Palo Alto Networks is looking for a talented Staff Systems Engineer (PKI ) who will be responsible for build, configuration, and maintainability of our PKI platform using Infrastructure as Code. As senior technical staff, you will support Tier-3 engineering for Linux build and configuration automation with core focus on PKI domain and related technologies.
PKI infra provides critical services which enhance secure and trustworthy communications between applications, services and users. The ideal candidate enjoys working in a fast-paced environment with highly innovative technologies. You will make a big impact in this highly visible role by building PKI as a service offering for our customers.
Your Impact
Implementing and supporting the PKI Linux infrastructure as code where our globally distributed customer-facing PKI platform runs.
Provision, configure & support resilient hybrid cloud deployment architecture using the automation framework and make it more efficient
Manage scalability, capacity planning, redundancy, and resiliency.
Maintain service availability and performance SLAs based on business and product requirements.
Contribute to documentation related to design, deployment, validation, operations and DR/BCP.
Design proactive service monitoring, alerting and trend analysis of underlying infrastructure, and support the operations team in implementation.
Your Experience
8-10 years of hands-on Linux experience in managing and supporting Linux server infrastructure in RHEL/Ubuntu.
Strong GCP compute and kubernetes engine knowledge
Capability to automate infrastructure related processes using programming languages such as Python, JavaScript/TypeScript, Golangt, etc
Experience with programming frameworks such as Flask, NestJS, Gin, etc
Understanding/experience working with microservice patterns such orchestration based Sagas using tools such as Conductor
Experience with Linux and container infrastructure CI/CD platform
Create and maintain operational runbooks.
Experience in configuring and supporting HashiCorp Vault
Design and performance tuning for Linux infrastructure and API, in-depth knowledge of multi-tier web applications.
Solid understanding of API infrastructure optimization and security.
Fluent in Linux security & system hardening, vulnerability management & patching process.
Familiarity with CIS compliance levels.
Must be comfortable with Ansible, Chef or similar configuration management tool to manage infrastructure as code and source code control systems such as GIT or SVN.
Ability to work cross-functionally across multiple business units, such as product development and engineering
Experience with configuring and supporting Certificate Authority, OCSP, and HSM solutions
Understanding of NIST, IEEE, FIPS security standards. NIST 1800-16, NIST 800-52, RFC5280,..
Experience with certificate request protocols, SCEP, ACME, CMP, or similar
Participate in 24x7 on-call rotation
Must be able to collaborate with a global team spread across multiple time zones
Strong technical writing skills to support required documentation
Bachelors/Masters degree in Computer Science, Information Technology or technical stream with the equivalent combination of work experience required.