Key and Certificate Engineer, Cyber

Deloitte Technology Posted: 26-Sep-2022

Same job available in 12 locations

Atlanta, Georgia, United States

Austin, Texas, United States

Cleveland, Ohio, United States

Dallas, Texas, United States

Detroit, Michigan, United States

Hermitage, Tennessee, United States

Houston, Texas, United States

Miami, Florida, United States

Raleigh, North Carolina, United States

San Antonio, Texas, United States

Tampa, Florida, United States

Toronto, Ontario, Canada

Position summary:

Do you thrive on developing creative and innovative insights to solve complex challenges? Want to work on next-generation, cutting-edge products and services that deliver outstanding value and that are global in vision and scope? Work with other experts in your field? Work for a world-class organization that provides an exceptional career experience with an inclusive and collaborative culture?

Want to make an impact that matters? Consider Deloitte Global.

Work you'll do

KCM Support Engineer role requires customer service, organizational skills, and multi-taking skills. The primary objective of the position is to provide support for the day-to-day operation of the Key and Certificate Management (KCM) services and its components. A base of foundational knowledge of general enterprise IT infrastructure and application support is required to enable the individual to deliver on a high level of customer support and trouble shooting and to meet the business expectations. The candidate must be able to demonstrate foundational understanding of Certificate lifestyle management. Use of industry tools such as Venafi, HSMs, PKI, web server technologies, knowledge of load balancer, or database technologies are a plus. This position reports to the KCM Regional Manager.

Specific responsibilities may change based on the given needs of the business. General responsibilities must always be carried out in accordance with defined standards, policies and procedures, and will include:

Infrastructure Management

  • Operation of Key and Certificate Management Components
  • Manage and control of enterprise infrastructure Hardware Security Modules (HSM)
  • Management and control of Key Certificate Management Disaster Recovery Process
  • Management and control of KCM automation process and tools and resiliency

Operational Support and Service Delivery

  • Provide support for the KCM services
  • Ensure the successful operation of the KCM services by timely processing service requests, addressing incident tickets and following change management global practices
  • Responsible for the daily operation and maintenance for the KCM systems
  • Validate certificate requests and following Global policies for certificate issuance
  • Educate users on the processes to request and use the KCM services, including but not limited to certificate requests and renewals, database encryption key management setups and code signing.
  • Responsible for maintaining and generating reporting, analytics, and dashboards for enterprise certificate management
  • Train and support other support teams including member firms, global member firm infrastructure support and Global Network Operations Centre to streamline support processes
  • Participate in postmortem activities and report generation
  • Participate in 24x7x365 on-call rotation
  • Support Disaster Recovery testing on a yearly basis
  • Identify and report any non-compliance with information security or other policies
  • Respond to escalated service issues and problems
  • Delivery of operational KPIs and associated reports
  • Support and development of PowerShell-based automation scripts for Certificate Management related Tasks

Project Delivery 

  • Attend meetings as needed
  • Work and coordinate with teams to implement project work
  • Document process and procedures

Knowledge Sharing / Documentation

  • Contribute to produce and maintain process, procedure, and other operational documentation, including runbooks, user manuals, administration guides, FAQs, etc.
  • Assist in training new staff in technical processes and procedures
  • Attend training and knowledge improvement activities as required

What you'll be part of - our Deloitte Global Culture:

At Deloitte, we expect results. Incredible—tangible—results. And Deloitte Global professionals play a unique role in delivering those results. We reach across disciplines and borders to serve our global organization. We are the engine of Deloitte. We develop and implement global strategies and provide programs and services that unite our network.

In Deloitte Global, everyone has opportunities. We see the importance of your perspective and your ability to create value. We want you to fit in—with an inclusive culture, focus on work-life fit and well-being, and a supportive, connected environment; but we also want you to stand out—with opportunities to have a strategic impact, innovate, and take the risks necessary to make your mark.

Who you'll work with:

Deloitte Technology Services works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.



  • 1-3 plus years’ experience in implementing or supporting information systems.
  • Basic understanding of PKI, TLS, certificate management and database encryption at rest.
  • Basic knowledge of cryptographic related standards, encryption keys, and key life cycle requirements.
  • Good knowledge of Powershell scripting. Advanced Powershell is a plus.
  • Strong potential for growth and acceptance of additional responsibilities
  • Ability to take a broad view of position and take initiative to communicate, interact and cooperate with others
  • Ability to work as a member of a team and independently
  • Strong ability to prioritize and handle workload
  • Basic Server support
  • Understanding of Certificate Authority
  • Basic SQL knowledge
  • Knowledge of Vormetric


  • Experience with Venafi, Vormetric and Luna HSMs
  • Professional Qualifications:
  •  Associate CISSP or similar Security certification
  • Venafi VSA certification
  • Vormetric certification

How you'll grow:

Deloitte Global inspires leaders at every level. We believe in investing in you, helping you embrace leadership opportunities at every step of your career, and helping you identify and hone your unique strengths. We encourage you to grow by providing formal and informal development programs, coaching and mentoring, and on-the-job challenges. We want you to ask questions, take chances, and explore the possible.

Benefits you'll receive:

Deloitte’s Total Rewards program reflects our continued commitment to lead from the front in everything we do—that’s why we take pride in offering a comprehensive variety of programs and resources to support your health and well-being needs. We provide the benefits, competitive compensation, and recognition to help sustain your efforts in making an impact that matters.

Corporate citizenship:

Deloitte is led by a purpose: to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our people, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities.