Skills required
Technologies this role asks for
Prepare for this role
Practice and Learn are coming soon for Amazon Web Services (AWS), Microsoft Azure — browse articles meanwhile, then apply.
Job description
What you’ll do in this role
Job Overview
Atos is hiring for a Machine Identity Service Architect role with work locations in Bangalore and Mumbai. The position focuses on architecting and productising identity and Public Key Infrastructure (PKI) services, with emphasis on service definition, reference architecture, platform evaluation, security controls, workload identity, machine identity governance, and cryptographic migration planning.
The role requires design-level PKI expertise together with hands-on understanding of hardware security modules, key custody, identity enrolment protocols, certificate lifecycle management, Kubernetes, cloud IAM, service mesh technologies, and post-quantum cryptography. The job description emphasizes architecture and productisation rather than implementation-only responsibilities.
Key Responsibilities and Architecture Focus
- Architect and productise identity or PKI services, including reference architecture, platform evaluation and selection, and service definition.
- Design PKI environments covering certificate authorities, certificate profiles, policies, revocation mechanisms, and audit frameworks.
- Address HSM and key-custody requirements, including PKCS#11, FIPS 140-3, and participation in a witnessed key ceremony.
- Support enrolment and certificate renewal protocols such as ACME, EST, SCEP, CMP, and Microsoft auto-enrolment.
- Work with Microsoft AD CS and commercial PKI platforms including EJBCA, Entrust, and DigiCert.
- Work with certificate lifecycle management platforms such as Idira Certificate Manager, Keyfactor, AppViewX, and DigiCert Trust Lifecycle Manager.
- Design workload identity approaches involving SPIFFE/SPIRE, Kubernetes service account tokens, cloud identity federation, mTLS, and service mesh environments.
- Apply Kubernetes administrator-level knowledge together with IAM capabilities across Azure, AWS, and GCP.
- Address machine identity governance for service accounts, managed identities, service principals, OAuth application grants, and API keys, including ownership inference and scope reduction.
- Support post-quantum cryptography initiatives, cryptographic inventory, hybrid certificates, migration planning, and crypto-agility.
Required Skills
- PKI architecture: Design-depth knowledge of X.509/RFC 5280, CA hierarchy design, certificate profiles, CP/CPS, CRL, OCSP, and audit frameworks including WebTrust and ETSI.
- HSM and key custody: Knowledge of PKCS#11 and FIPS 140-3, with hands-on participation in a witnessed key ceremony.
- Certificate enrolment and renewal: Experience with ACME, EST, SCEP, CMP, and Microsoft auto-enrolment.
- Microsoft PKI: Experience with Microsoft AD CS and at least one of EJBCA, Entrust, or DigiCert.
- Certificate lifecycle management: Familiarity with Idira Certificate Manager, Keyfactor, AppViewX, or DigiCert Trust Lifecycle Manager.
- Workload identity: Knowledge of SPIFFE/SPIRE, Kubernetes service account tokens, cluster-to-cloud identity federation, mTLS, and service mesh environments.
- Kubernetes and cloud IAM: Administrator-level Kubernetes knowledge and cloud IAM across Azure, AWS, and GCP.
- Machine identity governance: Understanding of service accounts, managed identities, service principals, OAuth application grants, and API keys, including ownership inference and scope reduction.
- Cryptographic modernization: Knowledge of NIST FIPS 203, FIPS 204, and FIPS 205, hybrid certificates, migration planning, and crypto-agility.
PKI and Cryptography
The role requires deep PKI design knowledge rather than implementation-only exposure. This includes X.509 and RFC 5280, CA hierarchy architecture, certificate profiles, certificate policies and practices, certificate revocation through CRL and OCSP, and relevant audit frameworks.
Key custody is another important area. The role calls for knowledge of PKCS#11 and FIPS 140-3 as well as hands-on participation in a witnessed key ceremony. The position also covers cryptographic inventory and planning for post-quantum cryptography, including NIST FIPS 203, FIPS 204, and FIPS 205, hybrid certificates, migration planning, and crypto-agility.
Identity, Kubernetes and Cloud
The position covers machine and workload identity across modern infrastructure. Relevant areas include SPIFFE/SPIRE, Kubernetes service account tokens, and federation between clusters and cloud identity systems such as IRSA, Azure Workload Identity, and GKE identity approaches.
Strong knowledge of Kubernetes at administrator depth is required along with cloud IAM across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). The role also includes mTLS and service mesh considerations and governance of non-human identities such as service accounts, managed identities, service principals, OAuth application grants, and API keys.
Good to Have
- IDnomic experience.
- Experience with machine identity governance platforms such as Cisco/Astrix, Entro, Natoma, Oasis, SailPoint, or Saviynt for non-human identity.
- Experience with cryptographic discovery tooling such as Keyfactor/InfoSec Global or SandboxAQ.
- Experience with secrets management platforms such as Vault or Akeyless at the integration boundary.
Work Location
The job description identifies Mumbai and Bangalore as the work locations. The publication listing specifically shows Bangalore, India, while the work-location section states Mumbai and Bangalore.
Who Should Apply
This opportunity is suited to professionals with architecture-level experience in identity or PKI services and strong knowledge of certificate infrastructure, key custody, certificate lifecycle management, workload identity, Kubernetes, cloud IAM, machine identity governance, and cryptographic modernization.
The provided job description does not specify an educational qualification, required years of experience, salary range, application deadline, or fresher eligibility. These fields are therefore not assumed.
How to Apply
Review the role requirements and submit an application through the supplied Atos job application page. Apply now through SoftoJobs to explore this opportunity.
Eligibility
Education, passing batch and experience
Education
Any Engineering Degree — All Branches
Experience
Not specified (Freshers welcome)
Similar Fresher Jobs
More openings you may like