSSL, keytool, certbot, and Keyfactor Command for enterprise CLM. - Experience administering web servers (Apache, Nginx) and application servers (Tomcat, JBoss, IIS) with certificate installations. - Strong command of Linux/Unix and Windows server administration, plus infrastructure-as-code frameworks such as Terraform, Ansible, Chef, or Puppet. - Familiarity with monitoring and alerting platforms for expiration tracking and incident notification.
Benefits and work setup Remote work in Brazil under a 40-hour weekly workload. Benefits include health and dental insurance for legal dependents, life insurance, private pension with company match, meal and internet allowance, an employee assistance program, and a wellness program. Additional compensation may include performance-based awards and an equity appreciation program.