The role is 5 days on-site in either Preston or Inverness
This role is a The Digital Certificate Management Consultant operates within the Operational Integrator (OI) function within a multi-supplier (SIAM) environment and is responsible for governing, coordinating, and assuring digital certificate management activities across all suppliers.
The role provides oversight of certificate life cycle management, supplier compliance, certificate ownership, inventory accuracy, and certificate-related risk.
This is a governance, coordination, and assurance role and does not perform certificate administration, PKI operations, cryptographic engineering, or technical certificate deployment activities.
skills and experience
Essential
Experience in Digital Certificate Management, PKI Governance, Cyber Security Governance, Information Assurance, or GRC
Strong understanding of:
Certificate life cycle management
Certificate-related operational risks
Governance and assurance practices
Security compliance and audit requirements
Experience working within multi-supplier, SIAM, or complex outsourced environments
Strong stakeholder management and supplier coordination skills
Experience producing governance reporting and risk-based management information
Ability to interpret certificate management outputs and reporting without direct operational ownership
Desirable
Knowledge of:
Enterprise PKI environments
Public Certificate Authorities (DigiCert, Sectigo, Entrust, GlobalSign etc.)
ISO 27001 and ISMS requirements
NIST Cyber Security Framework
NCSC guidance
Experience within Defence, Government, Critical National Infrastructure, or highly regulated environments
Experience supporting audit and assurance programmes
Exposure to ServiceNow, GRC tooling, or certificate management platforms
Key Deliverables
- Certificate Management Governance Framework
- Consolidated certificate inventory reporting
- Certificate risk and compliance dashboards
- Supplier performance reporting
- Certificate life cycle assurance reporting
- Audit-ready evidence repository
- Governance and risk board reporting packs
- Continuous improvement recommendations and maturity assessments