Job Title: Public Key Infrastructure (PKI) Administrator / Systems Administrator
Duration: 12 Months
Location: San Jose, Lehi, Ottawa
Position Summary:The PKI Administrator will be involved in the implementation, maintenance and support of Adobe’s Public Key Infrastructure (PKI) and Strong Authentication solutions. The position will involve the development, deployment, and support of Adobe’s PKI solutions corporate IT functions. As a PKI Administrator, he/she will also support Adobe’s enterprise authentication infrastructure which includes digital certificate authentication for our 802.1x wireless and Symantec VIP one-time password (OTP) services.
The PKI Administrator will interact with various engineering and corporate IT teams to maintain services and troubleshoot service issues.
Essential Duties, Responsibilities:• Assist in the maintenance and support all Enterprise PKI technology, including
o Symantec’s MPKI and VIP offerings
o Microsoft Certificate Services
• Administer the PKI certificate lifecycle for various solutions
• Evaluate upgrades and new products in a lab environment for the enterprise PKI infrastructure
• Propose and implement improvements to Adobe’s PKI in accordance with standard procedures and change control policies and procedures
• Participate in projects to deploy new PKI applications and services
• Assist in the development of PKI or authentication solutions using Perl or Java
• Implement all changes to the PKI infrastructure in accordance with standard procedures and change control policies and procedures
• Provide documentation and training to IT extended teams (Services Desk, Desktop Services, Desktop Engineering, Directory Services, and Messaging)
• Work with Technical Writers to maintain PKI online resources
Skills:• Demonstrated knowledge in systems administration (Required)
o Windows 20xx Server
o Apple OS X
o Linux
o Microsoft Active Directory
o GPOs (Global Policy Objects)
o Domain membership and authentication
o Internet Information Service (IIS)
o DNS
o Server hardening & security
• Familiarity with development environments (Required)
o Perl
o Java
• Familiarity with x.509 digital certificates (Desired)
o Windows
Certificate storage (User vs. Machine)
CSP
o Apple OS X
Certificate storage (e.g. Keychain)
o Java Keystore
o Command-line tools (e.g. certtool, security, openssl, etc.)
o Certificate Fields
o Certificate Usage
Client Authentication
Signing
Encryption
• S/MIME
• EFS
Revocation (CRL & OCSP)
Validity checking
o Microsoft Certificate Services
Certificate Templates
Auto enrollment
Manual enrollment
User and machine certs