Skip to main content
Posted 27 June, 2026

Senior Infrastructure Engineer

Anaplan
Gurugram, India Full Time
Reference: 102_698304_8450202002

Senior Infrastructure Engineer - Certificate Management

As a Senior Infrastructure Services Engineer specialising in Certificate Management, you will play a key role in designing, operating, and evolving our enterprise certificate management platform. This platform supports thousands of certificates across a global multi-cloud and on-premise environment.

You will focus on building a scalable, automated, and sustainable certificate management capability that enables service teams to manage their certificates through self-service workflows while ensuring strong governance, security, and visibility across the organisation.

Working closely with domain architecture, security, and platform teams, you will help define and implement the future state of certificate lifecycle management, automation, and observability.

The long-term objective of this role is to minimise manual certificate operations by engineering automation, self-service capabilities, and platform integrations that allow service teams to securely manage certificate lifecycles at scale.


Key Responsibilities

Design, implement, and operate the organisation's central certificate management platform supporting both public and internal certificates.

Work with architecture and security teams to define and implement enterprise standards for certificate lifecycle management, including issuance, renewal, revocation, and domain control validation (DCV).

Engineer automation that enables scalable and sustainable certificate operations across thousands of certificates in multi-cloud and on-prem environments.

Develop integrations and automation workflows to support automated certificate issuance, renewal, and lifecycle management.

Implement certificate discovery and inventory capabilities to ensure full visibility of certificates deployed across the environment.

Build supporting automation and integrations using scripting and infrastructure-as-code tools such as Python, Terraform, and Ansible.

Enable service teams to manage certificates through federated self-service capabilities while maintaining central governance and policy enforcement.

Improve observability of certificate health and lifecycle status through metrics, logging, dashboards, and alerting.

Integrate certificate lifecycle monitoring into the organisation's observability stack.

Partner with platform, infrastructure, and service teams to integrate certificate lifecycle processes into service delivery workflows.

Troubleshoot and resolve complex certificate lifecycle issues and drive improvements that reduce manual operational effort.

Maintain clear documentation, architectural diagrams, and operational runbooks for the certificate management platform.

Continuously evolve the platform to support changing industry requirements such as shorter certificate lifespans and updated domain validation processes.

Validate certificate signing requests and TLS certificate contents using tools such as openssl to ensure compliance with modern certificate standards and prevent issuance errors.


Required Qualifications

5+ years of experience working in infrastructure engineering, platform engineering, or site reliability roles.

Strong understanding of TLS/PKI fundamentals and certificate lifecycle management.

Experience operating or integrating with enterprise certificate management platforms.

Experience developing automation and integrations using scripting or programming languages such as Python or similar.

Practical experience automating infrastructure or operational workflows using tools such as Terraform, Ansible, or comparable automation frameworks.

Experience working in distributed infrastructure environments spanning cloud and on-premise platforms.

Strong troubleshooting and problem-solving skills in complex production environments.

Experience collaborating with cross-functional teams including security, platform engineering, and service owners.

Bachelor's degree in Computer Science, Engineering, or equivalent practical experience.


Desired Skills

Experience working with certificate lifecycle management platforms such as AppViewX, Sectigo, or CyberArk.

Experience integrating with public certificate authorities such as DigiCert, Let's Encrypt, SSL.com, or GlobalSign.

Experience implementing automated certificate lifecycle workflows using protocols such as ACME, EST (Enrollment over Secure Transport), or SCEP (Simple Certificate Enrollment Protocol).

Experience managing distributed certificate authorities, certificate revocation lists (CRLs), and Online Certificate Status Protocol (OCSP) services.

Experience with private certificate authorities such as AWS Private CA, HashiCorp Vault CA, or Microsoft Certificate Services.

Knowledge of different types of certificates used in enterprise environments and their use cases (e.g., TLS/SSL, mTLS, client authentication, service-to-service communication).

Experience with observability platforms such as Prometheus, Grafana, Splunk, or ElasticSearch/OpenSearch.

Experience supporting infrastructure across multi-cloud and on-premise environments.

Experience working with containers and container orchestration platforms such as Kubernetes.

Working knowledge of Linux systems and operating environments.

Experience validating certificate signing requests and certificate metadata using tools such as openssl.

Understanding of industry trends impacting certificate lifecycle management, including shorter certificate lifetimes and evolving domain control validation requirements.

Sign up for Job Alerts