Job Description
Company:
Marsh CorporateDescription:
The Enterprise-wide Certificate Management Leader is responsible for establishing and leading Marsh’s centralized Certificate Management Office (CMO). This role ensures robust governance, lifecycle management, and operational excellence of all digital certificates across the enterprise. The Lead will develop and implement strategy, policy, standards, automation, and cross-functional coordination to build a scalable, accountable, and standardized certificate management practice.
The role requires proven and capable leadership to manage direct reports and matrix teams, working collaboratively across business and technology domains to mitigate certificate-related risks, ensure compliance, and enable secure digital operations.
Key Responsibilities
Establish and Lead the Certificate Management Office (CMO):
Develop and implement an enterprise-wide certificate management strategy and governance framework.
Serve as the accountable owner for certificate lifecycle management, policy enforcement, and operational execution
Chair/facilitate and coordinate governance councils, steering committees, and working groups to ensure cross-functional alignment and execution.
Strategy and Roadmap:
Own the certificate management strategy, roadmap, and continuous improvement initiatives.
Advocate for and coordinate funding, tooling, and prioritization decisions in collaboration with senior leadership.
Deliver executive reporting on certificate risk, outages, compliance posture, and program status.
Policy, Standards, and Compliance:
Oversee the definition and enforcement of certificate policies aligned with industry standards (e.g., NIST, CA/Browser Forum).
Ensure compliance tracking, audit readiness, and management of policy exceptions.
Translate policy into technical standards and reusable templates for consistent implementation across environments.
Technical Architecture and Automation:
Guide the design and maintenance of PKI architecture and trust models.
Lead and coordinate automation initiatives to integrate certificate management platforms (e.g., HashiCorp Vault, Venafi) and reduce manual processes.
Serve as the technical authority and advisor on complex certificate scenarios and future-proofing cryptographic approaches.
Operations and Monitoring:
Oversee certificate issuance, renewal, revocation, and incident response coordination.
Maintain centralized certificate inventory and visibility across all domains.
Implement monitoring and alerting mechanisms for certificate expirations and unknown certificates.
Team Leadership and Collaboration:
Manage a team of direct reports including Certificate Program Manager, Policy & Compliance Lead, Standards & Architecture Lead, PKI Architect, Automation & Platform Lead, Certificate Operations Coordinator, and Discovery & Monitoring Lead.
Foster a collaborative matrix reporting environment to ensure domain teams execute certificate management responsibilities effectively.
Foster a culture of accountability, standardization, and continuous improvement within the CMO and across Marsh.
Required Skills and Qualifications
Demonstrated experience in enterprise-wide certificate management, PKI architecture, and digital security.
Proven ability to lead, with experience managing cross-functional teams and matrix reporting structures.
Deep understanding of certificate lifecycle management, cryptographic standards, and compliance frameworks (NIST, CA/Browser Forum).
Expertise in automation tools and platforms such as Venafi, HashiCorp Vault, ACME protocols, and API integrations.
Excellent communication and stakeholder management skills, capable of engaging with senior leadership and technical teams.
Ability to develop and enforce policies, standards, and governance frameworks.
Demonstrated analytical and problem-solving skills and ability to manage incident response related to certificate issues.
