
Senior Middleware Engineer
Posted Sep 16

Posted Sep 16
This is a fully remote position, open to applicants in Brazil.
• Generate and provision SSL/TLS certificates utilizing industry-standard tools and certificate authorities, overseeing the entire request-to-issuance workflow while ensuring secure key storage and thorough documentation.
• Proactively monitor certificate expiration dates and execute timely renewals to avoid service interruptions, achieving 100% uptime throughout the renewal process.
• Design and implement automated solutions for certificate management to optimize generation, installation, and renewal processes through scripting and orchestration.
• Integrate certificate management into CI/CD pipelines, infrastructure-as-code platforms, and environments utilizing Kubernetes and Docker.
• Ensure adherence to organizational security policies and industry standards by securely managing certificate-related credentials and keys, along with conducting routine security audits.
• Diagnose and resolve certificate-related issues across development, operations, and security environments, providing technical support and managing production incident escalations.
• Utilize Keyfactor Command (CLM) for automated discovery of certificates, lifecycle management, and large-scale renewals.
• Apply PKI fundamentals, including certificate chains, RSA/ECC key algorithms, CSR generation, CRL/AIA/OCSP, and key ceremonies.
• Develop documentation, runbooks, and training materials on certificate management practices and best practices.
• Over 6 years of practical experience in certificate management, PKI (Public Key Infrastructure) administration, or related security infrastructure roles.
• Strong technical expertise in SSL/TLS protocols, certificate formats (X.509, PEM, DER, PKCS#12), and their application across diverse platforms and environments.
• Proficient with certificate authorities, including commercial CAs (DigiCert, GlobalSign, Sectigo) and open-source solutions (Let's Encrypt, OpenSSL-based CAs).
• Advanced skills in certificate management tools such as OpenSSL, keytool, certbot, and platform-specific utilities for certificate management.
• Practical experience in administering and configuring web servers (Apache, Nginx) and application servers (Tomcat, JBoss, IIS) for certificate installations.
• Proven expertise in Linux/Unix and Windows server environments, including command-line administration and system-level operations.
• Experience with infrastructure-as-code and automation frameworks like Terraform, Ansible, Chef, or Puppet to manage certificate deployments at scale.
• Knowledge of monitoring and alerting solutions to implement systems for tracking certificate status, expiration monitoring, and incident notifications.
• Conduct routine CA maintenance, including database backups, CA certificate renewals, CRL/AIA rollover planning, and root/subordinate CA key ceremonies as necessary.
• Troubleshoot ADCS-related challenges, such as enrollment failures, template permission issues, autoenrollment failures, and SPN/Kerberos-related errors (e.g., WSMAN SPN issues for remote enrollment/orchestration).
• Exceptional organizational, communication, and problem-solving skills, with a keen attention to detail and the ability to document procedures clearly while effectively communicating technical concepts.
• CLT hiring - 40 hours weekly workload
• Work remotely
• Health Insurance - SulAmérica Prestige (available for legal dependents)
• Dental Insurance - SulAmérica (available for legal dependents)
• Life Insurance - Prudential (24x salary)
• Private Pension - Metlife (up to 6% of company match)
• Meal Voucher and Internet allowance - Flash (R$1.000,00 per month)
• Employee Assistance Program
• Wellness program
• Individual performance compensation program, based on eligibility
• Equity grant under our Associate Equity Appreciation Program, based on eligibility
Mercor
RTX
Expel
Qualus
Get handpicked remote jobs straight to your inbox weekly.