Senior Analyst - IAM PKI
PepsiCo · Hyderabad
- Experience10–11 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelexecutive
- Posted16 Sept 2026
About PepsiCo
PepsiCo is hiring in Hyderabad in consumer goods. This role looks for around 10+ years of experience.
Skills
- Public Key Infrastructure
- Enterprise Key and Certificate Lifecycle Management
- Hardware Security Modules
- Non-Human Identity Management
- PowerShell
- Azure
- Amazon Web Services
- API development
- API integration
- cryptographic protocols
- certificate-based authentication
- device trust
- Active Directory Certificate Services
- Certificate Revocation List
- Online Certificate Status Protocol
- Thales HSM
- public certificate authorities
- Active Directory Domain Services
- ITSM
- modern authentication protocols
- single sign-on
The role
A cybersecurity analyst at a consumer goods company designs and operates Public Key Infrastructure, Non-Human Identity Management, and certificate lifecycle management, securing cloud and enterprise integrations. The role also applies PowerShell and cryptographic protocols to automate certificate services and maintain resilient authentication infrastructure.
Full job description
Overview
Main purpose of role PKI Sr. Analyst will be responsible for managing the end-to-end digital certificates and lifecycle management solution across all supporting components. This role includes Engineering, Integrations, Operations and maintaining the global PKI and NHI environment at par with industry standard and best practices.
Responsibilities
Accountabilities
Lead the digital certificate services space, a digital form of identification where consumers, businesses and organizations can exchange data securely, using public key infrastructure (PKI), Enterprise Key and Certificate Lifecycle management (EKCM), Hardware Security Modules (HSM) solutions for global PepsiCo.Drive technical discussions to understand digital certificate services requirements while partnering with application teams who design and implement solutions.Ensure digital certificate services provided align with PepsiCo’s security standards and align with industry best practices.Manage the engineering and operations teams (people and work) for digital certificate services by mentoring junior members, ensuring SLAs are met, and ensuring tasks are properly completed.Manage the certificate services space end-to-end from designing solutions for services for new integrations and patterns, to implementing projects in the certificate services space, and providing sustained support across all products in the certificate services space.Drive automation initiatives for certificate services including certificate provisioning and monitoring for digital certificate services by identifying opportunities for enhancements and implementation with no issues.Maintain and enhance global solutions for the digital certificate area ensuring high availability and disaster recovery across regions with resiliency including planning and delivering upgrades.Provide guidance, educate key stakeholders on certificate life cycle processes and procedures.Lead incident management for digital certificate services across the solution stack driving root cause and resolution within service level agreement.
Responsibilities
Engineering and solutioning PKI design and cross functional integrationsWorking on Non-Human Identity lifecycle managementAssisting users on submitting SSL certificate requestsWorking on Incidents, alerts, service requests in ITSMIssuing and managing both Internal and external CA certificates using cert management toolAssisting users to download the certificate from cert management toolDomain management for issuing external (Entrust) SSL certificates.Provisioning (pushing SSL certificates into server) of SSL certificates to AWS, Java JKS and Windows serversProvide support on installation of SSL certificates in Windows IIS, JAVA JKS, Unix/Linux, Apache, Tomcat, Azure Key vault, AWS ALB/ELB, F5’s etc.Provide support on generating a CSR or converting certificate formats using open SSLMaintaining data and sending follow up emails on certificates expiry, before they get expired, to avoid warnings and outagesPreparing and presenting weekly and monthly reports on Service requests, Incidents, and alertsFollow up with users for closure of pending tickets.Providing end to end operational support to internal customers.Managing certificate and key ownership data and keeping it up to dateWorking Knowledge of ITSM process (Request management, change management, Incident management) on tools such as SNOWConfiguring and managing ADCS, CRL and OCSP ServicesDocument all key generation and management activitiesCreating and maintaining CPS, architecture, Process and Run book documentsCommunicate progress, findings, and ensure successful handoff of deliverables to program and operational teamsProvide detailed project Status to stakeholders Collect feedback from stakeholders and users of security capabilities and incorporate that feedback into service
Qualifications
Years of exp:
Overall IT Experience – 10+ years
Security experience - 8+
PKI, EKCLM, NHI Management - 7+
Power shell scripting - 7+
Cloud platforms (Azure, AWS)- 5+
API development and integration - 5+
BS/BTech in Engineering
Mandatory Tech Skills
Good working knowledge of cryptographic and modern auth protocolsWell versed with Certificate based authentication and device trustWell versed with Non-Human Identity managementIn depth knowledge of Active Directory Certificate Services (AD CS)In depth knowledge of CRL and OCSP and their functionalityFamiliarity with PKI and cryptographic terminology and managementKnowledge of CLM tool such as Venafi, AppviewX, Keyfactor added advantageHands on experience and Working knowledge of Thales HSMHands on experience and working knowledge of public CAGood working knowledge of cloud platforms (Azure and AWS) and SaaS offerings for PKI and EKCLMKnowledge of Active Directory domain serviceKnowledge of scripting languages such as PowerShell, API based automationKnowledge of ITSM processes like request, incident, change management etc.
Mandatory Non Tech Skills
Strong oral and written communications skillsAbility to work within project timelinesDeliver outcomes with a little supervision, must be a self-starter and self-motivatorProactive approach and enthusiasm for problem identification and solvingAbility to think strategically and suggest creative solutionsAbility to synthesize complex requirements into simple business practicesFlexible and able to adapt to changing priorities
Differentiating factors
Knowledge of various Identity and Access Management technologies and platforms
Working knowledge of Active Directory Domain services
Working knowledge of Modern Auth protocols and single sign on
Good to have knowledge of Quantum cryptography and PQC protocols.
God to have knowledge of concepts like Device Trust, Zero trust and password less authentication