Digicert Architect
The Role: DigiCert Architect
Location: London (or) Watford, UK
Position Type: Contract Inside IR35
Remote work option Available: Hybrid - 3-4 days in a week
Job Description:
For an IAM or PKI assessment, the Active Directory Certificate Services (ADCS) & DigiCert Architect/SME is the primary owner of the organization's certificate infrastructure, PKI architecture, and certificate life cycle governance. Internal design documents in your environment reference deployment of Root CA, Issuing CA, AD Certificate Services, certificate hierarchy, SSL certificates, and certificate distribution, which are core responsibilities of this role.
Role Summary
Active Directory Certificate Services (ADCS) & DigiCert Architect/SME
Responsible for the design, implementation, governance, and operational management of enterprise Public Key Infrastructure (PKI), Microsoft ADCS, and DigiCert-managed public certificates. Ensures secure authentication, encryption, digital signing, and certificate life cycle management across on-premises, cloud, and hybrid environments.
Key Responsibilities
PKI Architecture & Design
- Design enterprise PKI architecture and certificate trust models.
- Define Root CA, Subordinate/Issuing CA hierarchy.
- Establish certificate policies and governance standards.
- Design high-availability and disaster recovery solutions for PKI services.
- Ensure compliance with security and regulatory requirements.
Active Directory Certificate Services (ADCS)
- Deploy and administer ADCS infrastructure.
- Manage Root CA and Issuing CA Servers.
- Configure certificate templates and enrolment policies.
- Implement Certificate Revocation Lists (CRL) and Online Certificate Status Protocol (OCSP).
- Enable certificate auto-enrolment through Group Policy.
- Integrate ADCS with Active Directory and Azure-based services.
DigiCert Certificate Management
- Administer DigiCert CertCentral portal.
- Manage external/public SSL/TLS certificates.
- Handle certificate requests, approvals, renewals, and revocations.
- Maintain certificate inventory and ownership records.
- Coordinate domain validation and organization validation activities.
- Ensure timely certificate renewals to avoid service outages.
Certificate Lifecycle Management
- Define certificate issuance and approval processes.
- Monitor certificate expiration and renewal schedules.
- Implement automated certificate life cycle management.
- Manage certificate revocation and replacement processes.
- Conduct periodic certificate inventory reviews.
Security & Compliance
- Enforce PKI security best practices.
- Protect CA private keys and HSM integrations.
- Conduct certificate audits and compliance reviews.
- Support cyber security, risk, and audit teams.
- Ensure adherence to regulatory and organizational standards.
Identity & Access Management Integration
- Support certificate-based authentication.
- Enable Smartcard authentication where applicable.
- Integrate certificates with:
- Active Directory
- Azure AD/Entra ID
- VPN solutions
- Wi-Fi Authentication (802.1X)
- Web applications
- Email security services
- Device management platforms
Operations & Troubleshooting
- Resolve certificate enrolment failures.
- Troubleshoot SSL/TLS issues.
- Support application teams during certificate deployments.
- Investigate authentication failures related to certificates.
- Perform root cause analysis for PKI incidents.
Assessment & Advisory Responsibilities
For assessments such as the RIO IAM Assessment, the SME should:
- Provide current PKI architecture details.
- Explain certificate governance and management processes.
- Identify security gaps and improvement opportunities.
- Support maturity assessments and control evaluations.
- Recommend modernization and automation initiatives.
- Define target-state certificate management strategy.
Typical Deliverables
- PKI Architecture Design Documents
- Certificate Lifecycle Procedures
- Certificate Inventory Reports
- CA Hardening Standards
- Certificate Governance Framework
- Operational Runbooks and SOPs
- Audit and Compliance Evidence
- Risk Assessment Reports
Required Skills
- Microsoft Active Directory Certificate Services (ADCS)
- Public Key Infrastructure (PKI)
- DigiCert CertCentral
- SSL/TLS Certificates
- Active Directory & Microsoft Entra ID
- Windows Server Administration
- PowerShell Automation
- HSM Technologies
- Security Architecture
- Cybersecurity Governance & Compliance